Stránka 1 z 1

kontrola Logu, díky

Napsal: 31 pro 2010 11:20
od SGTEAM
Zdravím,
poprosím o kontrolu logu, nějak se mi něco v poslední době nezdá, sice nic co by něco naznačovalo, ale člověk má být opatrný :)

Předem díky

Kód: Vybrat vše

info.txt logfile of random's system information tool 1.08 2010-12-31 11:13:01

======Uninstall list======

-->MsiExec /X{F9835182-794B-4F24-902A-E2CA9D43380F}
7-Zip 4.64-->"C:\Programy\7-Zip\Uninstall.exe"
AAA Logo 3.10 Free Trial-->"C:\Programy\AAALOGO2010\unins000.exe"
Acronis Drive Monitor-->MsiExec.exe /X{706AE61D-40A4-4F50-8359-FE8F6F7FA461}
Adobe AIR-->c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10l_Plugin.exe -maintain plugin
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3-->C:\Program Files (x86)\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Reader 9.4.1 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A94000000001}
Adobe Setup-->MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0405-0000-0000000FF1CE} /uninstall {0A1FAC46-B899-421D-B1A2-470896DC45DB}
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0405-0000-0000000FF1CE} /uninstall {5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0405-0000-0000000FF1CE} /uninstall {E68DD413-B834-4923-8181-0A03B7555187}
All2WAV Recorder 3.20-->"C:\Programy\All2WAV Recorder\unins000.exe"
A-PDF Restrictions Remover 1.6-->"C:\Programy\A-PDF Restrictions Remover\unins000.exe"
Apple Application Support-->MsiExec.exe /I{EE6097DD-05F4-4178-9719-D3170BF098E8}
Apple Mobile Device Support-->MsiExec.exe /I{963BFE7E-C350-4346-B43C-B02358306A45}
Apple Software Update-->MsiExec.exe /I{C41300B9-185D-475E-BFEC-39EF732F19B1}
ATI AVIVO64 Codecs-->MsiExec.exe /X{26113040-1E26-F41F-8D3C-5C22B0006D41}
ATI Catalyst Install Manager-->msiexec /q/x{1647B68B-7193-04C8-CD5D-6CCDAD8E63E9} REBOOT=ReallySuppress
Auto Mouse 1.3-->"C:\Programy\Auto Mouse\unins000.exe"
BattleForge™-->MsiExec.exe /X{C580908C-B3BA-4C19-BD60-16F02F272201}
Bonjour-->MsiExec.exe /X{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}
BS.Player FREE-->"C:\Programy\BSplayer\uninstall.exe"
BusinessCardsMX 3.99-->"C:\Programy\BusinessCardsMX3\unins000.exe"
Call of Duty(R) - World at War(TM) 1.1 Patch-->C:\Program Files (x86)\InstallShield Installation Information\{AFAE2B15-89A0-4215-A030-F7B5B478886B}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) - World at War(TM) 1.2 Patch-->C:\Program Files (x86)\InstallShield Installation Information\{2BF0AE92-C3BC-4112-9066-1546342B1FAE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) - World at War(TM) 1.4 Patch-->C:\Program Files (x86)\InstallShield Installation Information\{9F01A67B-7D67-482F-9D4F-D5980A440FD4}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) - World at War(TM) 1.5 Patch-->C:\Program Files (x86)\InstallShield Installation Information\{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files (x86)\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files (x86)\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
Call of Duty: Black Ops-->"C:\Hry\Call of Duty - Black Ops\unins000.exe"
Call of Duty: Modern Warfare 2 - Multiplayer-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/10190
Call of Duty: Modern Warfare 2-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/10180
Catalyst Control Center - Branding-->MsiExec.exe /I{87323561-58BA-4D5B-BADA-A791B69D1705}
CCleaner-->"C:\Program Files (x86)\CCleaner\uninst.exe"
Cisco AnyConnect VPN Client-->MsiExec.exe /X{0474CEF2-37AE-441D-8FDE-A1EF7EAD01B9}
Cisco Systems VPN Client 5.0.07.0290-->MsiExec.exe /X{467D5E81-8349-4892-9E81-C3674ED8E451}
Combined Community Codec Pack 2008-09-21 16:18-->"C:\Programy\Combined Community Codec Pack\unins000.exe"
Epson Easy Photo Print 2-->C:\Program Files (x86)\InstallShield Installation Information\{DEDB47A3-C988-4A43-A645-E2CEA571E680}\SETUP.EXE -runfromtemp -l0x0009 UNINST -removeonly
EPSON Scan-->C:\Program Files (x86)\epson\escndv\setup\setup.exe /r
EPSON Stylus SX100_TX100 Manuál-->C:\Program Files (x86)\EPSON\TPMANUAL\ESSX100_TX100\CZE\USE_G\DOCUNINS.EXE
EPSON SX100 Series Printer Uninstall-->C:\Windows\system32\spool\DRIVERS\x64\3\E_IINSEDE.EXE /R /APD /P:"EPSON SX100 Series"
ESET Smart Security-->MsiExec.exe /I{A03346F6-0579-4AEB-852C-FBA13914F635}
FeedReader-->"C:\Programy\FeedReader30\unins000.exe"
ffdshow [rev 2280] [2008-11-02]-->"C:\Programy\Combined Community Codec Pack\Filters\FFDShow\unins000.exe"
FileZilla Client 3.3.1-->C:\Programy\FileZilla FTP Client\uninstall.exe
Flash Designer 5 (5.0.22.8)-->C:\Programy\FLASHD~1\Setup.exe /remove
