W7 problem s casem a dalsi
Napsal: 22 črc 2010 10:57
Dobry den. Prosim o kontrolu logu RSIT. V PC dnes po spusteni bezi vse velmi rychle. Vlastni hodiny, ale zrychlene jsou i procesy. Neda se udelat double click, nestihne se provest obnova sytemu pred vyprsenim casoveho limitu atp. Nekolika nasobny restart nepomohl. PC nyni nema pripojeni na internet. Vse se musi prenaset pres flashku na NTB.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Karel at 2010-07-22 11:34:46
Microsoft Windows 7 Ultimate
System drive C: has 258 GB (85%) free of 304 GB
Total RAM: 4095 MB (73% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
C:\ASUS.SYS\config\DVMExportService.exe
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {C58FCEFE-E08D-4201-8AA7-87DCD4D79117}
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
C:\Windows\system32\spool\DRIVERS\x64\3\fpphelp3a.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\guardhlp.exe" GRD1
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000008b4
\??\C:\Windows\system32\conhost.exe
"D:\Data\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2010-05-07 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-06-19 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-06-19 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-06-01 8074184]
"pdfFactory Pro Dispatcher v3"=C:\Windows\system32\spool\DRIVERS\x64\3\fppdis3a.exe [2009-09-02 744448]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"= []
"Nektra OEAPI"= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"WEBTRAN"= []
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-07-19 2957040]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
""= []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-27 98304]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageMixer 3 SE Camera Monitor Ver.6.lnk - C:\Program Files (x86)\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0xB1000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe"="C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe"="C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\PROGRA~2\PSPADE~1\PSPad.exe "%1"
======List of files/folders created in the last 1 months======
2010-07-22 11:51:09 ----D---- C:\Program Files\trend micro
2010-07-22 11:50:57 ----D---- C:\rsit
2010-07-22 11:19:12 ----D---- C:\Users\Karel\AppData\Roaming\SUPERAntiSpyware.com
2010-07-22 11:19:12 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2010-07-22 11:15:30 ----D---- C:\ProgramData\!SASCORE
2010-07-22 11:13:37 ----D---- C:\Program Files\SUPERAntiSpyware
2010-07-22 10:45:41 ----D---- C:\32788R22FWJFW
2010-07-20 21:56:14 ----D---- C:\Program Files (x86)\PIXELA
2010-07-18 12:26:09 ----A---- C:\Program Files (x86)\MPC-HomeCinema.1.3.1249.0.(x86).exe
2010-07-14 19:16:34 ----A---- C:\Windows\system32\cdd.dll
2010-07-13 13:23:24 ----D---- C:\Users\Karel\AppData\Roaming\602XML
2010-07-13 13:23:22 ----D---- C:\Program Files (x86)\Software602
2010-07-13 13:06:35 ----D---- C:\Users\Karel\AppData\Roaming\Mozilla
2010-07-04 18:22:17 ----D---- C:\Downloads
2010-07-04 18:21:51 ----D---- C:\Users\Karel\AppData\Roaming\Orbit
2010-07-04 18:21:51 ----D---- C:\Program Files (x86)\Orbitdownloader
2010-07-04 18:04:32 ----A---- C:\Windows\libem.INI
2010-07-04 18:04:27 ----D---- C:\Users\Karel\AppData\Roaming\FlashGet
2010-07-04 18:04:26 ----D---- C:\Users\Karel\AppData\Roaming\BITS
2010-07-04 18:04:24 ----D---- C:\Users\Karel\AppData\Roaming\FlashGetBHO
2010-07-04 18:04:22 ----D---- C:\Program Files (x86)\FlashGet Network
2010-06-24 20:26:07 ----D---- C:\Program Files (x86)\Blu Ray Player
2010-06-24 20:15:18 ----D---- C:\Program Files (x86)\MPC HomeCinema
2010-06-24 20:07:06 ----D---- C:\Program Files\MPC
2010-06-24 15:03:30 ----D---- C:\Users\Karel\AppData\Roaming\Media Player Classic
2010-06-23 16:22:06 ----D---- C:\Users\Karel\AppData\Roaming\AntispamSniper
2010-06-23 15:55:07 ----D---- C:\Program Files (x86)\The KMPlayer
2010-06-23 14:16:10 ----D---- C:\Program Files (x86)\AntispamSniper for TheBat!
2010-06-23 14:00:17 ----D---- C:\Program Files (x86)\The Bat!
