Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém, preventivní kontrola

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Problém, preventivní kontrola

#1 Příspěvek od zody »

Zdravím, všiml jsem si jednoho programu v Správci úloh.
Když dam procesy tak je to OK ale když nechám zobrazit procesy všech uživatelů mam tam program svchost.exe který zabírá 90 000 až 130 000kb.
Přijde mi to trochu divné a výkon počítače se poněkud snížil.
Pro jistotu dávám výpis z RSIT

Logfile of random's system information tool 1.08 (written by random/random)
Run by PC at 2011-06-17 18:36:17
Microsoft Windows 7 Home Premium
System drive C: has 82 GB (18%) free of 454 GB
Total RAM: 4095 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:36:24, on 17.6.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Vtune\TBPANEL.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\World of Warcraft\Wow.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files\trend micro\PC.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Lišta Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9115 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2264
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files (x86)\Vtune\TBPANEL.exe" /A
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3684.103059e0.103669824 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" "Mozilla.Firefox.4.0.1" -omnijar C:\Program Files (x86)\Mozilla Firefox\omni.jar 3684 \\.\pipe\gecko-crash-server-pipe.3684 plugin
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\AUDIODG.EXE 0x1e0
"C:\Program Files (x86)\World of Warcraft\Wow.exe"
"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /prefetch:1
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Windows\system32\Dwm.exe"
"C:\Users\PC\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-07-27 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar BHO - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll [2010-10-11 612616]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806} - Lišta Centrum.cz Toolbar - C:\Program Files (x86)\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]
{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - uTorrentBar Toolbar - C:\Program Files (x86)\uTorrentBar\tbuTor.dll [2010-12-09 3911776]
{30F9B915-B755-4826-820B-08FBA6BD249D} - Conduit Engine - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll [2010-12-09 3911776]
{8dcb7100-df86-4384-8842-8fa844297b3f} - @C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll,-100 - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2348.0\npwinext.dll [2010-10-11 612616]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VIAAUD"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"=C:\Program Files (x86)\Vtune\TBPanel.exe [2010-10-22 2158592]
"Sony Ericsson PC Companion"=C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2009-12-08 774144]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-12-04 2792448]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-05-10 3459712]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"Microsoft Default Manager"=C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [2010-05-10 439568]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2011-05-17 395144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-06-17 18:36:17 ----D---- C:\rsit
2011-06-17 18:36:17 ----D---- C:\Program Files\trend micro
2011-06-17 06:25:25 ----SHD---- C:\Config.Msi
2011-06-16 15:33:15 ----D---- C:\Program Files (x86)\Bethesda Softworks
2011-06-15 06:44:32 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-15 06:44:16 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 06:44:15 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 06:44:09 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 06:44:05 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 06:43:58 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 06:43:58 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 06:43:57 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 06:43:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 06:43:51 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 06:43:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 06:43:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-06-15 06:43:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 06:43:45 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 06:43:16 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 06:43:16 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-15 06:43:06 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 06:43:06 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-12 18:24:01 ----D---- C:\Program Files (x86)\Ask.com
2011-06-12 18:23:47 ----D---- C:\Program Files (x86)\DsNET Corp
2011-06-11 02:36:01 ----D---- C:\ProgramData\Solidshield
2011-06-05 19:56:36 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-05 19:45:05 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-05 19:45:05 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-02 18:54:24 ----SHD---- C:\ProgramData\DSS
2011-06-02 18:54:20 ----D---- C:\ProgramData\Codemasters
2011-06-02 18:52:15 ----D---- C:\Windows\SYSWOW64\xlive
2011-06-02 18:51:56 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-06-02 18:51:15 ----RA---- C:\Windows\SYSWOW64\tmp8FD3.tmp
2011-06-02 18:38:33 ----D---- C:\Program Files (x86)\DiRT 3
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\rapture3d_oal.dll
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\mkl_blueripple.dll
2011-06-02 18:02:18 ----D---- C:\Program Files (x86)\BRS
2011-06-02 18:02:11 ----D---- C:\Program Files (x86)\OpenAL
2011-06-02 18:02:11 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\OpenAL32.dll
2011-06-02 18:02:10 ----RA---- C:\Windows\SYSWOW64\tmpA278.tmp
2011-06-02 18:02:10 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-06-02 17:50:44 ----D---- C:\Program Files (x86)\Codemasters
2011-05-28 11:48:20 ----D---- C:\Program Files (x86)\Fable III
2011-05-28 00:59:16 ----A---- C:\Windows\SYSWOW64\msidcrl40.dll
2011-05-28 00:56:58 ----A---- C:\Windows\system32\roboot64.exe
2011-05-28 00:27:14 ----D---- C:\Program Files (x86)\Microsoft Games
2011-05-27 17:17:35 ----D---- C:\Program Files\The Witcher 2
2011-05-27 15:00:08 ----D---- C:\Program Files (x86)\The Witcher 2
2011-05-25 19:32:47 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-25 18:27:21 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-05-25 18:27:21 ----A---- C:\Windows\system32\poqexec.exe
2011-05-14 23:14:44 ----D---- C:\Program Files (x86)\Dragon Age 2
2011-05-14 20:45:30 ----D---- C:\Program Files (x86)\Electronic Arts
2011-05-14 02:05:21 ----D---- C:\Program Files\Activision
2011-05-11 15:48:25 ----D---- C:\Program Files (x86)\Adobe
2011-05-11 15:43:29 ----D---- C:\Program Files (x86)\MegaDev
2011-05-11 14:34:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-04 16:57:26 ----D---- C:\Users\PC\AppData\Roaming\Mount&Blade With Fire and Sword
2011-05-04 16:53:55 ----D---- C:\Program Files (x86)\Mount&Blade With Fire and Sword
2011-04-28 06:34:10 ----A---- C:\Windows\explorer.exe
2011-04-28 06:34:09 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-04-28 06:34:06 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-04-28 06:34:06 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-28 06:33:26 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-04-28 06:33:25 ----A---- C:\Windows\SYSWOW64\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\storport.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-04-28 06:33:24 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2011-04-28 06:33:24 ----A---- C:\Windows\system32\fsutil.exe
2011-04-28 06:33:16 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-04-28 06:33:16 ----A---- C:\Windows\system32\prevhost.exe
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmpA100.tmp
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmp8FD2.tmp
2011-04-15 20:28:26 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-15 20:28:26 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\jscript.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42.dll
2011-04-15 20:28:11 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-15 20:28:11 ----A---- C:\Windows\system32\atmfd.dll
2011-04-15 20:28:10 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-15 20:28:10 ----A---- C:\Windows\system32\atmlib.dll
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winresume.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winload.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdusb.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdcom.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kd1394.dll
2011-04-15 20:27:34 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-15 20:27:32 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-12 12:46:12 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-04-09 18:55:44 ----A---- C:\Windows\SYSWOW64\xlive.dll
2011-04-09 18:55:42 ----A---- C:\Windows\SYSWOW64\xlivefnt.dll
2011-04-09 18:55:28 ----A---- C:\Windows\SYSWOW64\xlive.dll.cat
2011-04-09 16:06:56 ----D---- C:\ProgramData\Electronic Arts
2011-04-09 16:06:56 ----D---- C:\ProgramData\EA Core
2011-04-08 16:24:21 ----A---- C:\Windows\system32\drivers\atksgt.sys
2011-04-08 16:24:18 ----A---- C:\Windows\system32\drivers\lirsgt.sys
2011-04-08 16:24:17 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2011-04-08 16:20:57 ----D---- C:\Program Files (x86)\Deep Silver
2011-04-05 15:47:32 ----D---- C:\Program Files (x86)\Crysis 2
2011-03-27 12:47:46 ----D---- C:\Users\PC\AppData\Roaming\The Creative Assembly
2011-03-27 12:31:03 ----D---- C:\Program Files (x86)\Total War Shogun 2
2011-03-27 12:18:13 ----D---- C:\Program Files (x86)\ Total War Shogun 2
2011-03-23 16:37:32 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-03-23 16:37:30 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-03-23 16:37:28 ----D---- C:\Users\PC\AppData\Roaming\PunkBuster
2011-03-20 20:23:49 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-20 20:23:49 ----A---- C:\Windows\system32\FntCache.dll
2011-03-20 20:23:48 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-20 20:23:48 ----A---- C:\Windows\system32\DWrite.dll
2011-03-20 20:23:48 ----A---- C:\Windows\system32\d2d1.dll
2011-03-20 02:22:22 ----D---- C:\Program Files (x86)\FDRLab

