Často mám poškozené DLL apod.
Napsal: 28 pro 2010 13:21
Docela často se mi stává, že mám poškozený některý DLL soubory (někdy i jiný; jednou to bylo dokonce přímo EXE od Opery nebo film v AVI).
Vždycky jsou na oddílu E:\ (tam mám programy a hry, tzn. nic systémovýho, spíš jsou poškozený třeba pluginy od Mirandy nebo nějaký knihovny ke hrám...) a jestli jsem to správně odpozoroval, tak to bývá po nepovedeným uspání počítače (asi jednou za 2 týdny se nepovede počítači uspat a po cca 15 minutách se sám natvrdo vypne, nevím proč; pak jsou na discích - podle chkdsk - chyby).
Takže se pokusím aspoň vyloučit (nebo zjistit), že jde o nějakýho červíka apod... Díky za kontrolu!
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jenda at 2010-12-28 12:50:22
Microsoft Windows 7 Professional
System drive C: has 3 GB (11%) free of 31 GB
Total RAM: 4094 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:50:47, on 28.12.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
E:\Programy\DAEMON Tools Lite\daemon.exe
C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Windows\SysWOW64\rundll32.exe
E:\Programy\Logitech\Logitech WebCam Software\LWS.exe
E:\Programy\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
E:\Programy\Opera\opera.exe
E:\Programy\Miranda IM\miranda32.exe
C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe
I:\setup.exe
C:\Users\Jenda\AppData\Local\Temp\is-VQUA1.tmp\setup.tmp
C:\Users\Jenda\AppData\Local\Temp\is-FCLRJ.tmp\Unpack.dll
C:\Program Files\trend micro\Jenda.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=217.91.70.238:8085
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Programy\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [IR_SERVER] e:\Programy\Realtek\DVB-T USB DEVICE\IR_SERVER.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Programy\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "E:\Programy\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [Corel File Shell Monitor] e:\Programy\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe
O4 - HKLM\..\Run: [Standby] "C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Programy\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\Programy\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Programy\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: e:\programy\vmware\vsocklib.dll
O10 - Unknown file in Winsock LSP: e:\programy\vmware\vsocklib.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Unknown owner - C:\Windows\System32\appdrvrem01.exe (file missing)
O23 - Service: @%systemroot%\system32\CISVC.EXE,-1 (CISVC) - Unknown owner - C:\Windows\system32\CISVC.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - e:\Programy\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - E:\Programy\VMware\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - E:\Programy\VMware\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9948 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\CISVC.EXE
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe" -Embedding
"e:\Programy\Sandboxie\SbieSvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe"
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"E:\Programy\VMware\vmware-authd.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\vmnetdhcp.exe
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Microsoft IntelliType Pro\itype.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"E:\Programy\DAEMON Tools Lite\daemon.exe" -autorun
"C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe"
"E:\Programy\Logitech\SetPoint\SetPoint.exe"
"C:\Windows\System32\rundll32.exe" P17RunE.dll,RunDLLEntry
"E:\Programy\Logitech\Logitech WebCam Software\LWS.exe" /hide
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"E:\Programy\Logitech\SetPoint\x86\SetPoint32.exe"
KHALMNPR.EXE /API
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-35ba2861-0189-438a-b59f-fffc6a94af42 -SystemEventPortName:HostProcess-94bfe9ee-c454-4350-b6f2-d3b4585a781d -IoCancelEventPortName:HostProcess-6752e133-0d31-4f0a-a847-dfde80d7e256 -NonStateChangingEventPortName:HostProcess-e145c506-491e-4a4b-b768-82bd8c30d68c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d9a9b2fc-8364-41e9-9752-72e74b3b6a98
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe" -Embedding
C:\Windows\System32\mobsync.exe -Embedding
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
"E:\Programy\Opera\opera.exe"
"E:\Programy\7-Zip\7zFM.exe" "C:\Users\Jenda\AppData\Local\Opera\Opera\temporary_downloads\uniws.zip"
"taskhost.exe"
"E:\Programy\Miranda IM\miranda32.exe"