2010-06-23 11:39:50 ----D---- C:\Windows\WindowsMobile
2010-06-23 11:38:39 ----D---- C:\ProgramData\Windows Genuine Advantage
2010-06-23 10:27:53 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
======List of files/folders modified in the last 1 months======
2010-07-22 12:10:25 ----SHD---- C:\Windows\Installer
2010-07-22 12:10:18 ----D---- C:\Program Files (x86)\Ask.com
2010-07-22 12:08:42 ----D---- C:\Windows\Prefetch
2010-07-22 11:59:20 ----D---- C:\Windows\Temp
2010-07-22 11:56:19 ----D---- C:\Windows\system32\config
2010-07-22 11:51:09 ----RD---- C:\Program Files
2010-07-22 11:19:12 ----HD---- C:\ProgramData
2010-07-22 11:03:21 ----D---- C:\Windows\system32\NDF
2010-07-22 10:45:05 ----D---- C:\Windows\system32\Tasks
2010-07-22 10:21:33 ----D---- C:\Windows\System32
2010-07-22 10:21:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-22 10:21:29 ----D---- C:\Windows\inf
2010-07-22 10:04:22 ----D---- C:\Windows\debug
2010-07-22 10:03:40 ----AD---- C:\Windows
2010-07-22 10:02:34 ----D---- C:\Windows\system32\LogFiles
2010-07-22 09:52:50 ----SHD---- C:\System Volume Information
2010-07-22 09:41:31 ----D---- C:\Users\Karel\AppData\Roaming\Spyware Terminator
2010-07-22 09:26:40 ----D---- C:\Windows\system32\wdi
2010-07-21 23:45:48 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-07-21 21:53:26 ----A---- C:\Windows\cdplayer.ini
2010-07-21 21:24:34 ----D---- C:\Program Files (x86)\Opera
2010-07-20 22:05:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-07-20 21:56:14 ----RD---- C:\Program Files (x86)
2010-07-18 07:42:24 ----D---- C:\Users\Karel\AppData\Roaming\vlc
2010-07-17 20:27:34 ----D---- C:\Windows\system32\drivers
2010-07-17 20:27:32 ----D---- C:\Windows\system32\drivers\UMDF
2010-07-17 13:12:53 ----D---- C:\ProgramData\Spyware Terminator
2010-07-17 13:12:38 ----D---- C:\Program Files (x86)\Spyware Terminator
2010-07-15 09:53:49 ----D---- C:\Windows\system32\catroot2
2010-07-15 07:06:12 ----D---- C:\Windows\winsxs
2010-07-14 20:50:46 ----D---- C:\Windows\SysWOW64
2010-07-14 20:50:46 ----D---- C:\Program Files (x86)\MSXML 4.0
2010-07-14 20:50:38 ----D---- C:\ProgramData\Microsoft Help
2010-07-14 19:16:20 ----D---- C:\Windows\system32\catroot
2010-07-13 13:23:24 ----D---- C:\Program Files (x86)\Common Files
2010-07-07 12:25:57 ----D---- C:\Program Files (x86)\DreamCom
2010-07-03 18:36:33 ----SD---- C:\Users\Karel\AppData\Roaming\Microsoft
2010-07-02 22:18:43 ----A---- C:\Windows\system32\MRT.exe
2010-07-01 21:58:30 ----D---- C:\Program Files (x86)\Audiograbber
2010-06-23 16:38:04 ----D---- C:\Users\Karel\AppData\Roaming\LangSoft
2010-06-23 14:40:48 ----D---- C:\Users\Karel\AppData\Roaming\dvdcss
2010-06-23 12:57:34 ----SD---- C:\ProgramData\Microsoft
2010-06-23 11:41:08 ----D---- C:\Windows\system32\DriverStore
2010-06-23 10:26:28 ----D---- C:\Windows\Microsoft.NET
2010-06-23 10:26:26 ----RSD---- C:\Windows\assembly
2010-06-23 00:01:53 ----D---- C:\Windows\AppPatch
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-06-20 828912]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-04-06 13368]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2009-07-06 13368]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2010-03-02 116568]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2010-06-04 236112]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2010-06-01 33208]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2010-06-01 85208]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2010-02-16 81072]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-05-27 6856192]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-05-27 264192]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-06-20 82816]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-19 239616]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-08-17 1235968]
S3 a69rwaqv;a69rwaqv; C:\Windows\system32\drivers\a69rwaqv.sys []
S3 actl0kyb;actl0kyb; C:\Windows\system32\drivers\actl0kyb.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-05-27 203264]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-04-10 294912]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2010-06-22 488960]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-06-01 2348600]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-18 651720]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1255736]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Karel at 2010-07-22 11:34:46