======List of files/folders modified in the last 3 months======

2011-06-17 18:36:22 ----D---- C:\Windows\Temp
2011-06-17 18:36:17 ----RD---- C:\Program Files
2011-06-17 18:22:09 ----D---- C:\Windows\System32
2011-06-17 18:22:09 ----D---- C:\Windows\inf
2011-06-17 18:22:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-17 16:50:46 ----SHD---- C:\System Volume Information
2011-06-17 12:58:01 ----D---- C:\Windows\system32\config
2011-06-17 12:43:09 ----D---- C:\ProgramData\NVIDIA
2011-06-17 06:25:45 ----SHD---- C:\Windows\Installer
2011-06-16 20:16:59 ----RSD---- C:\Windows\assembly
2011-06-16 20:16:59 ----D---- C:\Windows\Microsoft.NET
2011-06-16 19:46:54 ----D---- C:\Users\PC\AppData\Roaming\Skype
2011-06-16 18:57:31 ----D---- C:\Users\PC\AppData\Roaming\skypePM
2011-06-16 15:52:20 ----D---- C:\Windows\winsxs
2011-06-16 15:33:15 ----RD---- C:\Program Files (x86)
2011-06-15 19:27:04 ----D---- C:\Windows\system32\drivers
2011-06-15 19:27:03 ----D---- C:\Windows\SYSWOW64\migration
2011-06-15 19:27:03 ----D---- C:\Windows\SysWOW64
2011-06-15 19:27:03 ----D---- C:\Windows\system32\migration
2011-06-15 19:27:03 ----D---- C:\Program Files\Internet Explorer
2011-06-15 19:27:03 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 15:16:47 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 14:53:52 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 06:44:24 ----D---- C:\Windows\system32\catroot
2011-06-15 06:27:35 ----D---- C:\Windows\system32\catroot2
2011-06-14 16:46:45 ----D---- C:\Users\PC\AppData\Roaming\TS3Client
2011-06-12 18:38:15 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2011-06-12 18:24:08 ----D---- C:\Windows\system32\Tasks
2011-06-11 02:36:01 ----HD---- C:\ProgramData
2011-06-10 14:42:10 ----D---- C:\Program Files (x86)\World of Warcraft
2011-06-06 06:19:14 ----D---- C:\Windows
2011-06-05 21:57:33 ----D---- C:\Windows\system32\DriverStore
2011-06-05 19:54:44 ----D---- C:\Program Files (x86)\Common Files
2011-06-05 19:54:10 ----SD---- C:\ProgramData\Microsoft
2011-06-02 18:51:30 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-28 11:44:25 ----D---- C:\Windows\Tasks
2011-05-28 00:38:54 ----D---- C:\Windows\Prefetch
2011-05-27 17:50:10 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-05-26 21:18:10 ----D---- C:\Windows\Logs
2011-05-11 15:48:27 ----D---- C:\ProgramData\Adobe
2011-05-10 14:10:55 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-05-10 14:10:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-05-07 19:38:25 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-05-03 20:12:58 ----D---- C:\Users\PC\AppData\Roaming\Ubisoft
2011-05-02 20:23:17 ----D---- C:\Windows\rescache
2011-05-01 21:20:30 ----SD---- C:\Users\PC\AppData\Roaming\Microsoft
2011-04-28 15:37:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\system32\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\AppPatch
2011-04-16 18:56:37 ----D---- C:\Windows\system32\wdi
2011-04-16 08:23:28 ----D---- C:\Windows\system32\Boot
2011-03-23 16:38:21 ----D---- C:\ProgramData\Ubisoft
2011-03-23 16:37:29 ----D---- C:\Windows\system32\LogFiles
2011-03-23 16:29:21 ----D---- C:\Program Files (x86)\Ubisoft
2011-03-21 19:27:58 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 287576]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 53592]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-02-06 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 64344]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-04-08 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-04-08 43680]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-02-23 1847296]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-11-12 155752]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-11-25 1276928]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 cpuz134;cpuz134; \??\C:\Users\PC\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2009-11-19 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2009-11-19 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2009-11-19 158320]
S3 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-05-10 42184]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-02-23 1005160]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-05-03 75136]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-07-27 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]

-----------------EOF-------------
Předem děkuji. :)

Uživatelský avatar
Danstahr
Přítel fóra
Přítel fóra
Příspěvky: 1069
Registrován: 28 říj 2006 20:23
Bydliště: Londýn
Kontaktovat uživatele:

Re: Problém, preventivní kontrola

#2 Příspěvek od Danstahr »

Dobrý večer :welcome: ,

poprosím ještě o druhý log z RSIT, najdete jej ve složce C:\rsit jako info.txt.
Koupím trochu času, cenu respektuji.

zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Re: Problém, preventivní kontrola

#3 Příspěvek od zody »