"C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -RESTART
"I:\setup.exe"
"C:\Users\Jenda\AppData\Local\Temp\is-VQUA1.tmp\setup.tmp" /SL5="$9075A,7861335,147456,I:\setup.exe"
"C:\Users\Jenda\AppData\Local\Temp\is-FCLRJ.tmp\Unpack.dll" x I:\data-a.bin -y -dp"E:\Hry\Rockstar Games\Grand Theft Auto IV - Episodes From Liberty City"
\??\C:\Windows\system32\conhost.exe
"C:\Users\Jenda\AppData\Local\Opera\Opera\temporary_downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Programy\Java\jre6\bin\jp2ssv.dll [2009-10-23 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2009-06-17 130576]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-11-16 2716216]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2009-11-11 2345848]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"DAEMON Tools Lite"=E:\Programy\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"SansaDispatch"=C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [2010-01-31 79872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"P17RunE"=RunDll32 P17RunE.dll,RunDLLEntry []
"IR_SERVER"=e:\Programy\Realtek\DVB-T USB DEVICE\IR_SERVER.exe []
"SunJavaUpdateSched"=E:\Programy\Java\jre6\bin\jusched.exe [2009-10-23 149280]
"LogitechQuickCamRibbon"=E:\Programy\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]
"Corel File Shell Monitor"=e:\Programy\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe []
"Standby"=C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe [2010-04-14 105632]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech SetPoint.lnk - E:\Programy\Logitech\SetPoint\SetPoint.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-07-20 76816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\Windows\NOTEPAD.EXE %1
======List of files/folders created in the last 1 months======
2010-12-15 21:41:47 ----A---- C:\Windows\system32\mshtml.dll
2010-12-15 21:41:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-12-15 21:41:46 ----A---- C:\Windows\system32\mstime.dll
2010-12-15 21:41:46 ----A---- C:\Windows\system32\iertutil.dll
2010-12-15 21:41:46 ----A---- C:\Windows\system32\ieframe.dll
2010-12-15 21:41:45 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-12-15 21:41:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-15 21:41:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-15 21:41:43 ----A---- C:\Windows\system32\wininet.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\urlmon.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\ieui.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\iepeers.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-15 21:41:41 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-12-15 21:41:41 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-12-15 21:41:41 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-12-15 21:41:41 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-15 21:41:41 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-15 21:41:41 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-15 21:41:39 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-15 21:41:39 ----A---- C:\Windows\system32\win32k.sys
2010-12-15 21:41:39 ----A---- C:\Windows\system32\taskschd.dll
2010-12-15 21:41:39 ----A---- C:\Windows\system32\taskeng.exe
2010-12-15 21:41:39 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-15 21:41:38 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-15 21:41:38 ----A---- C:\Windows\system32\schtasks.exe
2010-12-15 21:41:38 ----A---- C:\Windows\system32\atmfd.dll
2010-12-15 21:41:37 ----A---- C:\Windows\SYSWOW64\webio.dll
2010-12-15 21:41:37 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-15 21:41:37 ----A---- C:\Windows\system32\webio.dll
2010-12-15 21:41:37 ----A---- C:\Windows\system32\atmlib.dll
2010-12-15 21:41:35 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-15 21:41:35 ----A---- C:\Windows\system32\tzres.dll
2010-12-15 21:41:29 ----A---- C:\Windows\system32\consent.exe
2010-12-13 20:47:04 ----D---- C:\Program Files\Adobe
2010-12-12 10:37:24 ----D---- C:\Program Files (x86)\Microsoft Office
2010-12-06 20:28:45 ----D---- C:\Program Files (x86)\Corel
2010-12-06 20:27:25 ----D---- C:\ProgramData\Corel
2010-12-06 20:21:03 ----D---- C:\ProgramData\Ulead Systems
2010-12-05 21:58:57 ----D---- C:\Users\Jenda\AppData\Roaming\PACE Anti-Piracy
2010-12-05 21:58:57 ----D---- C:\ProgramData\PACE Anti-Piracy
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files\PACE Anti-Piracy
2010-12-05 21:58:57 ----A---- C:\Windows\SurCode.INI
