Rootkit? Zpomalený PC a podivné chování
Napsal: 18 črc 2010 14:18
Zdravím, přicházím s mírně problémovým PC, tentokrát je to můj (pořád nic proti tomu, co občas vídám, ale začíná mě to znervózňovat). Počítač se mi zdá být oproti normálu zpomalený, dneska, když jsem se pokoušel zadat do adresního řádku Chromu "the avenger", hodil BSoD (nemůžu se k těm informacím dostat) a nyní mám kurzívu v Google Chrome a Steamu. Mám podezření na rootkit, podívejte se:
AVG Anti-Rootkit Free:
C:\Windows\System32\Drivers\aufbwt25.SYS,Hidden driver file
C:\Windows\System32\Drivers\azwpvfwd.SYS,Hidden driver file
Abych to udělal zajímavější, GMER spadne chvíli po spuštění. Prosím pěkně o pomoc a vyčištění PC. Děkuju předem!
RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Pavel at 2010-07-18 13:59:42
Microsoft Windows 7 Ultimate
System drive C: has 11 GB (17%) free of 65 GB
Total RAM: 1023 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:00:05, on 18.7.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\V0420Mon.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\LifeView MVP\RemoteControl.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\OO Software\Defrag\oodtray.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exe
C:\Program Files\Launchy\Launchy.exe
C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Users\Pavel\Desktop\RSIT.exe
C:\Program Files\trend micro\Pavel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [V0420Mon.exe] C:\Windows\V0420Mon.exe
O4 - HKLM\..\Run: [C:\Windows\system32\V0420Ext.ax] C:\Windows\system32\RegSvr32.exe /s C:\Windows\system32\V0420Ext.ax
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [UpdatePDRShortCut] "E:\Program Files\CyberLink\PowerDirector\PowerDirector\MUITransfer\MUIStartMenu.exe" "E:\Program Files\CyberLink\PowerDirector\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [DTVRemote] "C:\Program Files\LifeView MVP\RemoteControl.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "e:\hry\steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: iReboot 1.1.1.lnk = C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exe
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O8 - Extra context menu item: Download all by FlashGet3 - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
O8 - Extra context menu item: Download by FlashGet3 - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\GetUrl.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O15 - Trusted Zone: http://software.kuaiche.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0019C12E-4FF2-46B8-B5FB-A6D2D934B8CA}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0019C12E-4FF2-46B8-B5FB-A6D2D934B8CA}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{0019C12E-4FF2-46B8-B5FB-A6D2D934B8CA}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Application Updater - Unknown owner - C:\Program Files\Application Updater\ApplicationUpdater.exe (file missing)
O23 - Service: Fast Multimedia Timer - Unknown owner - C:\Windows\system32\fmmtimersvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iReboot Background Service (iReboot) - Unknown owner - C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag Agent (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: ProgDVB Scheduler Service (ProgDVBService) - Unknown owner - C:\Program Files\ProgDVB\ProgDVBService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe
--
End of file - 8630 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1278905916-617490914-3079557870-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1278905916-617490914-3079557870-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0}]
FlashGetBHO - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll [2009-12-22 157232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-22 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"V0420Mon.exe"=C:\Windows\V0420Mon.exe [2007-04-30 32768]
"C:\Windows\system32\V0420Ext.ax"=C:\Windows\system32\RegSvr32.exe [2009-07-14 14848]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"UpdatePDRShortCut"=E:\Program Files\CyberLink\PowerDirector\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"BrMfcWnd"=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2009-05-26 1159168]
"ControlCenter3"=C:\Program Files\Brother\ControlCenter3\brctrcen.exe [2008-12-24 114688]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-29 7625248]
"DTVRemote"=C:\Program Files\LifeView MVP\RemoteControl.exe [2007-02-09 69632]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2010-05-11 2528584]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-28 136176]
"Steam"=e:\hry\steam\steam.exe [2010-05-09 1238352]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-05-13 26192168]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
iReboot 1.1.1.lnk - C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exe
Launchy.lnk - C:\Program Files\Launchy\Launchy.exe
C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-07-18 13:37:51 ----D---- C:\Program Files\trend micro
2010-07-18 13:37:50 ----D---- C:\rsit
2010-07-18 13:11:00 ----D---- C:\!KillBox
2010-07-18 13:06:42 ----D---- C:\Windows\system32\oodag
2010-07-18 13:03:12 ----D---- C:\Program Files\OO Software
2010-07-17 15:14:44 ----D---- C:\Program Files\Microsoft SSL ChainSaver
2010-07-16 09:22:52 ----D---- C:\Users\Pavel\AppData\Roaming\Launchy
2010-07-16 09:22:46 ----D---- C:\Program Files\Launchy
2010-07-14 19:42:26 ----D---- C:\Users\Pavel\AppData\Roaming\dvdcss
2010-07-13 21:17:59 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-13 21:17:35 ----D---- C:\Program Files\Windows Live
2010-07-13 21:14:13 ----D---- C:\Program Files\Common Files\Windows Live