info.txt logfile of random's system information tool 1.08 2011-06-17 18:36:26

======Uninstall list======

-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Plugin.exe -maintain plugin
Adobe Reader 9.4.5 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Apple Application Support-->MsiExec.exe /I{EE6097DD-05F4-4178-9719-D3170BF098E8}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Ask Toolbar-->MsiExec.exe /X{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Assassin's Creed Brotherhood-->"C:\Program Files (x86)\InstallShield Installation Information\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}\setup.exe" -runfromtemp -l0x0005 -removeonly
Assassin's Creed II-->"C:\Program Files (x86)\InstallShield Installation Information\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}\setup.exe" -runfromtemp -l0x0005 -removeonly
aTube Catcher-->C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\uninstall.exe
avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
Bing Bar Platform-->MsiExec.exe /I{02EE107B-8D95-4949-8935-4DEBE8F08BE3}
Call of Duty: Black Ops-->"C:\Program Files (x86)\Activision\Call of Duty - Black Ops\unins000.exe"
Conduit Engine-->C:\PROGRA~2\CONDUI~1\ConduitEngineUninstall.exe
Crysis® 2-->MsiExec.exe /X{6033673D-2530-4587-8AD0-EB059FC263F9}
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
DiRT 3-->MsiExec.exe /I{434D0FA0-1558-4D8E-AC3D-BD1000008200}
DiRT 3-->MsiExec.exe /X{434D0FA0-1558-4D8E-AC3D-BD1000008200}
Dragon Age II-->"C:\Program Files (x86)\Common Files\BioWare\Uninstall Dragon Age 2.exe"
Drahyho Program 3.6-->"C:\Program Files (x86)\World of Warcraft\unins000.exe"
EA Download Manager-->C:\Program Files (x86)\Electronic Arts\EADM\EADMUninstall.exe
Fable III-->MsiExec.exe /I{4D53090A-9B45-437B-A66A-831000008300}
Fable III-->MsiExec.exe /I{4D53090A-CE35-42BD-B377-831000018301}
Fable III-->MsiExec.exe /I{4D53090A-CE35-42BD-B377-831000018302}
Fable III-->MsiExec.exe /I{4D53090A-CE35-42BD-B377-831000018303}
Fable III-->MsiExec.exe /X{4D53090A-9B45-437B-A66A-831000008300}
Hunted: The Demon's Forge verze 1.0-->"C:\Program Files (x86)\Bethesda Softworks\Hunted\unins000.exe"
Lišta Centrum.cz Toolbar 1.203.023.002-->"C:\Program Files (x86)\CentrumczToolbar\unins000.exe"
MegaTrainer eXperience V1.0.4.6-->"C:\Program Files (x86)\MegaDev\MD-Trainers\MT-X\unins000.exe"
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /x64 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{790E02A1-145A-3843-8C13-A4F41C9B48B7}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft Default Manager-->MsiExec.exe /X{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{F2508213-9989-4E85-A078-72BE483917EF}
Microsoft Games for Windows Marketplace-->MsiExec.exe /X{4CB0307C-565E-4441-86BE-0DF2E4FB828C}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{928B06E4-DDAA-476A-926A-641620326327}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570-->MsiExec.exe /X{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319-->MsiExec.exe /X{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319-->MsiExec.exe /X{196BB40D-1578-3D01-B289-BEFC77A11A1E}
Mount&Blade With Fire and Sword-->C:\Program Files (x86)\Mount&Blade With Fire and Sword\uninstall.exe
Mozilla Firefox 4.0.1 (x86 cs)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
NirSoft BlueScreenView-->"C:\Program Files (x86)\NirSoft\BlueScreenView\uninst.exe"
NVIDIA Ovladač 3D Vision 266.58-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA Ovladač HD audia 1.1.13.1-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVI2.DLL",UninstallPackage HDAudio.Driver
NVIDIA Ovladače grafiky 267.24-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.3\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
NVIDIA Systémový software PhysX 9.10.0514-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVI2.DLL",UninstallPackage Display.PhysX
OpenAL-->"C:\Program Files (x86)\OpenAL\OpenALwEAX.exe" /U
Panel nástrojů Bing-->C:\Program Files (x86)\Bing Bar Installer\InstallManager.exe /UNINSTALL
PunkBuster Services-->C:\Users\PC\AppData\Roaming\PunkBuster\pbsetup\pbsvc.exe -u
Q-Dir-->C:\Program Files\Q-Dir\Q-Dir.exe -uninstall
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
Rapture3D 2.4.8 Game-->"C:\Program Files (x86)\BRS\unins000.exe"
Risen-->"C:\Program Files (x86)\InstallShield Installation Information\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}\setup.exe" -runfromtemp -l0x0009 -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {F66C3466-1FDB-347C-B3AE-FB6C50627B10} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {B5BD3CA1-11AB-35A6-B22A-6A219DC0668E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {B5BD3CA1-11AB-35A6-B22A-6A219DC0668E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder ClientLP
SHIFT 2 UNLEASHED™-->MsiExec.exe /X{E8C37E27-5205-4C8A-BECB-B00533045AAE}
Skype Toolbars-->MsiExec.exe /I{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}
Skype™ 5.1-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Sony Ericsson PC Companion 1.60.13-->"C:\Program Files (x86)\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
TeamSpeak 3 Client-->"C:\Program Files (x86)\TeamSpeak 3 Client\uninstall.exe"
The Witcher 2-->"C:\Program Files (x86)\InstallShield Installation Information\{F0A209B7-7F85-4BDD-8F1F-B98EEAD9E04B}\setup.exe" -runfromtemp -l0x0409 -removeonly
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
TP-LINK Wireless Client Utility-->"C:\Program Files (x86)\InstallShield Installation Information\{3BD98AAF-61B5-46E0-A6C8-593C242C7C48}\setup.exe" -runfromtemp -l0x0009 -removeonly
Two Worlds II-->C:\Program Files (x86)\Reality fuck Pump\Two Worlds II\Uninstall.exe
Ubisoft Game Launcher-->"C:\Program Files (x86)\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409 -removeonly
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {A45DD0BE-3CD9-3F1E-B233-B90C6983AE77} /parameterfolder Client
uTorrentBar Toolbar-->C:\PROGRA~2\UTORRE~1\UNWISE.EXE /U C:\PROGRA~2\UTORRE~1\INSTALL.LOG
VIA Platforma Ovladače zařízení-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
Vtune 7.14-->"C:\Program Files (x86)\Vtune\unins000.exe"
Windows Live ID Sign-in Assistant-->MsiExec.exe /X{9B48B0AC-C813-4174-9042-476A887592C7}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
World of Warcraft-->C:\Program Files (x86)\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
YouTube Downloader 2.5-->"C:\Program Files (x86)\FDRLab\YouTube Downloader\unins000.exe"

======System event log======

Computer Name: Skycom-PC
Event Code: 7036
Message: Stav služby Centrum zabezpečení byl změněn na: Spuštěno
Record Number: 7237
Source Name: Service Control Manager
Time Written: 20110212171248.602400-000
Event Type: Informace
User:

Computer Name: Skycom-PC
Event Code: 7036
Message: Stav služby Windows Defender byl změněn na: Spuštěno
Record Number: 7236
Source Name: Service Control Manager
Time Written: 20110212171248.251400-000
Event Type: Informace
User:

Computer Name: Skycom-PC
Event Code: 7036
Message: Stav služby Ochrana softwaru byl změněn na: Spuštěno
Record Number: 7235
Source Name: Service Control Manager
Time Written: 20110212171247.527400-000
Event Type: Informace
User:

Computer Name: Skycom-PC
Event Code: 7036
Message: Stav služby SSDP Discovery byl změněn na: Spuštěno
Record Number: 7234
Source Name: Service Control Manager
Time Written: 20110212171247.184400-000
Event Type: Informace
User:

Computer Name: Skycom-PC
Event Code: 7036
Message: Stav služby Služba Výčet přenosných zařízení byl změněn na: Zastaveno
Record Number: 7233
Source Name: Service Control Manager
Time Written: 20110212171247.135400-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247E29-32
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPGenericDriverFound
Reakce: Není k dispozici
ID souboru CAB: 0

Podpis problému:
P1: x64
P2: PCI\VEN_10DE&DEV_0E23&SUBSYS_00000000&REV_A1
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

Připojené soubory:

Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_361e3cf25519a0a4e8d6ec6a1a96aac6bc324b8_cab_064e1d52

Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: d7f49b02-2f98-11e0-97e8-0025227d8c72
Stav hlášení: 4
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20110203132353.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20110203132235.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20110203132233.000000-000
Event Type: Informace
User:

Computer Name: 37L4247E29-32
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110203132229.343750-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247E29-32
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20110203132229.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: 37L4247E29-32
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110203132212.140625-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x1a4
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110203132212.140625-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x2ef2c
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110203132207.718750-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110203132205.468750-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247E29-32
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110203132205.421875-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=AMD64 Family 16 Model 4 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=0403
"CLASSPATH"=.;C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------
tady to je :)

Uživatelský avatar
Danstahr
Přítel fóra
Přítel fóra
Příspěvky: 1069
Registrován: 28 říj 2006 20:23
Bydliště: Londýn
Kontaktovat uživatele:

Re: Problém, preventivní kontrola

#4 Příspěvek od Danstahr »

:arrow: Odinstalujte tyto toolbary :
Ask Toolbar
Bing Bar Platform
Panel nástrojů Bing
uTorrentBar Toolbar
a pokud nepoužíváte, odinstalujte i ten Centrum toolbar.