2010-12-05 21:57:32 ----D---- C:\Users\Jenda\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2010-12-05 21:47:28 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2010-12-05 21:43:35 ----D---- C:\Program Files (x86)\Adobe Media Player
2010-12-05 21:43:12 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2010-12-05 21:43:12 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2010-12-05 21:43:12 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2010-12-05 21:43:12 ----D---- C:\Program Files (x86)\My Company Name
2010-12-05 15:06:06 ----A---- C:\Windows\WA.INI
2010-12-02 18:26:38 ----SHD---- C:\ProgramData\SecuROM
2010-12-01 16:49:42 ----D---- C:\Users\Jenda\AppData\Roaming\gtk-2.0
======List of files/folders modified in the last 1 months======
2010-12-28 12:50:47 ----D---- C:\Program Files\trend micro
2010-12-28 12:50:17 ----D---- C:\Windows\Temp
2010-12-28 11:13:06 ----D---- C:\Windows\system32\config
2010-12-28 11:12:59 ----SHD---- C:\System Volume Information
2010-12-28 11:05:55 ----D---- C:\Windows\System32
2010-12-28 11:05:55 ----D---- C:\Windows\inf
2010-12-28 11:05:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-28 11:02:32 ----D---- C:\Windows
2010-12-28 11:01:53 ----D---- C:\ProgramData\VMware
2010-12-28 11:01:45 ----D---- C:\ProgramData\NVIDIA
2010-12-28 10:53:24 ----A---- C:\Windows\ntbtlog.txt
2010-12-27 20:21:56 ----D---- C:\Windows\system32\drivers
2010-12-27 20:21:55 ----D---- C:\Windows\system32\catroot
2010-12-27 20:21:54 ----D---- C:\Windows\system32\DriverStore
2010-12-27 16:50:57 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-27 16:46:59 ----A---- C:\Windows\Sandboxie.ini
2010-12-27 13:46:05 ----SHD---- C:\Windows\Installer
2010-12-27 13:46:00 ----SHD---- C:\Config.Msi
2010-12-27 13:45:52 ----D---- C:\Program Files (x86)\Google
2010-12-27 13:38:15 ----D---- C:\Windows\Prefetch
2010-12-23 11:13:50 ----D---- C:\Program Files (x86)\Common Files
2010-12-21 20:18:39 ----D---- C:\Users\Jenda\AppData\Roaming\FileZilla
2010-12-21 18:23:23 ----D---- C:\Users\Jenda\AppData\Roaming\Mozilla
2010-12-19 12:05:18 ----ASD---- C:\ProgramData\Microsoft
2010-12-17 19:49:20 ----D---- C:\Windows\winsxs
2010-12-17 19:46:54 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-12-17 19:46:54 ----D---- C:\Windows\SysWOW64
2010-12-17 19:46:54 ----D---- C:\Windows\system32\cs-CZ
2010-12-17 19:46:53 ----D---- C:\Program Files\Windows Mail
2010-12-17 19:46:53 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-17 19:46:52 ----D---- C:\Windows\SYSWOW64\migration
2010-12-17 19:46:52 ----D---- C:\Windows\system32\migration
2010-12-17 19:46:52 ----D---- C:\Program Files\Internet Explorer
2010-12-17 19:46:52 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-15 21:42:37 ----A---- C:\Windows\system32\MRT.exe
2010-12-15 21:41:24 ----D---- C:\Windows\system32\catroot2
2010-12-14 20:18:28 ----AD---- C:\ProgramData\TEMP
2010-12-14 19:14:02 ----RSD---- C:\Windows\Fonts
2010-12-13 21:47:19 ----D---- C:\Users\Jenda\AppData\Roaming\Adobe
2010-12-13 20:50:13 ----D---- C:\Program Files\Common Files\Adobe
2010-12-13 20:47:33 ----SD---- C:\Users\Jenda\AppData\Roaming\Microsoft
2010-12-13 20:47:04 ----RD---- C:\Program Files
2010-12-13 20:46:07 ----D---- C:\ProgramData\Adobe
2010-12-13 20:37:09 ----D---- C:\Program Files (x86)\Adobe
2010-12-12 23:03:20 ----D---- C:\Users\Jenda\AppData\Roaming\VMware
2010-12-12 10:37:29 ----D---- C:\ProgramData\Microsoft Help
2010-12-12 10:37:29 ----A---- C:\Windows\win.ini
2010-12-12 10:37:24 ----RD---- C:\Program Files (x86)
2010-12-06 20:29:03 ----HD---- C:\Windows\msdownld.tmp
2010-12-06 20:27:25 ----HD---- C:\ProgramData
2010-12-06 20:20:43 ----RSD---- C:\Windows\assembly
2010-12-06 20:03:41 ----D---- C:\Windows\SYSWOW64\wbem
2010-12-06 19:54:54 ----D---- C:\Windows\SYSWOW64\Setup
2010-12-06 19:54:54 ----D---- C:\Windows\SYSWOW64\oobe
2010-12-06 19:54:54 ----D---- C:\Windows\SYSWOW64\MUI
2010-12-06 19:54:53 ----D---- C:\Windows\SYSWOW64\DriverStore
2010-12-06 19:54:53 ----D---- C:\Windows\SYSWOW64\config
2010-12-06 19:54:53 ----D---- C:\Windows\SYSWOW64\com
2010-12-06 19:52:31 ----D---- C:\Temp
2010-12-06 19:48:12 ----A---- C:\Windows\WDICT32.INI
2010-12-06 16:43:54 ----D---- C:\Windows\system32\Tasks
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files\System
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files
2010-12-05 21:28:48 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-12-02 18:24:21 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-09-27 871408]