2010-07-11 19:08:21 ----D---- C:\Extendir
2010-07-11 17:38:35 ----D---- C:\Users\Pavel\AppData\Roaming\Blender Foundation
2010-07-11 17:38:31 ----D---- C:\Program Files\Blender Foundation
2010-07-10 21:23:19 ----D---- C:\Users\Pavel\AppData\Roaming\Audacity
2010-07-10 21:23:03 ----D---- C:\Program Files\Audacity 1.3 Beta (Unicode)
2010-07-10 19:40:42 ----A---- C:\Windows\system32\drivers\AmdLLD.sys
2010-07-10 19:40:40 ----D---- C:\Program Files\AMD
2010-07-10 19:40:03 ----D---- C:\Windows\system32\AGEIA
2010-07-10 19:40:03 ----D---- C:\Program Files\AGEIA Technologies
2010-07-10 19:38:51 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-07-10 19:38:51 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XAudioD2_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XAPOFXD1_5.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XactEngineD3_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XactEngineA3_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\X3DAudioD1_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\D3dx9d_43.dll
2010-07-10 15:04:01 ----A---- C:\Windows\system32\d3dx9d_33.dll
2010-07-10 15:03:59 ----A---- C:\Windows\system32\D3DX11d_43.dll
2010-07-10 15:03:59 ----A---- C:\Windows\system32\D3DX10d_43.dll
2010-07-10 15:03:59 ----A---- C:\Windows\system32\d3dref9.dll
2010-07-10 15:03:58 ----A---- C:\Windows\system32\D3DCSXd_43.dll
2010-07-10 15:03:57 ----A---- C:\Windows\system32\d3d9d.dll
2010-07-10 15:03:55 ----A---- C:\Windows\system32\D3D11SDKLayers.dll
2010-07-10 15:03:54 ----A---- C:\Windows\system32\D3D11Ref.dll
2010-07-10 15:03:53 ----A---- C:\Windows\system32\D3D10SDKLayers.DLL
2010-07-10 15:03:53 ----A---- C:\Windows\system32\D3D10Ref.DLL
2010-07-10 15:02:30 ----A---- C:\Windows\system32\XAudio2_7.dll
2010-07-10 15:02:30 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\xactengine3_7.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\D3DX9_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\d3dx11_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\d3dx10_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\d3dcsx_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2010-07-10 14:59:34 ----A---- C:\Windows\dxsdkuninst.exe
2010-07-10 14:59:33 ----D---- C:\Program Files\Microsoft DirectX SDK (June 2010)
2010-07-10 13:36:10 ----D---- C:\Program Files\Microsoft Windows Performance Toolkit
2010-07-10 13:33:23 ----D---- C:\Program Files\Debugging Tools for Windows (x86)
2010-07-10 13:32:52 ----D---- C:\Program Files\Application Verifier
2010-07-10 12:43:31 ----D---- C:\ea975158002bb4c4a19cf7 – kopie
2010-07-09 23:52:27 ----D---- C:\Program Files\Windows Mobile 6.5.3 DTK
2010-07-09 23:08:37 ----D---- C:\Program Files\Windows Mobile 6 SDK
2010-07-09 21:03:18 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-07-09 20:47:04 ----D---- C:\Program Files\Microsoft Device Emulator
2010-07-09 20:46:38 ----D---- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2010-07-09 20:37:08 ----A---- C:\Windows\ODBC.INI
2010-07-09 20:23:45 ----D---- C:\Program Files\Common Files\Designer
2010-07-09 20:23:07 ----D---- C:\ProgramData\PreEmptive Solutions
2010-07-09 20:23:06 ----D---- C:\Program Files\HTML Help Workshop
2010-07-09 20:23:06 ----D---- C:\Program Files\Common Files\Business Objects
2010-07-09 20:23:06 ----D---- C:\Program Files\CE Remote Tools
2010-07-09 20:16:12 ----D---- C:\Program Files\Microsoft Office
2010-07-09 20:16:11 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-07-08 21:19:26 ----A---- C:\Windows\system32\RestoratorContextMenu.dll
2010-07-08 21:19:24 ----D---- C:\Program Files\Restorator 2007
2010-07-08 21:10:27 ----D---- C:\Program Files\XN Resource Editor
2010-07-08 08:19:47 ----D---- C:\Program Files\Minefield
2010-07-08 08:01:21 ----D---- C:\Program Files\Mozilla Firefox 4.0 Beta 1
2010-07-07 18:21:24 ----D---- C:\Flash
2010-07-06 19:38:03 ----D---- C:\License
2010-07-06 19:38:03 ----D---- C:\DirectX9
2010-07-06 19:38:03 ----D---- C:\Autorun
2010-07-06 12:02:21 ----D---- C:\MinGW
2010-07-06 11:44:48 ----A---- C:\Windows\system32\pywintypes26.dll
2010-07-06 11:44:48 ----A---- C:\Windows\system32\pythoncom26.dll
2010-07-06 11:42:00 ----D---- C:\Windows\symbols
2010-07-06 11:41:48 ----D---- C:\Program Files\Common Files\Merge Modules
2010-07-06 11:20:27 ----D---- C:\Python26
2010-07-05 22:05:20 ----D---- C:\Program Files\VisualSVN Server
2010-07-05 19:39:17 ----D---- C:\Program Files\Alcohol Soft
2010-07-05 18:43:03 ----A---- C:\Windows\system32\drivers\ezplay.sys
2010-07-05 18:43:03 ----A---- C:\Users\Pavel\AppData\Roaming\ezplay.sys
2010-07-05 18:43:03 ----A---- C:\Users\Pavel\AppData\Roaming\ezplay.ini
2010-07-05 18:41:43 ----D---- C:\Users\Pavel\AppData\Roaming\Vso
2010-07-05 18:41:43 ----A---- C:\Windows\system32\drivers\pcouffin.sys
2010-07-05 18:41:43 ----A---- C:\Users\Pavel\AppData\Roaming\pcouffin.sys
2010-07-05 18:41:43 ----A---- C:\Users\Pavel\AppData\Roaming\inst.exe
2010-07-05 18:41:26 ----D---- C:\Program Files\VSO
2010-06-30 14:48:39 ----D---- C:\Users\Pavel\AppData\Roaming\vlc
2010-06-30 14:48:02 ----D---- C:\Program Files\VideoLAN
2010-06-30 14:26:47 ----D---- C:\Program Files\ProgDVB
2010-06-30 14:25:52 ----D---- C:\ProgramData\ProgDVB
2010-06-30 10:20:34 ----D---- C:\Program Files\LifeView MVP
2010-06-29 10:51:38 ----D---- C:\Users\Pavel\AppData\Roaming\NVIDIA
2010-06-28 22:26:34 ----D---- C:\Program Files\SMPlayer
2010-06-28 11:36:30 ----D---- C:\Users\Pavel\AppData\Roaming\CDRoller
2010-06-28 11:36:28 ----D---- C:\Program Files\CDRoller
2010-06-28 10:57:53 ----D---- C:\Program Files\Smart Projects
2010-06-28 09:22:59 ----D---- C:\Windows\system32\RTCOM
