Kontrola logu
Napsal: 23 lis 2010 16:32
Prosim o nekoho aby me skontroloval log Diky moc
info.txt logfile of random's system information tool 1.08 2010-11-23 16:37:45
======Uninstall list======
-->C:\Program Files (x86)\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
AC3Filter 1.63b-->"C:\Program Files (x86)\AC3Filter\unins000.exe"
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_Plugin.exe -maintain plugin
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
AIDA64 Extreme Edition v1.20-->"C:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\unins000.exe"
Aktualizace pro Microsoft Outlook Social Connector (KB2289116)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-0405-0000-0000000FF1CE}" "{E09910D9-C94A-410B-9ACB-6F350F2BF9E7}" "1029" "0"
Catalyst Control Center - Branding-->MsiExec.exe /I{8D7133DE-27D2-47E5-B248-4180278D32AA}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Color Efex Pro 3.0 Complete-->C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Plug-ins\Nik Software\Color Efex Pro 3.0 Complete\uninstall.exe
Combined Community Codec Pack 2010-10-10-->"C:\Program Files (x86)\Combined Community Codec Pack\unins000.exe"
Corel WinDVD 2010-->MsiExec.exe /X{5C1F18D2-F6B7-4242-B803-B5A78648185D}
Definition update for Microsoft Office 2010 (KB982726)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{820F2EBF-0AEC-46F1-9DCD-66CAAD8344D3}" "1029" "0"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
ICQ7.2-->"C:\Program Files (x86)\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Java(TM) 6 Update 22-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216022FF}
JPEG Resampler Vs 5.0-->"C:\Program Files (x86)\JPEG Resampler\unins000.exe"
Microsoft Office Access MUI (Czech) 2010-->MsiExec.exe /X{90140000-0015-0405-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2010-->MsiExec.exe /X{90140000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2010-->MsiExec.exe /X{90140000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2010-->MsiExec.exe /X{90140000-0044-0405-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2010-->MsiExec.exe /X{90140000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2010-->MsiExec.exe /X{90140000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2010-->MsiExec.exe /X{90140000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2010-->MsiExec.exe /X{90140000-0018-0405-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2010-->MsiExec.exe /X{90140000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2010-->MsiExec.exe /X{90140000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Czech) 2010-->MsiExec.exe /X{90140000-002A-0405-1000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2010-->MsiExec.exe /X{90140000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2010-->MsiExec.exe /X{90140000-001B-0405-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053-->MsiExec.exe /X{B6E3757B-5E77-3915-866A-CCFC4B8D194C}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_ATL_x86-->MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Mozilla Firefox (3.6.12)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nero 7 Ultra Edition-->MsiExec.exe /X{91C0B95B-B83A-4828-A775-BBE2DD421029}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Security Update for Microsoft Office 2010 (KB2289161)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{F134C2C6-30B3-4169-A325-58482B4CE6FC}" "1029" "0"
Security Update for Microsoft Word 2010 (KB2345000)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{A6D422EE-1196-45EE-B9AE-6B5B64975E8B}" "1029" "0"
Skype™ 5.0-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Soluto-->MsiExec.exe /X{47381488-49C5-414A-B49F-FBCC633AF8E3}
Splash PRO-->MsiExec.exe /I{DE2679C3-CAC9-4089-B8F2-C0337E533857}
Spybot - Search & Destroy-->"C:\Program Files (x86)\Spybot - Search & Destroy\unins000.exe"
TeamViewer 5-->C:\Program Files (x86)\TeamViewer\Version5\uninstall.exe
Topaz Adjust 4-->MsiExec.exe /I{9FDC7042-CB9F-4336-A14C-DF10F53762E2}
TuneUp Utilities 2011-->C:\Program Files (x86)\TuneUp Utilities 2011\TUInstallHelper.exe --Trigger-Uninstall
Update for Microsoft Office 2010 (KB2202188)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{86B7A074-265D-420C-9E1E-7A920EF0ECA7}" "1029" "0"
Update for Microsoft OneNote 2010 (KB2288640)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{521AB5E8-5FFF-45C8-B750-6967F8C0A2B9}" "1029" "0"
Update for Microsoft Outlook Social Connector (KB2289116)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{75F91382-920C-4AE1-B9E6-FFFCEDA797E8}" "1029" "0"
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
======Hosts File======
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
======System event log======
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Cryptographic Services byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714051424.262212-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Modules Installer byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714051424.168612-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Software Protection byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714051424.059412-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Event Log byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714051424.012612-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Volume Shadow Copy byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714051423.934612-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247E29-32
Event Code: 900
Message: Služba Ochrana softwaru se spouští.
Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100810114714.000000-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20100810114516.000000-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20100810114511.000000-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100810114506.484375-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247E29-32
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20100810114506.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247E29-32
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114448.093750-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114448.078125-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x32029
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114447.578125-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114445.328125-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114445.250000-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=AMD64 Family 15 Model 67 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=4303
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by ROMAN at 2010-11-23 16:37:30
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (78%) free of 80 GB
Total RAM: 4094 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:37:43, on 23.11.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\trend micro\ROMAN.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6101 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-00241994-17d5-4b8e-988b-d11a64c5926c -SystemEventPortName:HostProcess-eea71b52-bce0-4357-942a-e0be008c5dbd -IoCancelEventPortName:HostProcess-96634bf9-49d9-4343-8316-e9925a644de4 -NonStateChangingEventPortName:HostProcess-8ed5844f-c1e5-4ac8-9c30-6aed5f47982a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:eba38b70-cd5b-459f-b28d-1451c9435b1a
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\servicing\TrustedInstaller.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
Ati2evxx.exe -Client
"taskhost.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1680
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"D:\Stažené soubory\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-01 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-11-02 11545192]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-11-08 2919168]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DelayedDesktopSwitchTimeout"=5
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-11-23 16:37:30 ----D---- C:\rsit
2010-11-23 16:37:30 ----D---- C:\Program Files\trend micro
2010-11-23 15:46:09 ----N---- C:\Windows\system32\MpSigStub.exe
2010-11-23 15:32:00 ----D---- C:\Program Files (x86)\Trend Micro
2010-11-23 14:46:49 ----D---- C:\Program Files (x86)\FinalWire
2010-11-22 15:14:30 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Apple Computer
2010-11-22 15:14:19 ----D---- C:\ProgramData\Apple Computer
2010-11-22 15:14:06 ----D---- C:\ProgramData\Apple
2010-11-22 15:06:43 ----SHD---- C:\Windows\system32\%APPDATA%
2010-11-16 11:30:20 ----D---- C:\Program Files (x86)\Combined Community Codec Pack
2010-11-16 11:29:42 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Media Player Classic
2010-11-16 09:39:12 ----D---- C:\Program Files (x86)\FreeRapid-0.85
2010-11-16 09:26:34 ----D---- C:\ProgramData\ESET
2010-11-16 09:26:34 ----D---- C:\Program Files\ESET
2010-11-15 14:41:11 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\NVIDIA 3D Vision Video Player
2010-11-15 14:20:40 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Stereoscopic Player
2010-11-15 07:41:27 ----D---- C:\Program Files\Defraggler
2010-11-11 15:35:02 ----D---- C:\Program Files (x86)\TeamViewer
2010-11-10 14:20:58 ----D---- C:\Windows\SYSWOW64\RTCOM
2010-11-10 14:20:58 ----D---- C:\Program Files\Realtek
2010-11-10 14:20:37 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\WavesGUILib.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSWOW64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSTSX64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSTSH64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSHP64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFSS_APO.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFNHK64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFCOM64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFAPO64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtPgEx64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtkCfg64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtkAPO64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtkApi64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEEP64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEEL64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEEG64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEED64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTCOM64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RP3DHT64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RP3DAA64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RCoInst64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEP64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEL64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEG64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EED64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEA64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2010-11-10 14:20:35 ----D---- C:\Program Files (x86)\Realtek
2010-11-10 14:20:35 ----A---- C:\Windows\system32\FMAPO64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\AERTAR64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\AERTAC64.dll
2010-11-10 14:20:33 ----A---- C:\Windows\RtlExUpd.dll