R1 appdrv01;Application Driver (01); C:\Windows\System32\Drivers\appdrv01.sys [2010-06-21 2793064]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-11-16 169080]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2009-11-16 44944]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2010-08-01 38448]
R2 vmci;VMware vmci; \??\C:\Windows\system32\drivers\vmci.sys [2010-08-01 80944]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2010-08-01 45104]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2010-08-01 30256]
R2 VMparport;VMware VMparport; \??\C:\Windows\system32\drivers\VMparport.sys [2010-08-01 18480]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\drivers\vmx86.sys [2010-08-01 68656]
R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\E:\Programy\VMware\vstor2-ws60.sys [2010-04-27 32816]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-06-19 33608]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-26 21832]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2009-06-17 55312]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2009-06-17 57872]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2009-06-17 40976]
R3 lvpopf64;Logitech POP Suppression Filter; C:\Windows\system32\DRIVERS\lvpopf64.sys [2009-10-07 271640]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2009-10-07 327704]
R3 LVUSBS64;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBS64.sys [2008-07-26 50072]
R3 LVUVC64;Logitech QuickCam Pro 5000(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2009-10-07 6379288]
R3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2007-11-16 1276928]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL2832U_IRHID;HID Infrared Remote Receiver; C:\Windows\system32\DRIVERS\RTL2832U_IRHID.sys [2009-07-13 42912]
R3 RTL2832UBDA;REALTEK 2832U BDA Driver; C:\Windows\system32\drivers\RTL2832UBDA.sys [2010-07-01 224488]
R3 RTL2832UUSB;REALTEK 2832U USB Driver; C:\Windows\System32\Drivers\RTL2832UUSB.sys [2010-07-01 39016]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
R3 SbieDrv;SbieDrv; \??\e:\Programy\Sandboxie\SbieDrv.sys [2010-02-03 134760]
R3 vmkbd;VMware kbd; \??\C:\Windows\system32\drivers\VMkbd.sys [2010-08-01 31792]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2010-08-01 20016]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 L8042Kbd;SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2009-06-17 30736]
S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 tapoas;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2010-07-11 30720]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 vmusb;VMware USB Client Driver; C:\Windows\System32\Drivers\vmusb.sys [2010-08-01 37680]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CISVC;@%systemroot%\system32\CISVC.EXE,-1; C:\Windows\system32\CISVC.EXE [2009-07-14 19456]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-11-16 735960]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 159336]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SbieSvc;Sandboxie Service; e:\Programy\Sandboxie\SbieSvc.exe [2010-02-03 94440]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 VMAuthdService;VMware Authorization Service; E:\Programy\VMware\vmware-authd.exe [2010-08-01 113200]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\syswow64\vmnetdhcp.exe [2010-08-01 334384]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-08-01 539184]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\syswow64\vmnat.exe [2010-08-01 399920]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\Windows\System32\appdrvrem01.exe [2010-06-21 538000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 23296]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-12 655624]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 160784]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2009-07-16 316664]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 ufad-ws60;VMware Agent Service; E:\Programy\VMware\vmware-ufad.exe [2010-04-27 191024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-03-22 1255736]
-----------------EOF-----------------
Vždycky jsou na oddílu E:\ (tam mám programy a hry, tzn. nic systémovýho, spíš jsou poškozený třeba pluginy od Mirandy nebo nějaký knihovny ke hrám...) a jestli jsem to správně odpozoroval, tak to bývá po nepovedeným uspání počítače (asi jednou za 2 týdny se nepovede počítači uspat a po cca 15 minutách se sám natvrdo vypne, nevím proč; pak jsou na discích - podle chkdsk - chyby).
Takže se pokusím aspoň vyloučit (nebo zjistit), že jde o nějakýho červíka apod... Díky za kontrolu!