Poté prosím dejte nový log z RIST.
Koupím trochu času, cenu respektuji.

zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Re: Problém, preventivní kontrola

#5 Příspěvek od zody »

Logfile of random's system information tool 1.08 (written by random/random)
Run by PC at 2011-06-18 15:19:05
Microsoft Windows 7 Home Premium
System drive C: has 65 GB (14%) free of 454 GB
Total RAM: 4095 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:19:07, on 18.6.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Vtune\TBPANEL.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\PC.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6902 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Vtune\TBPANEL.exe" /A
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
WLIDSvcM.exe 2144
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\AUDIODG.EXE 0xec
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2888.d51a440.567143322 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" "Mozilla.Firefox.4.0.1" -omnijar C:\Program Files (x86)\Mozilla Firefox\omni.jar 2888 \\.\pipe\gecko-crash-server-pipe.2888 plugin
"C:\Users\PC\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VIAAUD"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"=C:\Program Files (x86)\Vtune\TBPanel.exe [2010-10-22 2158592]
"Sony Ericsson PC Companion"=C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2009-12-08 774144]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-12-04 2792448]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-05-10 3459712]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-06-08 37296]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-06-17 18:36:17 ----D---- C:\rsit
2011-06-17 18:36:17 ----D---- C:\Program Files\trend micro
2011-06-16 15:33:15 ----D---- C:\Program Files (x86)\Bethesda Softworks
2011-06-15 06:44:32 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-15 06:44:16 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 06:44:15 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 06:44:09 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 06:44:05 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 06:43:58 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 06:43:58 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 06:43:57 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 06:43:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 06:43:51 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 06:43:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 06:43:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-06-15 06:43:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 06:43:45 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 06:43:16 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 06:43:16 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-15 06:43:06 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 06:43:06 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-12 18:23:47 ----D---- C:\Program Files (x86)\DsNET Corp
2011-06-11 02:36:01 ----D---- C:\ProgramData\Solidshield
2011-06-05 19:56:36 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-05 19:45:05 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-05 19:45:05 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-02 18:54:24 ----SHD---- C:\ProgramData\DSS
2011-06-02 18:54:20 ----D---- C:\ProgramData\Codemasters
2011-06-02 18:52:15 ----D---- C:\Windows\SYSWOW64\xlive
2011-06-02 18:51:56 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-06-02 18:51:15 ----RA---- C:\Windows\SYSWOW64\tmp8FD3.tmp
2011-06-02 18:38:33 ----D---- C:\Program Files (x86)\DiRT 3
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\rapture3d_oal.dll
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\mkl_blueripple.dll
2011-06-02 18:02:18 ----D---- C:\Program Files (x86)\BRS
2011-06-02 18:02:11 ----D---- C:\Program Files (x86)\OpenAL
2011-06-02 18:02:11 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\OpenAL32.dll
2011-06-02 18:02:10 ----RA---- C:\Windows\SYSWOW64\tmpA278.tmp
2011-06-02 18:02:10 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-06-02 17:50:44 ----D---- C:\Program Files (x86)\Codemasters
2011-05-28 11:48:20 ----D---- C:\Program Files (x86)\Fable III
2011-05-28 00:59:16 ----A---- C:\Windows\SYSWOW64\msidcrl40.dll
2011-05-28 00:56:58 ----A---- C:\Windows\system32\roboot64.exe
2011-05-28 00:27:14 ----D---- C:\Program Files (x86)\Microsoft Games
2011-05-27 17:17:35 ----D---- C:\Program Files\The Witcher 2
2011-05-27 15:00:08 ----D---- C:\Program Files (x86)\The Witcher 2
2011-05-25 19:32:47 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-25 18:27:21 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-05-25 18:27:21 ----A---- C:\Windows\system32\poqexec.exe
2011-05-14 23:14:44 ----D---- C:\Program Files (x86)\Dragon Age 2
2011-05-14 20:45:30 ----D---- C:\Program Files (x86)\Electronic Arts
2011-05-14 02:05:21 ----D---- C:\Program Files\Activision
2011-05-11 15:48:25 ----D---- C:\Program Files (x86)\Adobe
2011-05-11 15:43:29 ----D---- C:\Program Files (x86)\MegaDev
2011-05-11 14:34:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-04 16:57:26 ----D---- C:\Users\PC\AppData\Roaming\Mount&Blade With Fire and Sword
2011-05-04 16:53:55 ----D---- C:\Program Files (x86)\Mount&Blade With Fire and Sword
2011-04-28 06:34:10 ----A---- C:\Windows\explorer.exe
2011-04-28 06:34:09 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-04-28 06:34:06 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-04-28 06:34:06 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-28 06:33:26 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-04-28 06:33:25 ----A---- C:\Windows\SYSWOW64\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\storport.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-04-28 06:33:24 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2011-04-28 06:33:24 ----A---- C:\Windows\system32\fsutil.exe
2011-04-28 06:33:16 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-04-28 06:33:16 ----A---- C:\Windows\system32\prevhost.exe
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmpA100.tmp
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmp8FD2.tmp
2011-04-15 20:28:26 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-15 20:28:26 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\jscript.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42.dll
2011-04-15 20:28:11 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-15 20:28:11 ----A---- C:\Windows\system32\atmfd.dll
2011-04-15 20:28:10 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-15 20:28:10 ----A---- C:\Windows\system32\atmlib.dll
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winresume.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winload.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdusb.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdcom.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kd1394.dll
2011-04-15 20:27:34 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-15 20:27:32 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-12 12:46:12 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-04-09 18:55:44 ----A---- C:\Windows\SYSWOW64\xlive.dll
2011-04-09 18:55:42 ----A---- C:\Windows\SYSWOW64\xlivefnt.dll
2011-04-09 18:55:28 ----A---- C:\Windows\SYSWOW64\xlive.dll.cat
2011-04-09 16:06:56 ----D---- C:\ProgramData\Electronic Arts
2011-04-09 16:06:56 ----D---- C:\ProgramData\EA Core
2011-04-08 16:24:21 ----A---- C:\Windows\system32\drivers\atksgt.sys
2011-04-08 16:24:18 ----A---- C:\Windows\system32\drivers\lirsgt.sys
2011-04-08 16:24:17 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2011-04-08 16:20:57 ----D---- C:\Program Files (x86)\Deep Silver
2011-04-05 15:47:32 ----D---- C:\Program Files (x86)\Crysis 2
2011-03-27 12:47:46 ----D---- C:\Users\PC\AppData\Roaming\The Creative Assembly
2011-03-27 12:31:03 ----D---- C:\Program Files (x86)\Total War Shogun 2
2011-03-27 12:18:13 ----D---- C:\Program Files (x86)\ Total War Shogun 2
2011-03-23 16:37:32 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-03-23 16:37:30 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-03-23 16:37:28 ----D---- C:\Users\PC\AppData\Roaming\PunkBuster
2011-03-20 20:23:49 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-20 20:23:49 ----A---- C:\Windows\system32\FntCache.dll
2011-03-20 20:23:48 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-20 20:23:48 ----A---- C:\Windows\system32\DWrite.dll
2011-03-20 20:23:48 ----A---- C:\Windows\system32\d2d1.dll
2011-03-20 02:22:22 ----D---- C:\Program Files (x86)\FDRLab