2010-11-07 15:47:21 ----RD---- C:\Program Files (x86)\Skype
2010-11-05 12:24:11 ----D---- C:\Program Files\CCleaner
2010-11-02 16:43:04 ----D---- C:\ProgramData\Synetic
2010-11-02 16:42:34 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-11-02 16:42:32 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2010-11-02 16:42:32 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-11-02 16:42:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2010-11-02 16:42:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2010-11-02 16:42:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-11-02 16:42:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-11-02 16:42:30 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2010-11-02 16:42:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2010-11-02 16:42:30 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2010-11-02 16:42:30 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-11-02 16:42:30 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-11-02 16:42:30 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-11-02 16:42:27 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-11-02 16:42:26 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2010-11-02 16:42:26 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2010-11-02 16:42:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2010-11-02 16:42:26 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-11-02 16:42:26 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-11-02 16:42:26 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-11-02 16:42:25 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2010-11-02 16:42:25 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2010-11-02 16:42:25 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-11-02 16:42:25 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-11-02 16:42:24 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2010-11-02 16:42:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2010-11-02 16:42:24 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-11-02 16:42:24 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-11-02 16:42:22 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2010-11-02 16:42:22 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2010-11-02 16:42:22 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2010-11-02 16:42:22 ----A---- C:\Windows\system32\xinput1_3.dll
2010-11-02 16:42:22 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-11-02 16:42:22 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-11-02 16:42:20 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2010-11-02 16:42:20 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2010-11-02 16:42:20 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2010-11-02 16:42:20 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-11-02 16:42:20 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-11-02 16:42:20 ----A---- C:\Windows\system32\d3dx10.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\xinput1_2.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-11-02 16:42:18 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2010-11-02 16:42:18 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2010-11-02 16:42:18 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2010-11-02 16:42:18 ----A---- C:\Windows\system32\xinput1_1.dll
2010-11-02 16:42:18 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-11-02 16:42:18 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-11-02 16:42:15 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2010-11-02 16:42:15 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-11-02 16:42:14 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2010-11-02 16:42:14 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-11-02 16:42:13 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2010-11-02 16:42:13 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2010-11-02 16:42:13 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-11-02 16:42:13 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-11-02 16:42:12 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2010-11-02 16:42:12 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2010-11-02 16:42:12 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-11-02 16:42:12 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-11-02 16:42:11 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2010-11-02 16:42:11 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-11-01 16:05:30 ----A---- C:\Windows\SYSWOW64\javaws.exe
2010-11-01 16:05:30 ----A---- C:\Windows\SYSWOW64\javaw.exe
2010-11-01 16:05:30 ----A---- C:\Windows\SYSWOW64\java.exe
2010-11-01 15:41:24 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\VitySoft
2010-10-29 07:46:45 ----A---- C:\Windows\system32\TURegOpt.exe
2010-10-29 07:46:44 ----A---- C:\Windows\SYSWOW64\uxtuneup.dll
2010-10-29 07:46:44 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2010-10-29 07:46:44 ----A---- C:\Windows\system32\uxtuneup.dll
2010-10-29 07:46:44 ----A---- C:\Windows\system32\authuitu.dll
2010-10-29 07:46:36 ----D---- C:\Program Files (x86)\TuneUp Utilities 2011
2010-10-29 07:38:58 ----SHD---- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2010-10-28 16:54:15 ----D---- C:\Windows\Downloaded Installations
2010-10-28 16:54:05 ----D---- C:\ProgramData\Sling Media
2010-10-27 07:27:37 ----A---- C:\Windows\system32\drivers\Diskdump.sys
======List of files/folders modified in the last 1 months======
2010-11-23 16:37:31 ----D---- C:\Windows\Temp
2010-11-23 16:37:30 ----RD---- C:\Program Files
2010-11-23 16:34:42 ----D---- C:\Windows