Microsoft Windows 7 Ultimate
System drive C: has 258 GB (85%) free of 304 GB
Total RAM: 4095 MB (73% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
C:\ASUS.SYS\config\DVMExportService.exe
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {C58FCEFE-E08D-4201-8AA7-87DCD4D79117}
"C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe" -b
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
C:\Windows\system32\spool\DRIVERS\x64\3\fpphelp3a.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\guardhlp.exe" GRD1
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_000008b4
\??\C:\Windows\system32\conhost.exe
"D:\Data\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\rundll32.exe" "C:\Windows\system32\WININET.dll",DispatchAPICall 1
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll [2010-05-07 240912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-06-19 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11 345480]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-06-19 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-06-01 8074184]
"pdfFactory Pro Dispatcher v3"=C:\Windows\system32\spool\DRIVERS\x64\3\fppdis3a.exe [2009-09-02 744448]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"= []
"Nektra OEAPI"= []
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"WEBTRAN"= []
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-07-19 2957040]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
""= []
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-27 98304]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ImageMixer 3 SE Camera Monitor Ver.6.lnk - C:\Program Files (x86)\PIXELA\ImageMixer 3 SE Ver.6\Transfer Utility\CameraMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard64.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0xB1000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe"="C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit"
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe"="C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\PROGRA~2\PSPADE~1\PSPad.exe "%1"
======List of files/folders created in the last 1 months======
2010-07-22 11:51:09 ----D---- C:\Program Files\trend micro
2010-07-22 11:50:57 ----D---- C:\rsit
2010-07-22 11:19:12 ----D---- C:\Users\Karel\AppData\Roaming\SUPERAntiSpyware.com
2010-07-22 11:19:12 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2010-07-22 11:15:30 ----D---- C:\ProgramData\!SASCORE
2010-07-22 11:13:37 ----D---- C:\Program Files\SUPERAntiSpyware
2010-07-22 10:45:41 ----D---- C:\32788R22FWJFW
2010-07-20 21:56:14 ----D---- C:\Program Files (x86)\PIXELA
2010-07-18 12:26:09 ----A---- C:\Program Files (x86)\MPC-HomeCinema.1.3.1249.0.(x86).exe
2010-07-14 19:16:34 ----A---- C:\Windows\system32\cdd.dll
2010-07-13 13:23:24 ----D---- C:\Users\Karel\AppData\Roaming\602XML
2010-07-13 13:23:22 ----D---- C:\Program Files (x86)\Software602
2010-07-13 13:06:35 ----D---- C:\Users\Karel\AppData\Roaming\Mozilla
2010-07-04 18:22:17 ----D---- C:\Downloads
2010-07-04 18:21:51 ----D---- C:\Users\Karel\AppData\Roaming\Orbit
2010-07-04 18:21:51 ----D---- C:\Program Files (x86)\Orbitdownloader
2010-07-04 18:04:32 ----A---- C:\Windows\libem.INI
2010-07-04 18:04:27 ----D---- C:\Users\Karel\AppData\Roaming\FlashGet
2010-07-04 18:04:26 ----D---- C:\Users\Karel\AppData\Roaming\BITS
2010-07-04 18:04:24 ----D---- C:\Users\Karel\AppData\Roaming\FlashGetBHO
2010-07-04 18:04:22 ----D---- C:\Program Files (x86)\FlashGet Network
2010-06-24 20:26:07 ----D---- C:\Program Files (x86)\Blu Ray Player
2010-06-24 20:15:18 ----D---- C:\Program Files (x86)\MPC HomeCinema
2010-06-24 20:07:06 ----D---- C:\Program Files\MPC
2010-06-24 15:03:30 ----D---- C:\Users\Karel\AppData\Roaming\Media Player Classic
2010-06-23 16:22:06 ----D---- C:\Users\Karel\AppData\Roaming\AntispamSniper
2010-06-23 15:55:07 ----D---- C:\Program Files (x86)\The KMPlayer
2010-06-23 14:16:10 ----D---- C:\Program Files (x86)\AntispamSniper for TheBat!
2010-06-23 14:00:17 ----D---- C:\Program Files (x86)\The Bat!