======List of files/folders modified in the last 3 months======

2011-06-18 15:19:06 ----D---- C:\Windows\Temp
2011-06-18 15:07:48 ----RD---- C:\Program Files (x86)
2011-06-18 15:07:47 ----HD---- C:\ProgramData
2011-06-18 15:01:38 ----SHD---- C:\Windows\Installer
2011-06-18 15:01:38 ----D---- C:\Program Files (x86)\Microsoft
2011-06-18 14:59:52 ----D---- C:\Windows\system32\Tasks
2011-06-18 14:35:23 ----D---- C:\Users\PC\AppData\Roaming\Skype
2011-06-18 12:48:44 ----D---- C:\Program Files (x86)\World of Warcraft
2011-06-18 12:09:57 ----D---- C:\Users\PC\AppData\Roaming\skypePM
2011-06-18 12:00:36 ----D---- C:\Windows\system32\config
2011-06-18 11:51:34 ----D---- C:\Windows\System32
2011-06-18 11:51:34 ----D---- C:\Windows\inf
2011-06-18 11:51:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-18 11:47:11 ----D---- C:\ProgramData\NVIDIA
2011-06-17 23:19:33 ----D---- C:\Windows\winsxs
2011-06-17 23:18:24 ----SHD---- C:\System Volume Information
2011-06-17 22:33:05 ----RSD---- C:\Windows\assembly
2011-06-17 18:36:17 ----RD---- C:\Program Files
2011-06-16 20:16:59 ----D---- C:\Windows\Microsoft.NET
2011-06-15 19:27:04 ----D---- C:\Windows\system32\drivers
2011-06-15 19:27:03 ----D---- C:\Windows\SYSWOW64\migration
2011-06-15 19:27:03 ----D---- C:\Windows\SysWOW64
2011-06-15 19:27:03 ----D---- C:\Windows\system32\migration
2011-06-15 19:27:03 ----D---- C:\Program Files\Internet Explorer
2011-06-15 19:27:03 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 15:16:47 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 14:53:52 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 06:44:24 ----D---- C:\Windows\system32\catroot
2011-06-15 06:27:35 ----D---- C:\Windows\system32\catroot2
2011-06-14 16:46:45 ----D---- C:\Users\PC\AppData\Roaming\TS3Client
2011-06-12 18:38:15 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2011-06-06 06:19:14 ----D---- C:\Windows
2011-06-05 21:57:33 ----D---- C:\Windows\system32\DriverStore
2011-06-05 19:54:44 ----D---- C:\Program Files (x86)\Common Files
2011-06-05 19:54:10 ----SD---- C:\ProgramData\Microsoft
2011-06-02 18:51:30 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-28 11:44:25 ----D---- C:\Windows\Tasks
2011-05-28 00:38:54 ----D---- C:\Windows\Prefetch
2011-05-27 17:50:10 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-05-26 21:18:10 ----D---- C:\Windows\Logs
2011-05-11 15:48:27 ----D---- C:\ProgramData\Adobe
2011-05-10 14:10:55 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-05-10 14:10:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-05-07 19:38:25 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-05-03 20:12:58 ----D---- C:\Users\PC\AppData\Roaming\Ubisoft
2011-05-02 20:23:17 ----D---- C:\Windows\rescache
2011-05-01 21:20:30 ----SD---- C:\Users\PC\AppData\Roaming\Microsoft
2011-04-28 15:37:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\system32\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\AppPatch
2011-04-16 18:56:37 ----D---- C:\Windows\system32\wdi
2011-04-16 08:23:28 ----D---- C:\Windows\system32\Boot
2011-03-23 16:38:21 ----D---- C:\ProgramData\Ubisoft
2011-03-23 16:37:29 ----D---- C:\Windows\system32\LogFiles
2011-03-23 16:29:21 ----D---- C:\Program Files (x86)\Ubisoft
2011-03-21 19:27:58 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 287576]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 53592]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-02-06 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 64344]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-04-08 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-04-08 43680]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-02-23 1847296]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-11-12 155752]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-11-25 1276928]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 cpuz134;cpuz134; \??\C:\Users\PC\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2009-11-19 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2009-11-19 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2009-11-19 158320]
S3 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-05-10 42184]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-02-23 1005160]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-05-03 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]

-----------------EOF-----------------

zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Re: Problém, preventivní kontrola

#6 Příspěvek od zody »

Prosím nezkontroloval by mi to někdo?
Nechci nějak naléhat, ale už to je pár dní bez odpovědi tak jestli jsem nedal něco špatně :)

Uživatelský avatar
Danstahr
Přítel fóra
Přítel fóra
Příspěvky: 1069
Registrován: 28 říj 2006 20:23
Bydliště: Londýn
Kontaktovat uživatele:

Re: Problém, preventivní kontrola

#7 Příspěvek od Danstahr »

Dobré odpoledne,

:arrow: Otevřete HijackThis (najdete jej ve svém počítači jako C:\Program Files\trend micro\PC.exe ), stiskněte tlačítko Do a system scan only , u následujících položek zaškrtněte políčko vlevo a klikněte na Fix Checked.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com/?l=dis&o=14672
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
Poté restartujte PC a dejte nový log z RSIT.
Koupím trochu času, cenu respektuji.

zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Re: Problém, preventivní kontrola

#8 Příspěvek od zody »

Adobe Reader jsem odstranil ale toto O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file) jako jediné z toho logu nezmizelo.


Logfile of random's system information tool 1.08 (written by random/random)
Run by PC at 2011-06-20 16:42:27
Microsoft Windows 7 Home Premium
System drive C: has 63 GB (14%) free of 454 GB
Total RAM: 4095 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:42:29, on 20.6.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Vtune\TBPANEL.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\hijackthis.exe
C:\Program Files\trend micro\PC.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {D5D47440-0750-463D-BAEF-A47D02414806} - (no file)
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6263 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2ec
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
WLIDSvcM.exe 1488
"C:\Program Files (x86)\Vtune\TBPANEL.exe" /A
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3464.998fe40.1219823805 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" "Mozilla.Firefox.4.0.1" -omnijar C:\Program Files (x86)\Mozilla Firefox\omni.jar 3464 \\.\pipe\gecko-crash-server-pipe.3464 plugin
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\msiexec.exe /V
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\trend micro\hijackthis.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\PC\Downloads\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{D5D47440-0750-463D-BAEF-A47D02414806}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VIAAUD"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"=C:\Program Files (x86)\Vtune\TBPanel.exe [2010-10-22 2158592]
"Sony Ericsson PC Companion"=C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2009-12-08 774144]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-12-04 2792448]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-05-10 3459712]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-06-20 16:38:21 ----SHD---- C:\Config.Msi
2011-06-17 18:36:17 ----D---- C:\rsit
2011-06-17 18:36:17 ----D---- C:\Program Files\trend micro
2011-06-16 15:33:15 ----D---- C:\Program Files (x86)\Bethesda Softworks
2011-06-15 06:44:32 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-15 06:44:16 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 06:44:15 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 06:44:09 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 06:44:05 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 06:43:58 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 06:43:58 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 06:43:57 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 06:43:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 06:43:51 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 06:43:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 06:43:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-06-15 06:43:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 06:43:45 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 06:43:16 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 06:43:16 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-15 06:43:06 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 06:43:06 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-12 18:23:47 ----D---- C:\Program Files (x86)\DsNET Corp
2011-06-11 02:36:01 ----D---- C:\ProgramData\Solidshield
2011-06-05 19:56:36 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-05 19:45:05 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-05 19:45:05 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-02 18:54:24 ----SHD---- C:\ProgramData\DSS
2011-06-02 18:54:20 ----D---- C:\ProgramData\Codemasters
2011-06-02 18:52:15 ----D---- C:\Windows\SYSWOW64\xlive
2011-06-02 18:51:56 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-06-02 18:51:15 ----RA---- C:\Windows\SYSWOW64\tmp8FD3.tmp
2011-06-02 18:38:33 ----D---- C:\Program Files (x86)\DiRT 3
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\rapture3d_oal.dll
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\mkl_blueripple.dll
2011-06-02 18:02:18 ----D---- C:\Program Files (x86)\BRS
2011-06-02 18:02:11 ----D---- C:\Program Files (x86)\OpenAL
2011-06-02 18:02:11 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\OpenAL32.dll
2011-06-02 18:02:10 ----RA---- C:\Windows\SYSWOW64\tmpA278.tmp
2011-06-02 18:02:10 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-06-02 17:50:44 ----D---- C:\Program Files (x86)\Codemasters
2011-05-28 11:48:20 ----D---- C:\Program Files (x86)\Fable III
2011-05-28 00:59:16 ----A---- C:\Windows\SYSWOW64\msidcrl40.dll
2011-05-28 00:56:58 ----A---- C:\Windows\system32\roboot64.exe
2011-05-28 00:27:14 ----D---- C:\Program Files (x86)\Microsoft Games
2011-05-27 17:17:35 ----D---- C:\Program Files\The Witcher 2
2011-05-27 15:00:08 ----D---- C:\Program Files (x86)\The Witcher 2
2011-05-25 19:32:47 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-25 18:27:21 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-05-25 18:27:21 ----A---- C:\Windows\system32\poqexec.exe
2011-05-14 23:14:44 ----D---- C:\Program Files (x86)\Dragon Age 2
2011-05-14 20:45:30 ----D---- C:\Program Files (x86)\Electronic Arts
2011-05-14 02:05:21 ----D---- C:\Program Files\Activision
2011-05-11 15:43:29 ----D---- C:\Program Files (x86)\MegaDev
2011-05-11 14:34:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-04 16:57:26 ----D---- C:\Users\PC\AppData\Roaming\Mount&Blade With Fire and Sword
2011-05-04 16:53:55 ----D---- C:\Program Files (x86)\Mount&Blade With Fire and Sword
2011-04-28 06:34:10 ----A---- C:\Windows\explorer.exe
2011-04-28 06:34:09 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-04-28 06:34:06 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-04-28 06:34:06 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-28 06:33:26 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-04-28 06:33:25 ----A---- C:\Windows\SYSWOW64\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\storport.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-04-28 06:33:24 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2011-04-28 06:33:24 ----A---- C:\Windows\system32\fsutil.exe
2011-04-28 06:33:16 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-04-28 06:33:16 ----A---- C:\Windows\system32\prevhost.exe
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmpA100.tmp
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmp8FD2.tmp
2011-04-15 20:28:26 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-15 20:28:26 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\jscript.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42.dll
2011-04-15 20:28:11 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-15 20:28:11 ----A---- C:\Windows\system32\atmfd.dll
2011-04-15 20:28:10 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-15 20:28:10 ----A---- C:\Windows\system32\atmlib.dll
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winresume.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winload.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdusb.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdcom.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kd1394.dll
2011-04-15 20:27:34 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-15 20:27:32 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-12 12:46:12 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-04-09 18:55:44 ----A---- C:\Windows\SYSWOW64\xlive.dll
2011-04-09 18:55:42 ----A---- C:\Windows\SYSWOW64\xlivefnt.dll
2011-04-09 18:55:28 ----A---- C:\Windows\SYSWOW64\xlive.dll.cat
2011-04-09 16:06:56 ----D---- C:\ProgramData\Electronic Arts
2011-04-09 16:06:56 ----D---- C:\ProgramData\EA Core
2011-04-08 16:24:21 ----A---- C:\Windows\system32\drivers\atksgt.sys
2011-04-08 16:24:18 ----A---- C:\Windows\system32\drivers\lirsgt.sys
2011-04-08 16:24:17 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2011-04-08 16:20:57 ----D---- C:\Program Files (x86)\Deep Silver
2011-04-05 15:47:32 ----D---- C:\Program Files (x86)\Crysis 2
2011-03-27 12:47:46 ----D---- C:\Users\PC\AppData\Roaming\The Creative Assembly
2011-03-27 12:31:03 ----D---- C:\Program Files (x86)\Total War Shogun 2
2011-03-27 12:18:13 ----D---- C:\Program Files (x86)\ Total War Shogun 2
2011-03-23 16:37:32 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-03-23 16:37:30 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-03-23 16:37:28 ----D---- C:\Users\PC\AppData\Roaming\PunkBuster