2010-11-23 16:34:14 ----SD---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Microsoft
2010-11-23 16:33:12 ----D---- C:\Windows\system32\config
2010-11-23 16:29:35 ----SHD---- C:\Config.Msi
2010-11-23 16:27:24 ----SHD---- C:\Windows\Installer
2010-11-23 16:24:01 ----RD---- C:\Program Files (x86)
2010-11-23 16:23:14 ----HD---- C:\ProgramData
2010-11-23 16:18:53 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\ICQ
2010-11-23 15:53:05 ----D---- C:\Windows\system32\drivers\etc
2010-11-23 15:47:31 ----D---- C:\Windows\system32\drivers
2010-11-23 15:46:09 ----D---- C:\Windows\System32
2010-11-23 15:09:02 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Skype
2010-11-23 14:11:45 ----D---- C:\Windows\inf
2010-11-23 14:11:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-22 19:16:12 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\TeamViewer
2010-11-22 16:09:01 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-11-22 15:18:29 ----D---- C:\Program Files (x86)\Common Files
2010-11-22 15:14:34 ----D---- C:\Windows\SysWOW64
2010-11-20 16:00:37 ----D---- C:\ProgramData\boost_interprocess_ROMAN
2010-11-19 14:13:17 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Winamp
2010-11-18 19:57:51 ----SHD---- C:\Boot
2010-11-18 19:48:14 ----D---- C:\Windows\system32\catroot2
2010-11-18 19:47:25 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-11-18 19:43:50 ----D---- C:\Windows\Tasks
2010-11-18 19:43:50 ----D---- C:\Windows\system32\Tasks
2010-11-16 13:28:45 ----D---- C:\Windows\SoftwareDistribution
2010-11-16 09:32:27 ----D---- C:\Windows\debug
2010-11-16 09:31:54 ----D---- C:\Windows\Prefetch
2010-11-16 09:27:02 ----D---- C:\Windows\system32\DriverStore
2010-11-16 09:27:02 ----D---- C:\Windows\system32\catroot
2010-11-10 14:21:09 ----HD---- C:\Program Files (x86)\Temp
2010-11-10 14:20:35 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-11-10 14:13:59 ----D---- C:\ProgramData\Microsoft Help
2010-11-10 14:13:08 ----A---- C:\Windows\system32\MRT.exe
2010-11-09 20:39:33 ----SHD---- C:\$Recycle.Bin
2010-11-02 22:19:50 ----D---- C:\Windows\rescache
2010-11-02 16:42:18 ----RSD---- C:\Windows\assembly
2010-11-01 16:05:26 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2010-11-01 14:35:02 ----D---- C:\Program Files (x86)\ICQ7.2
2010-11-01 13:43:33 ----D---- C:\Windows\system32\drivers\UMDF
2010-10-29 07:46:28 ----D---- C:\ProgramData\TuneUp Software
2010-10-29 07:39:26 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\TuneUp Software
2010-10-27 07:31:21 ----D---- C:\Windows\winsxs
2010-10-27 07:31:19 ----D---- C:\Windows\AppPatch
2010-10-24 11:37:39 ----D---- C:\Windows\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PCGenFAM;PCGenFAM; C:\Windows\system32\DRIVERS\PCGenFAM.sys [2010-09-22 199112]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-17 834544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-08-31 314016]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-09-03 170104]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-07-29 171152]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 50624]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-08-31 43680]
R2 regi;regi; \??\C:\Windows\system32\drivers\regi.sys [2007-01-15 14112]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-02-11 5352960]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-07-29 33632]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-11-02 2536040]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-19 239616]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
S3 avvqsc9p;avvqsc9p; C:\Windows\system32\drivers\avvqsc9p.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2010-02-11 952320]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-11-08 810144]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2010-09-22 330784]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-10-27 1974080]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-11-08 42360]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S4 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
S4 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-19 2011944]
S4 UxTuneUp;TuneUp Theme Extension; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2010-11-23 16:37:45
======Uninstall list======
-->C:\Program Files (x86)\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
AC3Filter 1.63b-->"C:\Program Files (x86)\AC3Filter\unins000.exe"
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_Plugin.exe -maintain plugin
Adobe Photoshop CS5-->C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\core\PDApp.exe --appletID="DWA_UI" --appletVersion="1.0" --mode="Uninstall" --mediaSignature="{15FEDA5F-141C-4127-8D7E-B962D1742728}"
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
AIDA64 Extreme Edition v1.20-->"C:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\unins000.exe"
Aktualizace pro Microsoft Outlook Social Connector (KB2289116)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-0405-0000-0000000FF1CE}" "{E09910D9-C94A-410B-9ACB-6F350F2BF9E7}" "1029" "0"
Catalyst Control Center - Branding-->MsiExec.exe /I{8D7133DE-27D2-47E5-B248-4180278D32AA}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Color Efex Pro 3.0 Complete-->C:\Program Files (x86)\Adobe\Adobe Photoshop CS5\Plug-ins\Nik Software\Color Efex Pro 3.0 Complete\uninstall.exe
Combined Community Codec Pack 2010-10-10-->"C:\Program Files (x86)\Combined Community Codec Pack\unins000.exe"
Corel WinDVD 2010-->MsiExec.exe /X{5C1F18D2-F6B7-4242-B803-B5A78648185D}
Definition update for Microsoft Office 2010 (KB982726)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{820F2EBF-0AEC-46F1-9DCD-66CAAD8344D3}" "1029" "0"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