2010-06-28 09:22:29 ----A---- C:\Windows\system32\WavesLib.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSWOW.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSTSXT.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSTSHD.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSHP360.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\RtkPgExt.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\RtkCoInst.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\RtkApoApi.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2010-06-28 09:22:28 ----D---- C:\Program Files\Realtek
2010-06-28 09:22:28 ----A---- C:\Windows\system32\RtkAPO.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\RP3DHT32.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\RP3DAA32.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\FMAPO.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\AERTARen.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\AERTACap.dll
2010-06-28 09:22:26 ----HD---- C:\Program Files\Temp
2010-06-28 09:22:26 ----A---- C:\Windows\RtlExUpd.dll
2010-06-28 09:22:02 ----A---- C:\Windows\Language_trs.ini
2010-06-27 16:02:42 ----A---- C:\Windows\system32\ntdll.dll
2010-06-27 16:02:34 ----A---- C:\Windows\system32\CPFilters.dll
2010-06-27 16:02:33 ----A---- C:\Windows\system32\msdri.dll
2010-06-26 22:01:01 ----D---- C:\Program Files\Ubisoft
2010-06-26 21:59:26 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-06-26 21:59:26 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-06-26 21:59:25 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-06-26 20:47:20 ----D---- C:\ProgramData\Apple Computer
2010-06-26 20:47:20 ----D---- C:\Program Files\QuickTime
2010-06-26 20:45:55 ----D---- C:\Program Files\Common Files\Apple
2010-06-26 20:45:27 ----D---- C:\Program Files\Apple Software Update
2010-06-25 18:45:06 ----D---- C:\Program Files\Internet Explorer Platform Preview
2010-06-25 18:39:44 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-06-25 18:39:44 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\FntCache.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\DWrite.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\d3d10warp.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\d2d1.dll
2010-06-25 18:38:22 ----A---- C:\Windows\system32\mfreadwrite.dll
2010-06-25 18:38:22 ----A---- C:\Windows\system32\mf.dll
2010-06-25 18:38:21 ----A---- C:\Windows\system32\WMVDECOD.DLL
2010-06-23 21:14:22 ----D---- C:\Users\Pavel\AppData\Roaming\TortoiseSVN
2010-06-23 21:08:50 ----D---- C:\Users\Pavel\AppData\Roaming\Subversion
2010-06-23 21:07:37 ----D---- C:\Program Files\TortoiseSVN
2010-06-23 21:07:37 ----D---- C:\Program Files\Common Files\TortoiseOverlays
2010-06-22 21:00:10 ----A---- C:\Windows\IsUninst.exe
2010-06-22 17:49:18 ----D---- C:\Program Files\CCleaner
2010-06-22 17:36:20 ----D---- C:\Program Files\Defraggler
2010-06-22 14:11:08 ----D---- C:\Users\Pavel\AppData\Roaming\Dropbox
2010-06-20 10:09:24 ----D---- C:\Windows\SUA
2010-06-19 17:40:45 ----D---- C:\Program Files\TagScanner
2010-06-19 12:26:34 ----A---- C:\Windows\system32\drivers\ext2fsd.sys
======List of files/folders modified in the last 1 months======
2010-07-18 13:56:49 ----D---- C:\Windows\Temp
2010-07-18 13:54:02 ----D---- C:\Windows\system32\config
2010-07-18 13:44:04 ----SHD---- C:\System Volume Information
2010-07-18 13:43:17 ----D---- C:\Windows\Prefetch
2010-07-18 13:41:11 ----SHD---- C:\Windows\Installer
2010-07-18 13:40:59 ----D---- C:\Windows\system32\drivers
2010-07-18 13:40:59 ----D---- C:\Windows\system32\catroot
2010-07-18 13:40:58 ----SD---- C:\ProgramData\Microsoft
2010-07-18 13:40:33 ----RD---- C:\Program Files
2010-07-18 13:28:42 ----D---- C:\Windows
2010-07-18 13:24:49 ----D---- C:\Windows\Minidump
2010-07-18 13:24:32 ----D---- C:\Windows\System32
2010-07-18 13:03:03 ----D---- C:\Windows\system32\catroot2
2010-07-17 15:22:31 ----D---- C:\Windows\inf
2010-07-17 15:22:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-16 17:10:22 ----RSD---- C:\Windows\assembly
2010-07-16 17:10:22 ----D---- C:\Windows\Microsoft.NET
2010-07-16 15:04:12 ----D---- C:\HammerAutosave
2010-07-14 10:24:58 ----D---- C:\Windows\debug
2010-07-13 21:29:00 ----D---- C:\Program Files\Microsoft
2010-07-13 21:18:05 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-13 21:16:05 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-07-13 21:14:13 ----D---- C:\Program Files\Common Files
2010-07-13 16:16:00 ----AD---- C:\ProgramData\TEMP
2010-07-13 00:04:51 ----D---- C:\Users\Pavel\AppData\Roaming\Skype
2010-07-12 23:40:52 ----D---- C:\Ervius Package Creation
2010-07-12 16:06:05 ----D---- C:\Users\Pavel\AppData\Roaming\skypePM
2010-07-12 12:30:50 ----D---- C:\Windows\LiveKernelReports
2010-07-11 18:41:18 ----D---- C:\Windows\system32\LogFiles
2010-07-10 22:51:15 ----D---- C:\Windows\system32\DriverStore
2010-07-10 20:48:21 ----D---- C:\Users\Pavel\AppData\Roaming\BITS
2010-07-10 19:39:45 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-10 15:00:19 ----D---- C:\ProgramData\Microsoft Help
2010-07-10 14:59:23 ----D---- C:\Windows\Logs
2010-07-10 13:04:32 ----D---- C:\Windows\winsxs
2010-07-10 12:03:16 ----D---- C:\Windows\system32\Tasks
2010-07-10 09:57:24 ----SD---- C:\Users\Pavel\AppData\Roaming\Microsoft
2010-07-09 22:41:45 ----D---- C:\Windows\system32\1033
2010-07-09 20:32:23 ----D---- C:\Windows\Help
2010-07-09 20:23:40 ----RSD---- C:\Windows\Fonts
2010-07-09 20:23:07 ----HD---- C:\ProgramData
2010-07-09 16:53:02 ----D---- C:\Program Files\Opera
2010-07-09 13:07:05 ----D---- C:\Users\Pavel\AppData\Roaming\gtk-2.0
2010-07-09 12:12:28 ----D---- C:\Program Files\Mozilla Thunderbird
2010-07-08 09:23:33 ----D---- C:\Windows\system32\NDF