======List of files/folders modified in the last 3 months======

2011-06-20 16:42:29 ----D---- C:\Windows\Temp
2011-06-20 16:38:50 ----SHD---- C:\Windows\Installer
2011-06-20 16:38:42 ----RD---- C:\Program Files (x86)
2011-06-20 16:38:42 ----D---- C:\Program Files (x86)\Common Files
2011-06-20 16:38:39 ----D---- C:\ProgramData\Adobe
2011-06-20 16:38:16 ----D---- C:\Windows\SysWOW64
2011-06-20 16:37:51 ----SHD---- C:\System Volume Information
2011-06-20 16:35:26 ----D---- C:\Windows\System32
2011-06-20 16:35:26 ----D---- C:\Windows\inf
2011-06-20 16:35:26 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-20 16:31:13 ----D---- C:\ProgramData\NVIDIA
2011-06-20 16:30:17 ----D---- C:\Windows\system32\config
2011-06-19 21:55:18 ----D---- C:\Users\PC\AppData\Roaming\Skype
2011-06-19 21:55:16 ----D---- C:\Users\PC\AppData\Roaming\skypePM
2011-06-18 15:23:25 ----D---- C:\Program Files (x86)\World of Warcraft
2011-06-18 15:07:47 ----HD---- C:\ProgramData
2011-06-18 15:01:38 ----D---- C:\Program Files (x86)\Microsoft
2011-06-18 14:59:52 ----D---- C:\Windows\system32\Tasks
2011-06-17 23:19:33 ----D---- C:\Windows\winsxs
2011-06-17 22:33:05 ----RSD---- C:\Windows\assembly
2011-06-17 18:36:17 ----RD---- C:\Program Files
2011-06-16 20:16:59 ----D---- C:\Windows\Microsoft.NET
2011-06-15 19:27:04 ----D---- C:\Windows\system32\drivers
2011-06-15 19:27:03 ----D---- C:\Windows\SYSWOW64\migration
2011-06-15 19:27:03 ----D---- C:\Windows\system32\migration
2011-06-15 19:27:03 ----D---- C:\Program Files\Internet Explorer
2011-06-15 19:27:03 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 15:16:47 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 14:53:52 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 06:44:24 ----D---- C:\Windows\system32\catroot
2011-06-15 06:27:35 ----D---- C:\Windows\system32\catroot2
2011-06-14 16:46:45 ----D---- C:\Users\PC\AppData\Roaming\TS3Client
2011-06-12 18:38:15 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2011-06-06 06:19:14 ----D---- C:\Windows
2011-06-05 21:57:33 ----D---- C:\Windows\system32\DriverStore
2011-06-05 19:54:10 ----SD---- C:\ProgramData\Microsoft
2011-06-02 18:51:30 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-28 11:44:25 ----D---- C:\Windows\Tasks
2011-05-28 00:38:54 ----D---- C:\Windows\Prefetch
2011-05-27 17:50:10 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-05-26 21:18:10 ----D---- C:\Windows\Logs
2011-05-10 14:10:55 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-05-10 14:10:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-05-07 19:38:25 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-05-03 20:12:58 ----D---- C:\Users\PC\AppData\Roaming\Ubisoft
2011-05-02 20:23:17 ----D---- C:\Windows\rescache
2011-05-01 21:20:30 ----SD---- C:\Users\PC\AppData\Roaming\Microsoft
2011-04-28 15:37:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\system32\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\AppPatch
2011-04-16 18:56:37 ----D---- C:\Windows\system32\wdi
2011-04-16 08:23:28 ----D---- C:\Windows\system32\Boot
2011-03-23 16:38:21 ----D---- C:\ProgramData\Ubisoft
2011-03-23 16:37:29 ----D---- C:\Windows\system32\LogFiles
2011-03-23 16:29:21 ----D---- C:\Program Files (x86)\Ubisoft
2011-03-21 19:27:58 ----D---- C:\Windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 287576]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 53592]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-02-06 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 64344]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-04-08 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-04-08 43680]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-02-23 1847296]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-11-12 155752]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-11-25 1276928]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 cpuz134;cpuz134; \??\C:\Users\PC\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2009-11-19 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2009-11-19 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2009-11-19 158320]
S3 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-05-10 42184]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-02-23 1005160]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-05-03 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]

-----------------EOF-----------------

Uživatelský avatar
Danstahr
Přítel fóra
Přítel fóra
Příspěvky: 1069
Registrován: 28 říj 2006 20:23
Bydliště: Londýn
Kontaktovat uživatele:

Re: Problém, preventivní kontrola

#9 Příspěvek od Danstahr »

Nevadí, stane se, že něco HJT neopraví, máme ale i jiné nástroje :).