ICQ7.2-->"C:\Program Files (x86)\InstallShield Installation Information\{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
Java(TM) 6 Update 22-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216022FF}
JPEG Resampler Vs 5.0-->"C:\Program Files (x86)\JPEG Resampler\unins000.exe"
Microsoft Office Access MUI (Czech) 2010-->MsiExec.exe /X{90140000-0015-0405-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2010-->MsiExec.exe /X{90140000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2010-->MsiExec.exe /X{90140000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2010-->MsiExec.exe /X{90140000-0044-0405-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2010-->MsiExec.exe /X{90140000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2010-->MsiExec.exe /X{90140000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2010-->MsiExec.exe /X{90140000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2010-->MsiExec.exe /X{90140000-0018-0405-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2010-->MsiExec.exe /X{90140000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2010-->MsiExec.exe /X{90140000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Czech) 2010-->MsiExec.exe /X{90140000-002A-0405-1000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2010-->MsiExec.exe /X{90140000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2010-->MsiExec.exe /X{90140000-001B-0405-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053-->MsiExec.exe /X{B6E3757B-5E77-3915-866A-CCFC4B8D194C}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft_VC80_ATL_x86_x64-->MsiExec.exe /I{925D058B-564A-443A-B4B2-7E90C6432E55}
Microsoft_VC80_ATL_x86-->MsiExec.exe /I{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}
Microsoft_VC80_CRT_x86_x64-->MsiExec.exe /I{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}
Microsoft_VC80_CRT_x86-->MsiExec.exe /I{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}
Microsoft_VC80_MFC_x86_x64-->MsiExec.exe /I{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}
Microsoft_VC80_MFC_x86-->MsiExec.exe /I{D1A19B02-817E-4296-A45B-07853FD74D57}
Microsoft_VC80_MFCLOC_x86_x64-->MsiExec.exe /I{1E9FC118-651D-4934-97BE-E53CAE5C7D45}
Microsoft_VC80_MFCLOC_x86-->MsiExec.exe /I{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}
Microsoft_VC90_ATL_x86_x64-->MsiExec.exe /I{8557397C-A42D-486F-97B3-A2CBC2372593}
Microsoft_VC90_ATL_x86-->MsiExec.exe /I{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}
Microsoft_VC90_CRT_x86_x64-->MsiExec.exe /I{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}
Microsoft_VC90_CRT_x86-->MsiExec.exe /I{08D2E121-7F6A-43EB-97FD-629B44903403}
Microsoft_VC90_MFC_x86_x64-->MsiExec.exe /I{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}
Microsoft_VC90_MFC_x86-->MsiExec.exe /I{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}
Mozilla Firefox (3.6.12)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nero 7 Ultra Edition-->MsiExec.exe /X{91C0B95B-B83A-4828-A775-BBE2DD421029}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
PDF Settings CS5-->MsiExec.exe /I{A78FE97A-C0C8-49CE-89D0-EDD524A17392}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Security Update for Microsoft Office 2010 (KB2289161)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{F134C2C6-30B3-4169-A325-58482B4CE6FC}" "1029" "0"
Security Update for Microsoft Word 2010 (KB2345000)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{A6D422EE-1196-45EE-B9AE-6B5B64975E8B}" "1029" "0"
Skype™ 5.0-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Soluto-->MsiExec.exe /X{47381488-49C5-414A-B49F-FBCC633AF8E3}
Splash PRO-->MsiExec.exe /I{DE2679C3-CAC9-4089-B8F2-C0337E533857}
Spybot - Search & Destroy-->"C:\Program Files (x86)\Spybot - Search & Destroy\unins000.exe"
TeamViewer 5-->C:\Program Files (x86)\TeamViewer\Version5\uninstall.exe
Topaz Adjust 4-->MsiExec.exe /I{9FDC7042-CB9F-4336-A14C-DF10F53762E2}
TuneUp Utilities 2011-->C:\Program Files (x86)\TuneUp Utilities 2011\TUInstallHelper.exe --Trigger-Uninstall
Update for Microsoft Office 2010 (KB2202188)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{86B7A074-265D-420C-9E1E-7A920EF0ECA7}" "1029" "0"
Update for Microsoft OneNote 2010 (KB2288640)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{521AB5E8-5FFF-45C8-B750-6967F8C0A2B9}" "1029" "0"
Update for Microsoft Outlook Social Connector (KB2289116)-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-0011-0000-0000-0000000FF1CE}" "{75F91382-920C-4AE1-B9E6-FFFCEDA797E8}" "1029" "0"
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
======Hosts File======
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
======System event log======
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Cryptographic Services byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714051424.262212-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Modules Installer byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714051424.168612-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Software Protection byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714051424.059412-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Windows Event Log byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714051424.012612-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 7036
Message: Stav služby Volume Shadow Copy byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714051423.934612-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247E29-32
Event Code: 900
Message: Služba Ochrana softwaru se spouští.
Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100810114714.000000-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20100810114516.000000-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20100810114511.000000-000
Event Type: Informace
User:
Computer Name: 37L4247E29-32
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100810114506.484375-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247E29-32
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20100810114506.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247E29-32
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114448.093750-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247E29-32$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114448.078125-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x32029
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114447.578125-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114445.328125-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247E29-32
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100810114445.250000-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=AMD64 Family 15 Model 67 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=4303
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by ROMAN at 2010-11-23 16:37:30
Microsoft Windows 7 Ultimate
System drive C: has 62 GB (78%) free of 80 GB
Total RAM: 4094 MB (74% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:37:43, on 23.11.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\Program Files\trend micro\ROMAN.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files (x86)\ICQ7.2\ICQ.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - C:\Program Files\Soluto\SolutoService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6101 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-00241994-17d5-4b8e-988b-d11a64c5926c -SystemEventPortName:HostProcess-eea71b52-bce0-4357-942a-e0be008c5dbd -IoCancelEventPortName:HostProcess-96634bf9-49d9-4343-8316-e9925a644de4 -NonStateChangingEventPortName:HostProcess-8ed5844f-c1e5-4ac8-9c30-6aed5f47982a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:eba38b70-cd5b-459f-b28d-1451c9435b1a
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\servicing\TrustedInstaller.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
Ati2evxx.exe -Client
"taskhost.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:1680
"C:\Program Files\Soluto\soluto.exe" /userinit
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Soluto\SolutoService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"D:\Stažené soubory\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-11-01 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-11-02 11545192]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-11-08 2919168]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SolutoService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DelayedDesktopSwitchTimeout"=5
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-11-23 16:37:30 ----D---- C:\rsit
2010-11-23 16:37:30 ----D---- C:\Program Files\trend micro
2010-11-23 15:46:09 ----N---- C:\Windows\system32\MpSigStub.exe
2010-11-23 15:32:00 ----D---- C:\Program Files (x86)\Trend Micro
2010-11-23 14:46:49 ----D---- C:\Program Files (x86)\FinalWire
2010-11-22 15:14:30 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Apple Computer
2010-11-22 15:14:19 ----D---- C:\ProgramData\Apple Computer
2010-11-22 15:14:06 ----D---- C:\ProgramData\Apple
2010-11-22 15:06:43 ----SHD---- C:\Windows\system32\%APPDATA%
2010-11-16 11:30:20 ----D---- C:\Program Files (x86)\Combined Community Codec Pack
2010-11-16 11:29:42 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Media Player Classic
2010-11-16 09:39:12 ----D---- C:\Program Files (x86)\FreeRapid-0.85
2010-11-16 09:26:34 ----D---- C:\ProgramData\ESET
2010-11-16 09:26:34 ----D---- C:\Program Files\ESET
2010-11-15 14:41:11 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\NVIDIA 3D Vision Video Player
2010-11-15 14:20:40 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Stereoscopic Player
2010-11-15 07:41:27 ----D---- C:\Program Files\Defraggler
2010-11-11 15:35:02 ----D---- C:\Program Files (x86)\TeamViewer
2010-11-10 14:20:58 ----D---- C:\Windows\SYSWOW64\RTCOM
2010-11-10 14:20:58 ----D---- C:\Program Files\Realtek
2010-11-10 14:20:37 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\WavesGUILib.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSWOW64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSTSX64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSTSH64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SRSHP64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFSS_APO.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFNHK64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFCOM64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\SFAPO64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtPgEx64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtkCfg64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtkAPO64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RtkApi64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEEP64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEEL64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEEG64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTEED64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RTCOM64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RP3DHT64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RP3DAA64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\RCoInst64.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEP64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEL64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEG64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EED64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\R4EEA64A.dll
2010-11-10 14:20:37 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2010-11-10 14:20:36 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2010-11-10 14:20:35 ----D---- C:\Program Files (x86)\Realtek