2010-07-06 19:40:05 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-06 18:46:10 ----D---- C:\Downloads
2010-07-06 13:03:50 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2010-07-06 11:41:48 ----D---- C:\Program Files\MSBuild
2010-07-06 11:41:48 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2010-07-02 21:39:05 ----A---- C:\Windows\system32\MRT.exe
2010-07-02 18:42:08 ----D---- C:\Program Files\Common Files\Steam
2010-07-02 14:06:37 ----D---- C:\ProgramData\CyberLink
2010-06-29 08:15:31 ----D---- C:\Program Files\Microsoft SDKs
2010-06-28 21:59:08 ----D---- C:\Windows\Tasks
2010-06-28 20:54:11 ----AD---- C:\Program Files-second
2010-06-27 22:54:55 ----D---- C:\Windows\ehome
2010-06-27 16:04:03 ----D---- C:\Windows\AppPatch
2010-06-24 20:55:32 ----D---- C:\Users\Pavel\AppData\Roaming\Media Player Classic
2010-06-22 18:10:15 ----D---- C:\Windows\system32\appmgmt
2010-06-22 18:09:32 ----DC---- C:\Windows\system32\DRVSTORE
2010-06-22 18:06:48 ----D---- C:\Windows\ShellNew
2010-06-22 18:04:48 ----D---- C:\Program Files\Common Files\System
2010-06-22 18:04:46 ----A---- C:\Windows\win.ini
2010-06-22 16:03:18 ----D---- C:\Windows\Downloaded Program Files
2010-06-20 13:02:08 ----D---- C:\Windows\rescache
2010-06-20 10:09:24 ----D---- C:\Windows\system32\en-US
2010-06-20 10:09:24 ----D---- C:\Windows\system32\cs-CZ
2010-06-20 10:09:24 ----D---- C:\Windows\PolicyDefinitions
2010-06-20 10:09:24 ----D---- C:\Windows\en-US
2010-06-19 12:25:58 ----D---- C:\Program Files\Ext2Fsd
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-07-05 697328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 Ext2Fsd;Linux ext2 file system driver; C:\Windows\system32\drivers\Ext2Fsd.sys [2009-10-30 657280]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-12-31 295936]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller; C:\Windows\system32\DRIVERS\l260x86.sys [2009-07-14 29184]
R3 ezplay;VSO Software ezplay; C:\Windows\System32\Drivers\ezplay.sys [2010-07-05 94208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-29 2735504]
R3 LVMST;LVMST service; C:\Windows\system32\DRIVERS\LVMST.sys [2006-11-16 829312]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-07-05 47360]
R3 PsxDrv;@%systemroot%\system32\suares.dll,-107; C:\Windows\system32\drivers\psxdrv.sys [2009-07-14 9216]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
R3 StillCam;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
R3 V0420VID;Live! Cam Vista IM (VF0420); C:\Windows\system32\DRIVERS\V0420Vid.sys [2007-05-31 99648]
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 165376]
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 78336]
S3 a3m0nqvx;a3m0nqvx; C:\Windows\system32\drivers\a3m0nqvx.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 aktt5izp;aktt5izp; C:\Windows\system32\drivers\aktt5izp.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDISPM;RDPDISPM; C:\Windows\system32\DRIVERS\rdpdispm.sys [2010-06-06 9040]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 15872]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\Windows\system32\DRIVERS\wceusbsh.sys [2005-08-09 104576]
S3 ZSMC301b;USB WEBCAM; C:\Windows\System32\Drivers\usbVM31b.sys [2004-03-03 90534]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Fast Multimedia Timer;Fast Multimedia Timer; C:\Windows\system32\fmmtimersvc.exe [2007-06-27 6656]
R2 iReboot;iReboot Background Service; C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exe [2009-09-15 17408]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-04-03 129640]
R2 OODefragAgent;O&O Defrag Agent; C:\Program Files\OO Software\Defrag\oodag.exe [2010-05-11 1619272]
R2 ProgDVBService;ProgDVB Scheduler Service; C:\Program Files\ProgDVB\ProgDVBService.exe [2010-06-25 7680]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\Cyberlink\Shared files\RichVideo.exe [2009-04-17 247152]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 VisualSVNServer;VisualSVN Server; C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe [2010-04-24 23840]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-29 136176]
S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-07-02 395048]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-23 1343400]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
-----------------EOF-----------------
EDIT: Našel jsem tu zatracenou zprávu o BSoD
Podpis problému
Název události problému: BlueScreen
Verze operačního systému: 6.1.7600.2.0.0.256.1
ID národního prostředí: 1029
Další informace o tomto problému
BCCode: f4
BCP1: 00000003
BCP2: 857B7718
BCP3: 857B7884
BCP4: 82E34D90
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1
ID sady: 0xF4_C0000005_IMAGE_csrss.exe_Win7
Informace o serveru: 687e57b0-8dd8-4bf6-8dc0-51487a657d91
A ještě o pádu GMERu:
Popis
Cesta k chybující aplikaci: E:\Downloads\pw0su306.exe
Podpis problému
Název události problému: APPCRASH
Název aplikace: pw0su306.exe
Verze aplikace: 1.0.15.15281
Časové razítko aplikace: 4b2763f0
Název chybného modulu: pw0su306.exe
Verze chybného modulu: 1.0.15.15281
Časové razítko chybného modulu: 4b2763f0
Kód výjimky: c0000005
Posun výjimky: 0005c887
Verze operačního systému: 6.1.7600.2.0.0.256.1
ID národního prostředí: 1029
Další informace 1: 2609
Další informace 2: 2609570e3f803705f1bc6bd31216984b
Další informace 3: b7ae
Další informace 4: b7ae49a9cd64e3b328d09300410a6471
Další informace o tomto problému
ID sady: 1960634873
AVG Anti-Rootkit Free:
C:\Windows\System32\Drivers\aufbwt25.SYS,Hidden driver file
C:\Windows\System32\Drivers\azwpvfwd.SYS,Hidden driver file
Abych to udělal zajímavější, GMER spadne chvíli po spuštění. Prosím pěkně o pomoc a vyčištění PC. Děkuju předem!
RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Pavel at 2010-07-18 13:59:42
Microsoft Windows 7 Ultimate
System drive C: has 11 GB (17%) free of 65 GB
Total RAM: 1023 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:00:05, on 18.7.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\V0420Mon.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\LifeView MVP\RemoteControl.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\OO Software\Defrag\oodtray.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exe
C:\Program Files\Launchy\Launchy.exe
C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Users\Pavel\Desktop\RSIT.exe
C:\Program Files\trend micro\Pavel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [V0420Mon.exe] C:\Windows\V0420Mon.exe
O4 - HKLM\..\Run: [C:\Windows\system32\V0420Ext.ax] C:\Windows\system32\RegSvr32.exe /s C:\Windows\system32\V0420Ext.ax
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [UpdatePDRShortCut] "E:\Program Files\CyberLink\PowerDirector\PowerDirector\MUITransfer\MUIStartMenu.exe" "E:\Program Files\CyberLink\PowerDirector\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [DTVRemote] "C:\Program Files\LifeView MVP\RemoteControl.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "e:\hry\steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: iReboot 1.1.1.lnk = C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exe
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O8 - Extra context menu item: Download all by FlashGet3 - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
O8 - Extra context menu item: Download by FlashGet3 - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\GetUrl.htm
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O15 - Trusted Zone: http://software.kuaiche.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0019C12E-4FF2-46B8-B5FB-A6D2D934B8CA}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{0019C12E-4FF2-46B8-B5FB-A6D2D934B8CA}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{0019C12E-4FF2-46B8-B5FB-A6D2D934B8CA}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Application Updater - Unknown owner - C:\Program Files\Application Updater\ApplicationUpdater.exe (file missing)
O23 - Service: Fast Multimedia Timer - Unknown owner - C:\Windows\system32\fmmtimersvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iReboot Background Service (iReboot) - Unknown owner - C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag Agent (OODefragAgent) - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: ProgDVB Scheduler Service (ProgDVBService) - Unknown owner - C:\Program Files\ProgDVB\ProgDVBService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: VisualSVN Server (VisualSVNServer) - Apache Software Foundation - C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe
--
End of file - 8630 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1278905916-617490914-3079557870-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1278905916-617490914-3079557870-1001UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0}]
FlashGetBHO - C:\Users\Pavel\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll [2009-12-22 157232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-04-22 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"V0420Mon.exe"=C:\Windows\V0420Mon.exe [2007-04-30 32768]
"C:\Windows\system32\V0420Ext.ax"=C:\Windows\system32\RegSvr32.exe [2009-07-14 14848]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe []
"UpdatePDRShortCut"=E:\Program Files\CyberLink\PowerDirector\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"BrMfcWnd"=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2009-05-26 1159168]
"ControlCenter3"=C:\Program Files\Brother\ControlCenter3\brctrcen.exe [2008-12-24 114688]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-29 7625248]
"DTVRemote"=C:\Program Files\LifeView MVP\RemoteControl.exe [2007-02-09 69632]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2010-05-11 2528584]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1093208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-28 136176]
"Steam"=e:\hry\steam\steam.exe [2010-05-09 1238352]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2010-05-13 26192168]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
iReboot 1.1.1.lnk - C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exe
Launchy.lnk - C:\Program Files\Launchy\Launchy.exe
C:\Users\Pavel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Pavel\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-07-18 13:37:51 ----D---- C:\Program Files\trend micro
2010-07-18 13:37:50 ----D---- C:\rsit
2010-07-18 13:11:00 ----D---- C:\!KillBox
2010-07-18 13:06:42 ----D---- C:\Windows\system32\oodag
2010-07-18 13:03:12 ----D---- C:\Program Files\OO Software
2010-07-17 15:14:44 ----D---- C:\Program Files\Microsoft SSL ChainSaver
2010-07-16 09:22:52 ----D---- C:\Users\Pavel\AppData\Roaming\Launchy
2010-07-16 09:22:46 ----D---- C:\Program Files\Launchy
2010-07-14 19:42:26 ----D---- C:\Users\Pavel\AppData\Roaming\dvdcss
2010-07-13 21:17:59 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-13 21:17:35 ----D---- C:\Program Files\Windows Live
2010-07-13 21:14:13 ----D---- C:\Program Files\Common Files\Windows Live
2010-07-11 19:08:21 ----D---- C:\Extendir
2010-07-11 17:38:35 ----D---- C:\Users\Pavel\AppData\Roaming\Blender Foundation
2010-07-11 17:38:31 ----D---- C:\Program Files\Blender Foundation
2010-07-10 21:23:19 ----D---- C:\Users\Pavel\AppData\Roaming\Audacity
2010-07-10 21:23:03 ----D---- C:\Program Files\Audacity 1.3 Beta (Unicode)
2010-07-10 19:40:42 ----A---- C:\Windows\system32\drivers\AmdLLD.sys