:arrow: Na stránce http://tinyurl.com/653f7oz vložte do okna následující text a stiskněte tlačítko OK. Stažený soubor spusťte a přidání informace do registru potvrďte.

Kód: Vybrat vše

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
"{D5D47440-0750-463D-BAEF-A47D02414806}"=-

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=-
Po provedení restartujte PC a dejte nový log z RSIT.
Koupím trochu času, cenu respektuji.

zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Re: Problém, preventivní kontrola

#10 Příspěvek od zody »

Logfile of random's system information tool 1.08 (written by random/random)
Run by PC at 2011-06-21 15:28:09
Microsoft Windows 7 Home Premium
System drive C: has 64 GB (14%) free of 454 GB
Total RAM: 4095 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:28:13, on 21.6.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16800)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Vtune\TBPANEL.exe
C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\trend micro\PC.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [TBPanel] C:\Program Files (x86)\Vtune\TBPanel.exe /A
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 5933 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2e4
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\Alwil Software\Avast5\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 1308
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Vtune\TBPANEL.exe" /A
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Alwil Software\Avast5\AvastUI.exe" /nogui
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\PC\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VIAAUD"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"=C:\Program Files (x86)\Vtune\TBPanel.exe [2010-10-22 2158592]
"Sony Ericsson PC Companion"=C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [2009-12-08 774144]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-12-04 2792448]
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-05-10 3459712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2011-06-20 16:38:21 ----SHD---- C:\Config.Msi
2011-06-17 18:36:17 ----D---- C:\rsit
2011-06-17 18:36:17 ----D---- C:\Program Files\trend micro
2011-06-16 15:33:15 ----D---- C:\Program Files (x86)\Bethesda Softworks
2011-06-15 06:44:32 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-15 06:44:16 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-15 06:44:15 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-15 06:44:09 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-15 06:44:08 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-15 06:44:05 ----A---- C:\Windows\system32\win32k.sys
2011-06-15 06:43:58 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-06-15 06:43:58 ----A---- C:\Windows\system32\mshtml.dll
2011-06-15 06:43:57 ----A---- C:\Windows\system32\ieframe.dll
2011-06-15 06:43:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-06-15 06:43:51 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-06-15 06:43:51 ----A---- C:\Windows\system32\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-06-15 06:43:50 ----A---- C:\Windows\system32\iertutil.dll
2011-06-15 06:43:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-06-15 06:43:48 ----A---- C:\Windows\system32\msfeeds.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\wininet.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\mstime.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iepeers.dll
2011-06-15 06:43:47 ----A---- C:\Windows\system32\iedkcs32.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\mshtmled.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-06-15 06:43:46 ----A---- C:\Windows\system32\ieui.dll
2011-06-15 06:43:45 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\licmgr10.dll
2011-06-15 06:43:45 ----A---- C:\Windows\system32\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-06-15 06:43:44 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-06-15 06:43:44 ----A---- C:\Windows\system32\msfeedssync.exe
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-15 06:43:20 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-15 06:43:16 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-15 06:43:16 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-15 06:43:06 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-15 06:43:06 ----A---- C:\Windows\system32\inetcomm.dll
2011-06-12 18:23:47 ----D---- C:\Program Files (x86)\DsNET Corp
2011-06-11 02:36:01 ----D---- C:\ProgramData\Solidshield
2011-06-05 19:56:36 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-06-05 19:45:05 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-05 19:45:05 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-02 18:54:24 ----SHD---- C:\ProgramData\DSS
2011-06-02 18:54:20 ----D---- C:\ProgramData\Codemasters
2011-06-02 18:52:15 ----D---- C:\Windows\SYSWOW64\xlive
2011-06-02 18:51:56 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-06-02 18:51:15 ----RA---- C:\Windows\SYSWOW64\tmp8FD3.tmp
2011-06-02 18:38:33 ----D---- C:\Program Files (x86)\DiRT 3
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\rapture3d_oal.dll
2011-06-02 18:02:19 ----A---- C:\Windows\SYSWOW64\mkl_blueripple.dll
2011-06-02 18:02:18 ----D---- C:\Program Files (x86)\BRS
2011-06-02 18:02:11 ----D---- C:\Program Files (x86)\OpenAL
2011-06-02 18:02:11 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\wrap_oal.dll
2011-06-02 18:02:11 ----A---- C:\Windows\system32\OpenAL32.dll
2011-06-02 18:02:10 ----RA---- C:\Windows\SYSWOW64\tmpA278.tmp
2011-06-02 18:02:10 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2011-06-02 17:50:44 ----D---- C:\Program Files (x86)\Codemasters
2011-05-28 11:48:20 ----D---- C:\Program Files (x86)\Fable III
2011-05-28 00:59:16 ----A---- C:\Windows\SYSWOW64\msidcrl40.dll
2011-05-28 00:56:58 ----A---- C:\Windows\system32\roboot64.exe
2011-05-28 00:27:14 ----D---- C:\Program Files (x86)\Microsoft Games
2011-05-27 17:17:35 ----D---- C:\Program Files\The Witcher 2
2011-05-27 15:00:08 ----D---- C:\Program Files (x86)\The Witcher 2
2011-05-25 19:32:47 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-05-25 18:27:21 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2011-05-25 18:27:21 ----A---- C:\Windows\system32\poqexec.exe
2011-05-14 23:14:44 ----D---- C:\Program Files (x86)\Dragon Age 2
2011-05-14 20:45:30 ----D---- C:\Program Files (x86)\Electronic Arts
2011-05-14 02:05:21 ----D---- C:\Program Files\Activision
2011-05-11 15:43:29 ----D---- C:\Program Files (x86)\MegaDev
2011-05-11 14:34:59 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-05-11 14:34:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-05-11 14:34:54 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-05-11 14:34:53 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-05-04 16:57:26 ----D---- C:\Users\PC\AppData\Roaming\Mount&Blade With Fire and Sword
2011-05-04 16:53:55 ----D---- C:\Program Files (x86)\Mount&Blade With Fire and Sword
2011-04-28 06:34:10 ----A---- C:\Windows\explorer.exe
2011-04-28 06:34:09 ----A---- C:\Windows\SYSWOW64\explorer.exe
2011-04-28 06:34:06 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-04-28 06:34:06 ----A---- C:\Windows\system32\XpsPrint.dll
2011-04-28 06:33:26 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-04-28 06:33:25 ----A---- C:\Windows\SYSWOW64\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\esent.dll
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\storport.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-04-28 06:33:25 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-04-28 06:33:24 ----A---- C:\Windows\SYSWOW64\fsutil.exe
2011-04-28 06:33:24 ----A---- C:\Windows\system32\fsutil.exe
2011-04-28 06:33:16 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2011-04-28 06:33:16 ----A---- C:\Windows\system32\prevhost.exe
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmpA100.tmp
2011-04-16 01:40:18 ----RA---- C:\Windows\SYSWOW64\tmp8FD2.tmp
2011-04-15 20:28:26 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-04-15 20:28:26 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\vbscript.dll
2011-04-15 20:28:24 ----A---- C:\Windows\system32\jscript.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42u.dll
2011-04-15 20:28:20 ----A---- C:\Windows\system32\mfc42.dll
2011-04-15 20:28:11 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-04-15 20:28:11 ----A---- C:\Windows\system32\atmfd.dll
2011-04-15 20:28:10 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-04-15 20:28:10 ----A---- C:\Windows\system32\atmlib.dll
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-04-15 20:27:38 ----A---- C:\Windows\system32\dnsapi.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winresume.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\winload.exe
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdusb.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kdcom.dll
2011-04-15 20:27:35 ----A---- C:\Windows\system32\kd1394.dll
2011-04-15 20:27:34 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-04-15 20:27:32 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-04-12 12:46:12 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-04-09 18:55:44 ----A---- C:\Windows\SYSWOW64\xlive.dll
2011-04-09 18:55:42 ----A---- C:\Windows\SYSWOW64\xlivefnt.dll
2011-04-09 18:55:28 ----A---- C:\Windows\SYSWOW64\xlive.dll.cat
2011-04-09 16:06:56 ----D---- C:\ProgramData\Electronic Arts
2011-04-09 16:06:56 ----D---- C:\ProgramData\EA Core
2011-04-08 16:24:21 ----A---- C:\Windows\system32\drivers\atksgt.sys
2011-04-08 16:24:18 ----A---- C:\Windows\system32\drivers\lirsgt.sys
2011-04-08 16:24:17 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2011-04-08 16:20:57 ----D---- C:\Program Files (x86)\Deep Silver
2011-04-05 15:47:32 ----D---- C:\Program Files (x86)\Crysis 2
2011-03-27 12:47:46 ----D---- C:\Users\PC\AppData\Roaming\The Creative Assembly
2011-03-27 12:31:03 ----D---- C:\Program Files (x86)\Total War Shogun 2
2011-03-27 12:18:13 ----D---- C:\Program Files (x86)\ Total War Shogun 2
2011-03-23 16:37:32 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2011-03-23 16:37:30 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2011-03-23 16:37:28 ----D---- C:\Users\PC\AppData\Roaming\PunkBuster