2010-11-10 14:20:35 ----A---- C:\Windows\system32\FMAPO64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\AERTAR64.dll
2010-11-10 14:20:35 ----A---- C:\Windows\system32\AERTAC64.dll
2010-11-10 14:20:33 ----A---- C:\Windows\RtlExUpd.dll
2010-11-07 15:47:21 ----RD---- C:\Program Files (x86)\Skype
2010-11-05 12:24:11 ----D---- C:\Program Files\CCleaner
2010-11-02 16:43:04 ----D---- C:\ProgramData\Synetic
2010-11-02 16:42:34 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\system32\D3DX9_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\system32\d3dx10_41.dll
2010-11-02 16:42:34 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2010-11-02 16:42:33 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\XAudio2_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\xactengine3_4.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\d3dx10_40.dll
2010-11-02 16:42:33 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2010-11-02 16:42:32 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2010-11-02 16:42:32 ----A---- C:\Windows\system32\D3DX9_40.dll
2010-11-02 16:42:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2010-11-02 16:42:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2010-11-02 16:42:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2010-11-02 16:42:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2010-11-02 16:42:30 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2010-11-02 16:42:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2010-11-02 16:42:30 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2010-11-02 16:42:30 ----A---- C:\Windows\system32\XAudio2_1.dll
2010-11-02 16:42:30 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2010-11-02 16:42:30 ----A---- C:\Windows\system32\D3DX9_39.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2010-11-02 16:42:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\d3dx10_38.dll
2010-11-02 16:42:29 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2010-11-02 16:42:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-11-02 16:42:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2010-11-02 16:42:27 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-11-02 16:42:27 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-11-02 16:42:26 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2010-11-02 16:42:26 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2010-11-02 16:42:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2010-11-02 16:42:26 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-11-02 16:42:26 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-11-02 16:42:26 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-11-02 16:42:25 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2010-11-02 16:42:25 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2010-11-02 16:42:25 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-11-02 16:42:25 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-11-02 16:42:24 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2010-11-02 16:42:24 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2010-11-02 16:42:24 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-11-02 16:42:24 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2010-11-02 16:42:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\xactengine2_8.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\d3dx10_34.dll
2010-11-02 16:42:23 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2010-11-02 16:42:22 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2010-11-02 16:42:22 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2010-11-02 16:42:22 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2010-11-02 16:42:22 ----A---- C:\Windows\system32\xinput1_3.dll
2010-11-02 16:42:22 ----A---- C:\Windows\system32\xactengine2_7.dll
2010-11-02 16:42:22 ----A---- C:\Windows\system32\d3dx9_34.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\xactengine2_6.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\d3dx9_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\d3dx10_33.dll
2010-11-02 16:42:21 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2010-11-02 16:42:20 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2010-11-02 16:42:20 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2010-11-02 16:42:20 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2010-11-02 16:42:20 ----A---- C:\Windows\system32\xactengine2_5.dll
2010-11-02 16:42:20 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-11-02 16:42:20 ----A---- C:\Windows\system32\d3dx10.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2010-11-02 16:42:19 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\xinput1_2.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\xactengine2_4.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\xactengine2_3.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\x3daudio1_1.dll
2010-11-02 16:42:19 ----A---- C:\Windows\system32\d3dx9_31.dll
2010-11-02 16:42:18 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2010-11-02 16:42:18 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2010-11-02 16:42:18 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2010-11-02 16:42:18 ----A---- C:\Windows\system32\xinput1_1.dll
2010-11-02 16:42:18 ----A---- C:\Windows\system32\xactengine2_2.dll
2010-11-02 16:42:18 ----A---- C:\Windows\system32\xactengine2_1.dll
2010-11-02 16:42:15 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2010-11-02 16:42:15 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-11-02 16:42:14 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2010-11-02 16:42:14 ----A---- C:\Windows\system32\xactengine2_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\system32\x3daudio1_0.dll
2010-11-02 16:42:14 ----A---- C:\Windows\system32\d3dx9_29.dll
2010-11-02 16:42:13 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2010-11-02 16:42:13 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2010-11-02 16:42:13 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-11-02 16:42:13 ----A---- C:\Windows\system32\d3dx9_27.dll