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jenda at 2010-12-28 12:50:22
Microsoft Windows 7 Professional
System drive C: has 3 GB (11%) free of 31 GB
Total RAM: 4094 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:50:47, on 28.12.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
E:\Programy\DAEMON Tools Lite\daemon.exe
C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Windows\SysWOW64\rundll32.exe
E:\Programy\Logitech\Logitech WebCam Software\LWS.exe
E:\Programy\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
E:\Programy\Opera\opera.exe
E:\Programy\Miranda IM\miranda32.exe
C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe
I:\setup.exe
C:\Users\Jenda\AppData\Local\Temp\is-VQUA1.tmp\setup.tmp
C:\Users\Jenda\AppData\Local\Temp\is-FCLRJ.tmp\Unpack.dll
C:\Program Files\trend micro\Jenda.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=217.91.70.238:8085
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Programy\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [IR_SERVER] e:\Programy\Realtek\DVB-T USB DEVICE\IR_SERVER.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Programy\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "E:\Programy\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [Corel File Shell Monitor] e:\Programy\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe
O4 - HKLM\..\Run: [Standby] "C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Programy\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\Programy\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Programy\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: e:\programy\vmware\vsocklib.dll
O10 - Unknown file in Winsock LSP: e:\programy\vmware\vsocklib.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Unknown owner - C:\Windows\System32\appdrvrem01.exe (file missing)
O23 - Service: @%systemroot%\system32\CISVC.EXE,-1 (CISVC) - Unknown owner - C:\Windows\system32\CISVC.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - e:\Programy\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - E:\Programy\VMware\vmware-ufad.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - E:\Programy\VMware\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9948 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\CISVC.EXE
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe" -Embedding
"e:\Programy\Sandboxie\SbieSvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe"
C:\Windows\SysWOW64\vmnat.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"E:\Programy\VMware\vmware-authd.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\SysWOW64\vmnetdhcp.exe
"C:\Windows\WindowsMobile\wmdc.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\Microsoft IntelliType Pro\itype.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"E:\Programy\DAEMON Tools Lite\daemon.exe" -autorun
"C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe"
"E:\Programy\Logitech\SetPoint\SetPoint.exe"
"C:\Windows\System32\rundll32.exe" P17RunE.dll,RunDLLEntry
"E:\Programy\Logitech\Logitech WebCam Software\LWS.exe" /hide
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"E:\Programy\Logitech\SetPoint\x86\SetPoint32.exe"
KHALMNPR.EXE /API
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-35ba2861-0189-438a-b59f-fffc6a94af42 -SystemEventPortName:HostProcess-94bfe9ee-c454-4350-b6f2-d3b4585a781d -IoCancelEventPortName:HostProcess-6752e133-0d31-4f0a-a847-dfde80d7e256 -NonStateChangingEventPortName:HostProcess-e145c506-491e-4a4b-b768-82bd8c30d68c -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d9a9b2fc-8364-41e9-9752-72e74b3b6a98
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe" -Embedding
C:\Windows\System32\mobsync.exe -Embedding
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\explorer.exe /factory,{ceff45ee-c862-41de-aee2-a022c81eda92} -Embedding
"E:\Programy\Opera\opera.exe"
"E:\Programy\7-Zip\7zFM.exe" "C:\Users\Jenda\AppData\Local\Opera\Opera\temporary_downloads\uniws.zip"
"taskhost.exe"
"E:\Programy\Miranda IM\miranda32.exe"
"C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -RESTART
"I:\setup.exe"
"C:\Users\Jenda\AppData\Local\Temp\is-VQUA1.tmp\setup.tmp" /SL5="$9075A,7861335,147456,I:\setup.exe"
"C:\Users\Jenda\AppData\Local\Temp\is-FCLRJ.tmp\Unpack.dll" x I:\data-a.bin -y -dp"E:\Hry\Rockstar Games\Grand Theft Auto IV - Episodes From Liberty City"
\??\C:\Windows\system32\conhost.exe