2010-07-10 19:40:40 ----D---- C:\Program Files\AMD
2010-07-10 19:40:03 ----D---- C:\Windows\system32\AGEIA
2010-07-10 19:40:03 ----D---- C:\Program Files\AGEIA Technologies
2010-07-10 19:38:51 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-07-10 19:38:51 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XAudioD2_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XAPOFXD1_5.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XactEngineD3_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\XactEngineA3_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\X3DAudioD1_7.dll
2010-07-10 15:04:02 ----A---- C:\Windows\system32\D3dx9d_43.dll
2010-07-10 15:04:01 ----A---- C:\Windows\system32\d3dx9d_33.dll
2010-07-10 15:03:59 ----A---- C:\Windows\system32\D3DX11d_43.dll
2010-07-10 15:03:59 ----A---- C:\Windows\system32\D3DX10d_43.dll
2010-07-10 15:03:59 ----A---- C:\Windows\system32\d3dref9.dll
2010-07-10 15:03:58 ----A---- C:\Windows\system32\D3DCSXd_43.dll
2010-07-10 15:03:57 ----A---- C:\Windows\system32\d3d9d.dll
2010-07-10 15:03:55 ----A---- C:\Windows\system32\D3D11SDKLayers.dll
2010-07-10 15:03:54 ----A---- C:\Windows\system32\D3D11Ref.dll
2010-07-10 15:03:53 ----A---- C:\Windows\system32\D3D10SDKLayers.DLL
2010-07-10 15:03:53 ----A---- C:\Windows\system32\D3D10Ref.DLL
2010-07-10 15:02:30 ----A---- C:\Windows\system32\XAudio2_7.dll
2010-07-10 15:02:30 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\xactengine3_7.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\D3DX9_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\d3dx11_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\d3dx10_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\d3dcsx_43.dll
2010-07-10 15:02:29 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2010-07-10 14:59:34 ----A---- C:\Windows\dxsdkuninst.exe
2010-07-10 14:59:33 ----D---- C:\Program Files\Microsoft DirectX SDK (June 2010)
2010-07-10 13:36:10 ----D---- C:\Program Files\Microsoft Windows Performance Toolkit
2010-07-10 13:33:23 ----D---- C:\Program Files\Debugging Tools for Windows (x86)
2010-07-10 13:32:52 ----D---- C:\Program Files\Application Verifier
2010-07-10 12:43:31 ----D---- C:\ea975158002bb4c4a19cf7 – kopie
2010-07-09 23:52:27 ----D---- C:\Program Files\Windows Mobile 6.5.3 DTK
2010-07-09 23:08:37 ----D---- C:\Program Files\Windows Mobile 6 SDK
2010-07-09 21:03:18 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-07-09 20:47:04 ----D---- C:\Program Files\Microsoft Device Emulator
2010-07-09 20:46:38 ----D---- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2010-07-09 20:37:08 ----A---- C:\Windows\ODBC.INI
2010-07-09 20:23:45 ----D---- C:\Program Files\Common Files\Designer
2010-07-09 20:23:07 ----D---- C:\ProgramData\PreEmptive Solutions
2010-07-09 20:23:06 ----D---- C:\Program Files\HTML Help Workshop
2010-07-09 20:23:06 ----D---- C:\Program Files\Common Files\Business Objects
2010-07-09 20:23:06 ----D---- C:\Program Files\CE Remote Tools
2010-07-09 20:16:12 ----D---- C:\Program Files\Microsoft Office
2010-07-09 20:16:11 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-07-08 21:19:26 ----A---- C:\Windows\system32\RestoratorContextMenu.dll
2010-07-08 21:19:24 ----D---- C:\Program Files\Restorator 2007
2010-07-08 21:10:27 ----D---- C:\Program Files\XN Resource Editor
2010-07-08 08:19:47 ----D---- C:\Program Files\Minefield
2010-07-08 08:01:21 ----D---- C:\Program Files\Mozilla Firefox 4.0 Beta 1
2010-07-07 18:21:24 ----D---- C:\Flash
2010-07-06 19:38:03 ----D---- C:\License
2010-07-06 19:38:03 ----D---- C:\DirectX9
2010-07-06 19:38:03 ----D---- C:\Autorun
2010-07-06 12:02:21 ----D---- C:\MinGW
2010-07-06 11:44:48 ----A---- C:\Windows\system32\pywintypes26.dll
2010-07-06 11:44:48 ----A---- C:\Windows\system32\pythoncom26.dll
2010-07-06 11:42:00 ----D---- C:\Windows\symbols
2010-07-06 11:41:48 ----D---- C:\Program Files\Common Files\Merge Modules
2010-07-06 11:20:27 ----D---- C:\Python26
2010-07-05 22:05:20 ----D---- C:\Program Files\VisualSVN Server
2010-07-05 19:39:17 ----D---- C:\Program Files\Alcohol Soft
2010-07-05 18:43:03 ----A---- C:\Windows\system32\drivers\ezplay.sys
2010-07-05 18:43:03 ----A---- C:\Users\Pavel\AppData\Roaming\ezplay.sys
2010-07-05 18:43:03 ----A---- C:\Users\Pavel\AppData\Roaming\ezplay.ini
2010-07-05 18:41:43 ----D---- C:\Users\Pavel\AppData\Roaming\Vso
2010-07-05 18:41:43 ----A---- C:\Windows\system32\drivers\pcouffin.sys
2010-07-05 18:41:43 ----A---- C:\Users\Pavel\AppData\Roaming\pcouffin.sys
2010-07-05 18:41:43 ----A---- C:\Users\Pavel\AppData\Roaming\inst.exe
2010-07-05 18:41:26 ----D---- C:\Program Files\VSO
2010-06-30 14:48:39 ----D---- C:\Users\Pavel\AppData\Roaming\vlc
2010-06-30 14:48:02 ----D---- C:\Program Files\VideoLAN
2010-06-30 14:26:47 ----D---- C:\Program Files\ProgDVB
2010-06-30 14:25:52 ----D---- C:\ProgramData\ProgDVB
2010-06-30 10:20:34 ----D---- C:\Program Files\LifeView MVP
2010-06-29 10:51:38 ----D---- C:\Users\Pavel\AppData\Roaming\NVIDIA
2010-06-28 22:26:34 ----D---- C:\Program Files\SMPlayer
2010-06-28 11:36:30 ----D---- C:\Users\Pavel\AppData\Roaming\CDRoller
2010-06-28 11:36:28 ----D---- C:\Program Files\CDRoller
2010-06-28 10:57:53 ----D---- C:\Program Files\Smart Projects
2010-06-28 09:22:59 ----D---- C:\Windows\system32\RTCOM
2010-06-28 09:22:29 ----A---- C:\Windows\system32\WavesLib.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSWOW.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSTSXT.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSTSHD.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\SRSHP360.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\RtkPgExt.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\RtkCoInst.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\RtkApoApi.dll