2010-06-23 11:39:50 ----D---- C:\Windows\WindowsMobile
2010-06-23 11:38:39 ----D---- C:\ProgramData\Windows Genuine Advantage
2010-06-23 10:27:53 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
======List of files/folders modified in the last 1 months======
2010-07-22 12:10:25 ----SHD---- C:\Windows\Installer
2010-07-22 12:10:18 ----D---- C:\Program Files (x86)\Ask.com
2010-07-22 12:08:42 ----D---- C:\Windows\Prefetch
2010-07-22 11:59:20 ----D---- C:\Windows\Temp
2010-07-22 11:56:19 ----D---- C:\Windows\system32\config
2010-07-22 11:51:09 ----RD---- C:\Program Files
2010-07-22 11:19:12 ----HD---- C:\ProgramData
2010-07-22 11:03:21 ----D---- C:\Windows\system32\NDF
2010-07-22 10:45:05 ----D---- C:\Windows\system32\Tasks
2010-07-22 10:21:33 ----D---- C:\Windows\System32
2010-07-22 10:21:32 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-22 10:21:29 ----D---- C:\Windows\inf
2010-07-22 10:04:22 ----D---- C:\Windows\debug
2010-07-22 10:03:40 ----AD---- C:\Windows
2010-07-22 10:02:34 ----D---- C:\Windows\system32\LogFiles
2010-07-22 09:52:50 ----SHD---- C:\System Volume Information
2010-07-22 09:41:31 ----D---- C:\Users\Karel\AppData\Roaming\Spyware Terminator
2010-07-22 09:26:40 ----D---- C:\Windows\system32\wdi
2010-07-21 23:45:48 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-07-21 21:53:26 ----A---- C:\Windows\cdplayer.ini
2010-07-21 21:24:34 ----D---- C:\Program Files (x86)\Opera
2010-07-20 22:05:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-07-20 21:56:14 ----RD---- C:\Program Files (x86)
2010-07-18 07:42:24 ----D---- C:\Users\Karel\AppData\Roaming\vlc
2010-07-17 20:27:34 ----D---- C:\Windows\system32\drivers
2010-07-17 20:27:32 ----D---- C:\Windows\system32\drivers\UMDF
2010-07-17 13:12:53 ----D---- C:\ProgramData\Spyware Terminator
2010-07-17 13:12:38 ----D---- C:\Program Files (x86)\Spyware Terminator
2010-07-15 09:53:49 ----D---- C:\Windows\system32\catroot2
2010-07-15 07:06:12 ----D---- C:\Windows\winsxs
2010-07-14 20:50:46 ----D---- C:\Windows\SysWOW64
2010-07-14 20:50:46 ----D---- C:\Program Files (x86)\MSXML 4.0
2010-07-14 20:50:38 ----D---- C:\ProgramData\Microsoft Help
2010-07-14 19:16:20 ----D---- C:\Windows\system32\catroot
2010-07-13 13:23:24 ----D---- C:\Program Files (x86)\Common Files
2010-07-07 12:25:57 ----D---- C:\Program Files (x86)\DreamCom
2010-07-03 18:36:33 ----SD---- C:\Users\Karel\AppData\Roaming\Microsoft
2010-07-02 22:18:43 ----A---- C:\Windows\system32\MRT.exe
2010-07-01 21:58:30 ----D---- C:\Program Files (x86)\Audiograbber
2010-06-23 16:38:04 ----D---- C:\Users\Karel\AppData\Roaming\LangSoft
2010-06-23 14:40:48 ----D---- C:\Users\Karel\AppData\Roaming\dvdcss
2010-06-23 12:57:34 ----SD---- C:\ProgramData\Microsoft
2010-06-23 11:41:08 ----D---- C:\Windows\system32\DriverStore
2010-06-23 10:26:28 ----D---- C:\Windows\Microsoft.NET
2010-06-23 10:26:26 ----RSD---- C:\Windows\assembly
2010-06-23 00:01:53 ----D---- C:\Windows\AppPatch
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-06-20 828912]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2009-04-06 13368]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2009-07-06 13368]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2010-03-02 116568]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2010-06-04 236112]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2010-06-01 33208]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2010-06-01 85208]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2010-02-16 81072]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-05-27 6856192]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-05-27 264192]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-06-20 82816]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-19 239616]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-08-17 1235968]
S3 a69rwaqv;a69rwaqv; C:\Windows\system32\drivers\a69rwaqv.sys []
S3 actl0kyb;actl0kyb; C:\Windows\system32\drivers\actl0kyb.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-05-27 203264]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DvmMDES;DeviceVM Meta Data Export Service; C:\ASUS.SYS\config\DVMExportService.exe [2009-04-10 294912]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe [2010-06-22 488960]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 602XML Updater;602Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [2010-04-14 73728]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-06-01 2348600]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-18 651720]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-19 1255736]
-----------------EOF-----------------