"C:\Users\Jenda\AppData\Local\Opera\Opera\temporary_downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Programy\Java\jre6\bin\jp2ssv.dll [2009-10-23 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2009-06-17 130576]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 660360]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-11-16 2716216]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2009-11-11 2345848]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"DAEMON Tools Lite"=E:\Programy\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"SansaDispatch"=C:\Users\Jenda\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [2010-01-31 79872]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"P17RunE"=RunDll32 P17RunE.dll,RunDLLEntry []
"IR_SERVER"=e:\Programy\Realtek\DVB-T USB DEVICE\IR_SERVER.exe []
"SunJavaUpdateSched"=E:\Programy\Java\jre6\bin\jusched.exe [2009-10-23 149280]
"LogitechQuickCamRibbon"=E:\Programy\Logitech\Logitech WebCam Software\LWS.exe [2009-10-14 2793304]
"Corel File Shell Monitor"=e:\Programy\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe []
"Standby"=C:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe [2010-04-14 105632]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech SetPoint.lnk - E:\Programy\Logitech\SetPoint\SetPoint.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2009-07-20 76816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - C:\Windows\NOTEPAD.EXE %1
======List of files/folders created in the last 1 months======
2010-12-15 21:41:47 ----A---- C:\Windows\system32\mshtml.dll
2010-12-15 21:41:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-12-15 21:41:46 ----A---- C:\Windows\system32\mstime.dll
2010-12-15 21:41:46 ----A---- C:\Windows\system32\iertutil.dll
2010-12-15 21:41:46 ----A---- C:\Windows\system32\ieframe.dll
2010-12-15 21:41:45 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-12-15 21:41:44 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-15 21:41:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-15 21:41:43 ----A---- C:\Windows\system32\wininet.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-15 21:41:42 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\urlmon.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\ieui.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\iepeers.dll
2010-12-15 21:41:42 ----A---- C:\Windows\system32\iedkcs32.dll
2010-12-15 21:41:41 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-12-15 21:41:41 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2010-12-15 21:41:41 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-12-15 21:41:41 ----A---- C:\Windows\system32\msfeedssync.exe
2010-12-15 21:41:41 ----A---- C:\Windows\system32\licmgr10.dll
2010-12-15 21:41:41 ----A---- C:\Windows\system32\jsproxy.dll
2010-12-15 21:41:39 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-15 21:41:39 ----A---- C:\Windows\system32\win32k.sys
2010-12-15 21:41:39 ----A---- C:\Windows\system32\taskschd.dll
2010-12-15 21:41:39 ----A---- C:\Windows\system32\taskeng.exe
2010-12-15 21:41:39 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2010-12-15 21:41:38 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-15 21:41:38 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-15 21:41:38 ----A---- C:\Windows\system32\schtasks.exe
2010-12-15 21:41:38 ----A---- C:\Windows\system32\atmfd.dll
2010-12-15 21:41:37 ----A---- C:\Windows\SYSWOW64\webio.dll
2010-12-15 21:41:37 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-15 21:41:37 ----A---- C:\Windows\system32\webio.dll
2010-12-15 21:41:37 ----A---- C:\Windows\system32\atmlib.dll
2010-12-15 21:41:35 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-15 21:41:35 ----A---- C:\Windows\system32\tzres.dll
2010-12-15 21:41:29 ----A---- C:\Windows\system32\consent.exe
2010-12-13 20:47:04 ----D---- C:\Program Files\Adobe
2010-12-12 10:37:24 ----D---- C:\Program Files (x86)\Microsoft Office
2010-12-06 20:28:45 ----D---- C:\Program Files (x86)\Corel
2010-12-06 20:27:25 ----D---- C:\ProgramData\Corel
2010-12-06 20:21:03 ----D---- C:\ProgramData\Ulead Systems
2010-12-05 21:58:57 ----D---- C:\Users\Jenda\AppData\Roaming\PACE Anti-Piracy
2010-12-05 21:58:57 ----D---- C:\ProgramData\PACE Anti-Piracy
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files\PACE Anti-Piracy
2010-12-05 21:58:57 ----A---- C:\Windows\SurCode.INI
2010-12-05 21:57:32 ----D---- C:\Users\Jenda\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2010-12-05 21:47:28 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2010-12-05 21:43:35 ----D---- C:\Program Files (x86)\Adobe Media Player