2010-11-02 16:42:12 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2010-11-02 16:42:12 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2010-11-02 16:42:12 ----A---- C:\Windows\system32\d3dx9_26.dll
2010-11-02 16:42:12 ----A---- C:\Windows\system32\d3dx9_25.dll
2010-11-02 16:42:11 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2010-11-02 16:42:11 ----A---- C:\Windows\system32\d3dx9_24.dll
2010-11-01 16:05:30 ----A---- C:\Windows\SYSWOW64\javaws.exe
2010-11-01 16:05:30 ----A---- C:\Windows\SYSWOW64\javaw.exe
2010-11-01 16:05:30 ----A---- C:\Windows\SYSWOW64\java.exe
2010-11-01 15:41:24 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\VitySoft
2010-10-29 07:46:45 ----A---- C:\Windows\system32\TURegOpt.exe
2010-10-29 07:46:44 ----A---- C:\Windows\SYSWOW64\uxtuneup.dll
2010-10-29 07:46:44 ----A---- C:\Windows\SYSWOW64\authuitu.dll
2010-10-29 07:46:44 ----A---- C:\Windows\system32\uxtuneup.dll
2010-10-29 07:46:44 ----A---- C:\Windows\system32\authuitu.dll
2010-10-29 07:46:36 ----D---- C:\Program Files (x86)\TuneUp Utilities 2011
2010-10-29 07:38:58 ----SHD---- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2010-10-28 16:54:15 ----D---- C:\Windows\Downloaded Installations
2010-10-28 16:54:05 ----D---- C:\ProgramData\Sling Media
2010-10-27 07:27:37 ----A---- C:\Windows\system32\drivers\Diskdump.sys
======List of files/folders modified in the last 1 months======
2010-11-23 16:37:31 ----D---- C:\Windows\Temp
2010-11-23 16:37:30 ----RD---- C:\Program Files
2010-11-23 16:34:42 ----D---- C:\Windows
2010-11-23 16:34:14 ----SD---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Microsoft
2010-11-23 16:33:12 ----D---- C:\Windows\system32\config
2010-11-23 16:29:35 ----SHD---- C:\Config.Msi
2010-11-23 16:27:24 ----SHD---- C:\Windows\Installer
2010-11-23 16:24:01 ----RD---- C:\Program Files (x86)
2010-11-23 16:23:14 ----HD---- C:\ProgramData
2010-11-23 16:18:53 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\ICQ
2010-11-23 15:53:05 ----D---- C:\Windows\system32\drivers\etc
2010-11-23 15:47:31 ----D---- C:\Windows\system32\drivers
2010-11-23 15:46:09 ----D---- C:\Windows\System32
2010-11-23 15:09:02 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Skype
2010-11-23 14:11:45 ----D---- C:\Windows\inf
2010-11-23 14:11:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-22 19:16:12 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\TeamViewer
2010-11-22 16:09:01 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-11-22 15:18:29 ----D---- C:\Program Files (x86)\Common Files
2010-11-22 15:14:34 ----D---- C:\Windows\SysWOW64
2010-11-20 16:00:37 ----D---- C:\ProgramData\boost_interprocess_ROMAN
2010-11-19 14:13:17 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\Winamp
2010-11-18 19:57:51 ----SHD---- C:\Boot
2010-11-18 19:48:14 ----D---- C:\Windows\system32\catroot2
2010-11-18 19:47:25 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-11-18 19:43:50 ----D---- C:\Windows\Tasks
2010-11-18 19:43:50 ----D---- C:\Windows\system32\Tasks
2010-11-16 13:28:45 ----D---- C:\Windows\SoftwareDistribution
2010-11-16 09:32:27 ----D---- C:\Windows\debug
2010-11-16 09:31:54 ----D---- C:\Windows\Prefetch
2010-11-16 09:27:02 ----D---- C:\Windows\system32\DriverStore
2010-11-16 09:27:02 ----D---- C:\Windows\system32\catroot
2010-11-10 14:21:09 ----HD---- C:\Program Files (x86)\Temp
2010-11-10 14:20:35 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-11-10 14:13:59 ----D---- C:\ProgramData\Microsoft Help
2010-11-10 14:13:08 ----A---- C:\Windows\system32\MRT.exe
2010-11-09 20:39:33 ----SHD---- C:\$Recycle.Bin
2010-11-02 22:19:50 ----D---- C:\Windows\rescache
2010-11-02 16:42:18 ----RSD---- C:\Windows\assembly
2010-11-01 16:05:26 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2010-11-01 14:35:02 ----D---- C:\Program Files (x86)\ICQ7.2
2010-11-01 13:43:33 ----D---- C:\Windows\system32\drivers\UMDF
2010-10-29 07:46:28 ----D---- C:\ProgramData\TuneUp Software
2010-10-29 07:39:26 ----D---- C:\Users\ROMAN.ROMAN-PC\AppData\Roaming\TuneUp Software
2010-10-27 07:31:21 ----D---- C:\Windows\winsxs
2010-10-27 07:31:19 ----D---- C:\Windows\AppPatch
2010-10-24 11:37:39 ----D---- C:\Windows\Logs
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PCGenFAM;PCGenFAM; C:\Windows\system32\DRIVERS\PCGenFAM.sys [2010-09-22 199112]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-08-17 834544]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-07-29 141264]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2010-08-31 314016]
R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-09-03 170104]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2010-07-29 171152]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2010-07-29 50624]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2010-08-31 43680]
R2 regi;regi; \??\C:\Windows\system32\drivers\regi.sys [2007-01-15 14112]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-02-11 5352960]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2010-07-29 33632]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-11-02 2536040]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-19 239616]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2010-10-07 11856]
S3 avvqsc9p;avvqsc9p; C:\Windows\system32\drivers\avvqsc9p.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2010-02-11 952320]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2010-11-08 810144]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 SolutoService;Soluto PCGenome Core Service; C:\Program Files\Soluto\SolutoService.exe [2010-09-22 330784]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2010-10-27 1974080]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-11-08 42360]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S4 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
S4 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-19 2011944]
S4 UxTuneUp;TuneUp Theme Extension; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------