======List of files/folders modified in the last 3 months======

2011-06-21 15:28:13 ----D---- C:\Windows\Prefetch
2011-06-21 15:28:12 ----D---- C:\Windows\Temp
2011-06-21 15:27:32 ----D---- C:\Windows\System32
2011-06-21 15:27:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-06-21 15:27:31 ----D---- C:\Windows\inf
2011-06-21 15:24:55 ----D---- C:\Windows\system32\catroot2
2011-06-21 15:23:21 ----D---- C:\ProgramData\NVIDIA
2011-06-21 15:22:30 ----D---- C:\Windows\system32\config
2011-06-21 15:20:32 ----D---- C:\Users\PC\AppData\Roaming\Skype
2011-06-21 15:18:33 ----D---- C:\Users\PC\AppData\Roaming\skypePM
2011-06-21 14:37:58 ----D---- C:\Program Files (x86)\World of Warcraft
2011-06-21 13:05:37 ----SHD---- C:\System Volume Information
2011-06-20 16:38:50 ----SHD---- C:\Windows\Installer
2011-06-20 16:38:42 ----RD---- C:\Program Files (x86)
2011-06-20 16:38:42 ----D---- C:\Program Files (x86)\Common Files
2011-06-20 16:38:39 ----D---- C:\ProgramData\Adobe
2011-06-20 16:38:16 ----D---- C:\Windows\SysWOW64
2011-06-18 15:07:47 ----HD---- C:\ProgramData
2011-06-18 15:01:38 ----D---- C:\Program Files (x86)\Microsoft
2011-06-18 14:59:52 ----D---- C:\Windows\system32\Tasks
2011-06-17 23:19:33 ----D---- C:\Windows\winsxs
2011-06-17 22:33:05 ----RSD---- C:\Windows\assembly
2011-06-17 18:36:17 ----RD---- C:\Program Files
2011-06-16 20:16:59 ----D---- C:\Windows\Microsoft.NET
2011-06-15 19:27:04 ----D---- C:\Windows\system32\drivers
2011-06-15 19:27:03 ----D---- C:\Windows\SYSWOW64\migration
2011-06-15 19:27:03 ----D---- C:\Windows\system32\migration
2011-06-15 19:27:03 ----D---- C:\Program Files\Internet Explorer
2011-06-15 19:27:03 ----D---- C:\Program Files (x86)\Internet Explorer
2011-06-15 15:16:47 ----A---- C:\Windows\system32\MRT.exe
2011-06-15 14:53:52 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-06-15 06:44:24 ----D---- C:\Windows\system32\catroot
2011-06-14 16:46:45 ----D---- C:\Users\PC\AppData\Roaming\TS3Client
2011-06-12 18:38:15 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2011-06-06 06:19:14 ----D---- C:\Windows
2011-06-05 21:57:33 ----D---- C:\Windows\system32\DriverStore
2011-06-05 19:54:10 ----SD---- C:\ProgramData\Microsoft
2011-06-02 18:51:30 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-05-28 11:44:25 ----D---- C:\Windows\Tasks
2011-05-27 17:50:10 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-05-26 21:18:10 ----D---- C:\Windows\Logs
2011-05-24 19:14:10 ----N---- C:\Windows\system32\MpSigStub.exe
2011-05-10 14:10:55 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-05-10 14:10:44 ----A---- C:\Windows\system32\aswBoot.exe
2011-05-07 19:38:25 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-05-03 20:12:58 ----D---- C:\Users\PC\AppData\Roaming\Ubisoft
2011-05-02 20:23:17 ----D---- C:\Windows\rescache
2011-05-01 21:20:30 ----SD---- C:\Users\PC\AppData\Roaming\Microsoft
2011-04-28 15:37:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\system32\cs-CZ
2011-04-28 15:37:27 ----D---- C:\Windows\AppPatch
2011-04-16 18:56:37 ----D---- C:\Windows\system32\wdi
2011-04-16 08:23:28 ----D---- C:\Windows\system32\Boot
2011-03-23 16:38:21 ----D---- C:\ProgramData\Ubisoft
2011-03-23 16:37:29 ----D---- C:\Windows\system32\LogFiles
2011-03-23 16:29:21 ----D---- C:\Program Files (x86)\Ubisoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 287576]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 53592]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-02-06 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 64344]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-04-08 314016]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-04-08 43680]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-02-23 1847296]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2010-11-12 155752]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-11-25 1276928]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 cpuz134;cpuz134; \??\C:\Users\PC\AppData\Local\Temp\cpuz134\cpuz134_x64.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\Windows\system32\DRIVERS\s1039bus.sys [2009-11-19 127600]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1039mdfl.sys [2009-11-19 19568]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1039mdm.sys [2009-11-19 161904]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1039mgmt.sys [2009-11-19 141424]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1039nd5.sys [2009-11-19 34416]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1039obex.sys [2009-11-19 137328]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1039unic.sys [2009-11-19 158320]
S3 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-05-10 42184]
R2 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-02-23 1005160]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2011-05-03 75136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-05 1255736]

-----------------EOF-----------------

Uživatelský avatar
Danstahr
Přítel fóra
Přítel fóra
Příspěvky: 1069
Registrován: 28 říj 2006 20:23
Bydliště: Londýn
Kontaktovat uživatele:

Re: Problém, preventivní kontrola

#11 Příspěvek od Danstahr »

Log už se zdá být čistý a bez zbytečných blbinek. Jak je na tom PC?

Ještě doklepneme údržbu :

:arrow: Stáhněte CCleaner, nainstalujte a spusťte.
  • Na záložce Čistič stiskněte tlačítko Spustit Cleaner
  • Po provedení přepněte na záložku Registry, stiskněte Hledej problémy a poté Opravit vybrané problémy. Opakujte, dokud nebude po hledání problémů seznam prázdný.
:arrow: Stáhněte a spusťte TFC a dejte Start. Po použití smažte.
Koupím trochu času, cenu respektuji.

zody
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 17 čer 2011 17:22

Re: Problém, preventivní kontrola

#12 Příspěvek od zody »

Program přestal zabírat tolik Fyzické paměti a velice se mi zvětšil výkon PC mnohokrát děkuji za váš čas a pomoc. :cap:

Uživatelský avatar
Danstahr
Přítel fóra
Přítel fóra
Příspěvky: 1069
Registrován: 28 říj 2006 20:23
Bydliště: Londýn
Kontaktovat uživatele:

Re: Problém, preventivní kontrola

#13 Příspěvek od Danstahr »

Není zač, rád jsem pomohl! Zase někdy (snad jen v preventivkách) :bye:
Koupím trochu času, cenu respektuji.

Odpovědět