2010-06-28 09:22:29 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2010-06-28 09:22:28 ----D---- C:\Program Files\Realtek
2010-06-28 09:22:28 ----A---- C:\Windows\system32\RtkAPO.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\RP3DHT32.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\RP3DAA32.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\MaxxAudioAPO.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\FMAPO.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\AERTARen.dll
2010-06-28 09:22:28 ----A---- C:\Windows\system32\AERTACap.dll
2010-06-28 09:22:26 ----HD---- C:\Program Files\Temp
2010-06-28 09:22:26 ----A---- C:\Windows\RtlExUpd.dll
2010-06-28 09:22:02 ----A---- C:\Windows\Language_trs.ini
2010-06-27 16:02:42 ----A---- C:\Windows\system32\ntdll.dll
2010-06-27 16:02:34 ----A---- C:\Windows\system32\CPFilters.dll
2010-06-27 16:02:33 ----A---- C:\Windows\system32\msdri.dll
2010-06-26 22:01:01 ----D---- C:\Program Files\Ubisoft
2010-06-26 21:59:26 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-06-26 21:59:26 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-06-26 21:59:25 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-06-26 20:47:20 ----D---- C:\ProgramData\Apple Computer
2010-06-26 20:47:20 ----D---- C:\Program Files\QuickTime
2010-06-26 20:45:55 ----D---- C:\Program Files\Common Files\Apple
2010-06-26 20:45:27 ----D---- C:\Program Files\Apple Software Update
2010-06-25 18:45:06 ----D---- C:\Program Files\Internet Explorer Platform Preview
2010-06-25 18:39:44 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-06-25 18:39:44 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\FntCache.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\DWrite.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\d3d10warp.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-06-25 18:39:07 ----A---- C:\Windows\system32\d2d1.dll
2010-06-25 18:38:22 ----A---- C:\Windows\system32\mfreadwrite.dll
2010-06-25 18:38:22 ----A---- C:\Windows\system32\mf.dll
2010-06-25 18:38:21 ----A---- C:\Windows\system32\WMVDECOD.DLL
2010-06-23 21:14:22 ----D---- C:\Users\Pavel\AppData\Roaming\TortoiseSVN
2010-06-23 21:08:50 ----D---- C:\Users\Pavel\AppData\Roaming\Subversion
2010-06-23 21:07:37 ----D---- C:\Program Files\TortoiseSVN
2010-06-23 21:07:37 ----D---- C:\Program Files\Common Files\TortoiseOverlays
2010-06-22 21:00:10 ----A---- C:\Windows\IsUninst.exe
2010-06-22 17:49:18 ----D---- C:\Program Files\CCleaner
2010-06-22 17:36:20 ----D---- C:\Program Files\Defraggler
2010-06-22 14:11:08 ----D---- C:\Users\Pavel\AppData\Roaming\Dropbox
2010-06-20 10:09:24 ----D---- C:\Windows\SUA
2010-06-19 17:40:45 ----D---- C:\Program Files\TagScanner
2010-06-19 12:26:34 ----A---- C:\Windows\system32\drivers\ext2fsd.sys
======List of files/folders modified in the last 1 months======
2010-07-18 13:56:49 ----D---- C:\Windows\Temp
2010-07-18 13:54:02 ----D---- C:\Windows\system32\config
2010-07-18 13:44:04 ----SHD---- C:\System Volume Information
2010-07-18 13:43:17 ----D---- C:\Windows\Prefetch
2010-07-18 13:41:11 ----SHD---- C:\Windows\Installer
2010-07-18 13:40:59 ----D---- C:\Windows\system32\drivers
2010-07-18 13:40:59 ----D---- C:\Windows\system32\catroot
2010-07-18 13:40:58 ----SD---- C:\ProgramData\Microsoft
2010-07-18 13:40:33 ----RD---- C:\Program Files
2010-07-18 13:28:42 ----D---- C:\Windows
2010-07-18 13:24:49 ----D---- C:\Windows\Minidump
2010-07-18 13:24:32 ----D---- C:\Windows\System32
2010-07-18 13:03:03 ----D---- C:\Windows\system32\catroot2
2010-07-17 15:22:31 ----D---- C:\Windows\inf
2010-07-17 15:22:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-16 17:10:22 ----RSD---- C:\Windows\assembly
2010-07-16 17:10:22 ----D---- C:\Windows\Microsoft.NET
2010-07-16 15:04:12 ----D---- C:\HammerAutosave
2010-07-14 10:24:58 ----D---- C:\Windows\debug
2010-07-13 21:29:00 ----D---- C:\Program Files\Microsoft
2010-07-13 21:18:05 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-13 21:16:05 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-07-13 21:14:13 ----D---- C:\Program Files\Common Files
2010-07-13 16:16:00 ----AD---- C:\ProgramData\TEMP
2010-07-13 00:04:51 ----D---- C:\Users\Pavel\AppData\Roaming\Skype
2010-07-12 23:40:52 ----D---- C:\Ervius Package Creation
2010-07-12 16:06:05 ----D---- C:\Users\Pavel\AppData\Roaming\skypePM
2010-07-12 12:30:50 ----D---- C:\Windows\LiveKernelReports
2010-07-11 18:41:18 ----D---- C:\Windows\system32\LogFiles
2010-07-10 22:51:15 ----D---- C:\Windows\system32\DriverStore
2010-07-10 20:48:21 ----D---- C:\Users\Pavel\AppData\Roaming\BITS
2010-07-10 19:39:45 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-10 15:00:19 ----D---- C:\ProgramData\Microsoft Help
2010-07-10 14:59:23 ----D---- C:\Windows\Logs
2010-07-10 13:04:32 ----D---- C:\Windows\winsxs
2010-07-10 12:03:16 ----D---- C:\Windows\system32\Tasks
2010-07-10 09:57:24 ----SD---- C:\Users\Pavel\AppData\Roaming\Microsoft
2010-07-09 22:41:45 ----D---- C:\Windows\system32\1033
2010-07-09 20:32:23 ----D---- C:\Windows\Help
2010-07-09 20:23:40 ----RSD---- C:\Windows\Fonts
2010-07-09 20:23:07 ----HD---- C:\ProgramData
2010-07-09 16:53:02 ----D---- C:\Program Files\Opera
2010-07-09 13:07:05 ----D---- C:\Users\Pavel\AppData\Roaming\gtk-2.0
2010-07-09 12:12:28 ----D---- C:\Program Files\Mozilla Thunderbird
2010-07-08 09:23:33 ----D---- C:\Windows\system32\NDF
2010-07-06 19:40:05 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-06 18:46:10 ----D---- C:\Downloads
2010-07-06 13:03:50 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2010-07-06 11:41:48 ----D---- C:\Program Files\MSBuild