2010-12-05 21:43:12 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2010-12-05 21:43:12 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2010-12-05 21:43:12 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2010-12-05 21:43:12 ----D---- C:\Program Files (x86)\My Company Name
2010-12-05 15:06:06 ----A---- C:\Windows\WA.INI
2010-12-02 18:26:38 ----SHD---- C:\ProgramData\SecuROM
2010-12-01 16:49:42 ----D---- C:\Users\Jenda\AppData\Roaming\gtk-2.0
======List of files/folders modified in the last 1 months======
2010-12-28 12:50:47 ----D---- C:\Program Files\trend micro
2010-12-28 12:50:17 ----D---- C:\Windows\Temp
2010-12-28 11:13:06 ----D---- C:\Windows\system32\config
2010-12-28 11:12:59 ----SHD---- C:\System Volume Information
2010-12-28 11:05:55 ----D---- C:\Windows\System32
2010-12-28 11:05:55 ----D---- C:\Windows\inf
2010-12-28 11:05:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-28 11:02:32 ----D---- C:\Windows
2010-12-28 11:01:53 ----D---- C:\ProgramData\VMware
2010-12-28 11:01:45 ----D---- C:\ProgramData\NVIDIA
2010-12-28 10:53:24 ----A---- C:\Windows\ntbtlog.txt
2010-12-27 20:21:56 ----D---- C:\Windows\system32\drivers
2010-12-27 20:21:55 ----D---- C:\Windows\system32\catroot
2010-12-27 20:21:54 ----D---- C:\Windows\system32\DriverStore
2010-12-27 16:50:57 ----D---- C:\Windows\SYSWOW64\drivers
2010-12-27 16:46:59 ----A---- C:\Windows\Sandboxie.ini
2010-12-27 13:46:05 ----SHD---- C:\Windows\Installer
2010-12-27 13:46:00 ----SHD---- C:\Config.Msi
2010-12-27 13:45:52 ----D---- C:\Program Files (x86)\Google
2010-12-27 13:38:15 ----D---- C:\Windows\Prefetch
2010-12-23 11:13:50 ----D---- C:\Program Files (x86)\Common Files
2010-12-21 20:18:39 ----D---- C:\Users\Jenda\AppData\Roaming\FileZilla
2010-12-21 18:23:23 ----D---- C:\Users\Jenda\AppData\Roaming\Mozilla
2010-12-19 12:05:18 ----ASD---- C:\ProgramData\Microsoft
2010-12-17 19:49:20 ----D---- C:\Windows\winsxs
2010-12-17 19:46:54 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-12-17 19:46:54 ----D---- C:\Windows\SysWOW64
2010-12-17 19:46:54 ----D---- C:\Windows\system32\cs-CZ
2010-12-17 19:46:53 ----D---- C:\Program Files\Windows Mail
2010-12-17 19:46:53 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-17 19:46:52 ----D---- C:\Windows\SYSWOW64\migration
2010-12-17 19:46:52 ----D---- C:\Windows\system32\migration
2010-12-17 19:46:52 ----D---- C:\Program Files\Internet Explorer
2010-12-17 19:46:52 ----D---- C:\Program Files (x86)\Internet Explorer
2010-12-15 21:42:37 ----A---- C:\Windows\system32\MRT.exe
2010-12-15 21:41:24 ----D---- C:\Windows\system32\catroot2
2010-12-14 20:18:28 ----AD---- C:\ProgramData\TEMP
2010-12-14 19:14:02 ----RSD---- C:\Windows\Fonts
2010-12-13 21:47:19 ----D---- C:\Users\Jenda\AppData\Roaming\Adobe
2010-12-13 20:50:13 ----D---- C:\Program Files\Common Files\Adobe
2010-12-13 20:47:33 ----SD---- C:\Users\Jenda\AppData\Roaming\Microsoft
2010-12-13 20:47:04 ----RD---- C:\Program Files
2010-12-13 20:46:07 ----D---- C:\ProgramData\Adobe
2010-12-13 20:37:09 ----D---- C:\Program Files (x86)\Adobe
2010-12-12 23:03:20 ----D---- C:\Users\Jenda\AppData\Roaming\VMware
2010-12-12 10:37:29 ----D---- C:\ProgramData\Microsoft Help
2010-12-12 10:37:29 ----A---- C:\Windows\win.ini
2010-12-12 10:37:24 ----RD---- C:\Program Files (x86)
2010-12-06 20:29:03 ----HD---- C:\Windows\msdownld.tmp
2010-12-06 20:27:25 ----HD---- C:\ProgramData
2010-12-06 20:20:43 ----RSD---- C:\Windows\assembly
2010-12-06 20:03:41 ----D---- C:\Windows\SYSWOW64\wbem
2010-12-06 19:54:54 ----D---- C:\Windows\SYSWOW64\Setup
2010-12-06 19:54:54 ----D---- C:\Windows\SYSWOW64\oobe
2010-12-06 19:54:54 ----D---- C:\Windows\SYSWOW64\MUI
2010-12-06 19:54:53 ----D---- C:\Windows\SYSWOW64\DriverStore
2010-12-06 19:54:53 ----D---- C:\Windows\SYSWOW64\config
2010-12-06 19:54:53 ----D---- C:\Windows\SYSWOW64\com
2010-12-06 19:52:31 ----D---- C:\Temp
2010-12-06 19:48:12 ----A---- C:\Windows\WDICT32.INI
2010-12-06 16:43:54 ----D---- C:\Windows\system32\Tasks
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files\System
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-12-05 21:58:57 ----D---- C:\Program Files\Common Files
2010-12-05 21:28:48 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-12-02 18:24:21 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-09-27 871408]
R1 appdrv01;Application Driver (01); C:\Windows\System32\Drivers\appdrv01.sys [2010-06-21 2793064]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2007-02-18 296816]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-11-16 169080]