2010-07-06 11:41:48 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2010-07-02 21:39:05 ----A---- C:\Windows\system32\MRT.exe
2010-07-02 18:42:08 ----D---- C:\Program Files\Common Files\Steam
2010-07-02 14:06:37 ----D---- C:\ProgramData\CyberLink
2010-06-29 08:15:31 ----D---- C:\Program Files\Microsoft SDKs
2010-06-28 21:59:08 ----D---- C:\Windows\Tasks
2010-06-28 20:54:11 ----AD---- C:\Program Files-second
2010-06-27 22:54:55 ----D---- C:\Windows\ehome
2010-06-27 16:04:03 ----D---- C:\Windows\AppPatch
2010-06-24 20:55:32 ----D---- C:\Users\Pavel\AppData\Roaming\Media Player Classic
2010-06-22 18:10:15 ----D---- C:\Windows\system32\appmgmt
2010-06-22 18:09:32 ----DC---- C:\Windows\system32\DRVSTORE
2010-06-22 18:06:48 ----D---- C:\Windows\ShellNew
2010-06-22 18:04:48 ----D---- C:\Program Files\Common Files\System
2010-06-22 18:04:46 ----A---- C:\Windows\win.ini
2010-06-22 16:03:18 ----D---- C:\Windows\Downloaded Program Files
2010-06-20 13:02:08 ----D---- C:\Windows\rescache
2010-06-20 10:09:24 ----D---- C:\Windows\system32\en-US
2010-06-20 10:09:24 ----D---- C:\Windows\system32\cs-CZ
2010-06-20 10:09:24 ----D---- C:\Windows\PolicyDefinitions
2010-06-20 10:09:24 ----D---- C:\Windows\en-US
2010-06-19 12:25:58 ----D---- C:\Program Files\Ext2Fsd
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-07-05 697328]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 Ext2Fsd;Linux ext2 file system driver; C:\Windows\system32\drivers\Ext2Fsd.sys [2009-10-30 657280]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-12-31 295936]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 AmdLLD;AMD Low Level Device Driver; C:\Windows\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 Atc002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller; C:\Windows\system32\DRIVERS\l260x86.sys [2009-07-14 29184]
R3 ezplay;VSO Software ezplay; C:\Windows\System32\Drivers\ezplay.sys [2010-07-05 94208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-29 2735504]
R3 LVMST;LVMST service; C:\Windows\system32\DRIVERS\LVMST.sys [2006-11-16 829312]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-07-05 47360]
R3 PsxDrv;@%systemroot%\system32\suares.dll,-107; C:\Windows\system32\drivers\psxdrv.sys [2009-07-14 9216]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
R3 StillCam;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 9216]
R3 V0420VID;Live! Cam Vista IM (VF0420); C:\Windows\system32\DRIVERS\V0420Vid.sys [2007-05-31 99648]
R3 vpcbus;Virtual PC Host Bus Service; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 165376]
R3 vpcusb;USB Virtualization Connector Service; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 78336]
S3 a3m0nqvx;a3m0nqvx; C:\Windows\system32\drivers\a3m0nqvx.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 aktt5izp;aktt5izp; C:\Windows\system32\drivers\aktt5izp.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDISPM;RDPDISPM; C:\Windows\system32\DRIVERS\rdpdispm.sys [2010-06-06 9040]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 15872]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\Windows\system32\DRIVERS\wceusbsh.sys [2005-08-09 104576]
S3 ZSMC301b;USB WEBCAM; C:\Windows\System32\Drivers\usbVM31b.sys [2004-03-03 90534]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Fast Multimedia Timer;Fast Multimedia Timer; C:\Windows\system32\fmmtimersvc.exe [2007-06-27 6656]
R2 iReboot;iReboot Background Service; C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exe [2009-09-15 17408]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-04-03 129640]
R2 OODefragAgent;O&O Defrag Agent; C:\Program Files\OO Software\Defrag\oodag.exe [2010-05-11 1619272]
R2 ProgDVBService;ProgDVB Scheduler Service; C:\Program Files\ProgDVB\ProgDVBService.exe [2010-06-25 7680]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\Cyberlink\Shared files\RichVideo.exe [2009-04-17 247152]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
R2 VisualSVNServer;VisualSVN Server; C:\Program Files\VisualSVN Server\bin\VisualSVNServer.exe [2010-04-24 23840]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-29 136176]
S2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 43010392]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 MatSvc;@%ProgramFiles%\Microsoft Fix it Center\MatsRes.dll,-9000; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-07-02 395048]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-23 1343400]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
-----------------EOF-----------------
EDIT: Našel jsem tu zatracenou zprávu o BSoD

Podpis problému
Název události problému: BlueScreen
Verze operačního systému: 6.1.7600.2.0.0.256.1
ID národního prostředí: 1029
Další informace o tomto problému
BCCode: f4
BCP1: 00000003
BCP2: 857B7718
BCP3: 857B7884
BCP4: 82E34D90
OS Version: 6_1_7600
Service Pack: 0_0
Product: 256_1
ID sady: 0xF4_C0000005_IMAGE_csrss.exe_Win7
Informace o serveru: 687e57b0-8dd8-4bf6-8dc0-51487a657d91
A ještě o pádu GMERu:
Popis
Cesta k chybující aplikaci: E:\Downloads\pw0su306.exe
Podpis problému
Název události problému: APPCRASH
Název aplikace: pw0su306.exe
Verze aplikace: 1.0.15.15281
Časové razítko aplikace: 4b2763f0
Název chybného modulu: pw0su306.exe
Verze chybného modulu: 1.0.15.15281
Časové razítko chybného modulu: 4b2763f0
Kód výjimky: c0000005
Posun výjimky: 0005c887
Verze operačního systému: 6.1.7600.2.0.0.256.1
ID národního prostředí: 1029
Další informace 1: 2609
Další informace 2: 2609570e3f803705f1bc6bd31216984b
Další informace 3: b7ae
Další informace 4: b7ae49a9cd64e3b328d09300410a6471
Další informace o tomto problému
ID sady: 1960634873