R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2009-11-16 44944]
R2 hcmon;VMware hcmon; \??\C:\Windows\system32\drivers\hcmon.sys [2010-08-01 38448]
R2 vmci;VMware vmci; \??\C:\Windows\system32\drivers\vmci.sys [2010-08-01 80944]
R2 VMnetBridge;VMware Bridge Protocol; C:\Windows\system32\DRIVERS\vmnetbridge.sys [2010-08-01 45104]
R2 VMnetuserif;VMware Network Application Interface; \??\C:\Windows\system32\drivers\vmnetuserif.sys [2010-08-01 30256]
R2 VMparport;VMware VMparport; \??\C:\Windows\system32\drivers\VMparport.sys [2010-08-01 18480]
R2 vmx86;VMware vmx86; \??\C:\Windows\system32\drivers\vmx86.sys [2010-08-01 68656]
R2 vstor2-ws60;Vstor2 WS60 Virtual Storage Driver; \??\E:\Programy\VMware\vstor2-ws60.sys [2010-04-27 32816]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-06-19 33608]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-26 21832]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2009-06-17 55312]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2009-06-17 57872]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2009-06-17 40976]
R3 lvpopf64;Logitech POP Suppression Filter; C:\Windows\system32\DRIVERS\lvpopf64.sys [2009-10-07 271640]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
R3 LVRS64;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2009-10-07 327704]
R3 LVUSBS64;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBS64.sys [2008-07-26 50072]
R3 LVUVC64;Logitech QuickCam Pro 5000(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2009-10-07 6379288]
R3 P17;SB Live! 24-bit; C:\Windows\system32\drivers\P17.sys [2007-11-16 1276928]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL2832U_IRHID;HID Infrared Remote Receiver; C:\Windows\system32\DRIVERS\RTL2832U_IRHID.sys [2009-07-13 42912]
R3 RTL2832UBDA;REALTEK 2832U BDA Driver; C:\Windows\system32\drivers\RTL2832UBDA.sys [2010-07-01 224488]
R3 RTL2832UUSB;REALTEK 2832U USB Driver; C:\Windows\System32\Drivers\RTL2832UUSB.sys [2010-07-01 39016]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
R3 SbieDrv;SbieDrv; \??\e:\Programy\Sandboxie\SbieDrv.sys [2010-02-03 134760]
R3 vmkbd;VMware kbd; \??\C:\Windows\system32\drivers\VMkbd.sys [2010-08-01 31792]
R3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys [2010-08-01 20016]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2007-01-29 79760]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 L8042Kbd;SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2009-06-17 30736]
S3 LVPr2Mon;LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2009-10-07 30232]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 tapoas;TAP-Win32 Adapter OAS; C:\Windows\system32\DRIVERS\tapoas.sys [2010-07-11 30720]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 vmusb;VMware USB Client Driver; C:\Windows\System32\Drivers\vmusb.sys [2010-08-01 37680]
S3 WinUsb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CISVC;@%systemroot%\system32\CISVC.EXE,-1; C:\Windows\system32\CISVC.EXE [2009-07-14 19456]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-11-16 735960]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2009-10-07 191000]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-07-09 159336]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 SbieSvc;Sandboxie Service; e:\Programy\Sandboxie\SbieSvc.exe [2010-02-03 94440]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
R2 VMAuthdService;VMware Authorization Service; E:\Programy\VMware\vmware-authd.exe [2010-08-01 113200]
R2 VMnetDHCP;VMware DHCP Service; C:\Windows\syswow64\vmnetdhcp.exe [2010-08-01 334384]
R2 VMUSBArbService;VMware USB Arbitration Service; C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe [2010-08-01 539184]
R2 VMware NAT Service;VMware NAT Service; C:\Windows\syswow64\vmnat.exe [2010-08-01 399920]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\Windows\System32\appdrvrem01.exe [2010-06-21 538000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-11-16 23296]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-12 655624]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 160784]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2009-07-16 316664]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 ufad-ws60;VMware Agent Service; E:\Programy\VMware\vmware-ufad.exe [2010-04-27 191024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-03-22 1255736]
-----------------EOF-----------------