Full Tilt Poker-->C:\Hry\Full Tilt Poker\uninstall.exe
Garena 2010-->C:\Programy\Garena\uninst.exe
GlassFish Server Open Source Edition 3.0.1-->"C:\Program Files\glassfish-3.0.1\uninstall.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->c:\Windows\SysWOW64\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall  /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->c:\Windows\SysWOW64\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {08155812-0202-4D5F-A7FF-12A2782DC548} /qb+ REBOOTPROMPT=""
HydraVision-->MsiExec.exe /X{468C0AC6-8DBF-6074-F202-34DD80E7E2E9}
iTunes-->MsiExec.exe /I{0C682623-8F66-46A8-B9B3-93FE1E66A001}
Java(TM) 6 Update 22 (64-bit)-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F86416022FF}
Java(TM) 6 Update 22-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java(TM) SE Development Kit 6 Update 22 (64-bit)-->MsiExec.exe /I{64A3A4F4-B792-11D6-A78A-00B0D0160220}
LightScribe System Software  1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
Logitech QuickCam-->MsiExec.exe /X{1964A1A7-1FB1-484A-8BD7-AD36F4ABDDED}
LogitechŽ Camera Driver-->"C:\Program Files (x86)\Common Files\LogiShrd\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
Mafia II DLC Jimmy's Vendetta-->"C:\Users\SGTEAM\Desktop\Mafia II\unins000.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - csy-->MsiExec.exe /I{DD73CA82-EA82-38AA-863D-9A24A018DC96}
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY-->c:\Windows\Microsoft.NET\Framework64\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - csy\setup.exe
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework64\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /x64 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{790E02A1-145A-3843-8C13-A4F41C9B48B7}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{1FDA5A37-B22D-43FF-B582-B8964050DC13}
Microsoft Games for Windows - LIVE-->MsiExec.exe /X{86A4C6D9-29EE-4719-AFA1-BA3341862B83}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {E64BA721-2310-4B55-BE5A-2925F9706192}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0405-1000-0000000FF1CE} /uninstall {E12F9D31-4025-4BC6-B1B2-AB262C5580B0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0405-0000-0000000FF1CE} /uninstall {E12F9D31-4025-4BC6-B1B2-AB262C5580B0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0405-0000-0000000FF1CE} /uninstall {1FC5BC34-0301-40D2-9432-05BA220277B8}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2007-->MsiExec.exe /X{90120000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Czech) 2007-->MsiExec.exe /X{90120000-002A-0405-1000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053-->MsiExec.exe /X{B6E3757B-5E77-3915-866A-CCFC4B8D194C}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Mozilla Firefox (3.6.13)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (3.1.7)-->C:\Programy\Mozilla Thunderbird\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nero 9-->C:\Program Files (x86)\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe  REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NetBeans IDE 6.9.1-->"C:\Program Files\NetBeans 6.9.1\uninstall.exe"
NVIDIA PhysX-->MsiExec.exe /X{F9835182-794B-4F24-902A-E2CA9D43380F}
ParadisePoker-->C:\Hry\PARADI~1\UNWISE.EXE C:\Hry\PARADI~1\INSTALL.LOG
PDF Password Cracker Pro v3.2-->"C:\Programy\PDF Password Cracker Pro v3.2\unins000.exe"
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
PokerStars-->"C:\Hry\PokerStars\PokerStarsUninstall.exe" /u:PokerStars
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
RapidShare Manager-->C:\Programy\RapidShareManager\uninstall.exe
RealNetworks - Microsoft Visual C++ 2008 Runtime-->MsiExec.exe /X{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}
RealPlayer-->c:\program files\real\realplayer\Update\r1puninst.exe RealNetworks|RealPlayer|12.0
Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\SETUP.EXE -runfromtemp -l0x0005 -removeonly
Realtek High Definition Audio Driver-->RtlUpd64.exe -r -m -nrg2709
RealUpgrade 1.1-->MsiExec.exe /I{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}
Recuva-->"C:\Programy\Recuva\uninst.exe"
Replay Media Catcher 3.02-->"C:\Windows\Replay Media Catcher\uninstall.exe" "/U:C:\Programy\Replay Media Catcher\Uninstall\uninstall.xml"
Screen Shot Maker 2.5-->"C:\Windows\unins000.exe"
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2289158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {210B16C0-CEBD-4DE9-B474-04A7E8735E16}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)-->c:\Windows\SysWOW64\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {8EAF4926-5B5D-398A-BA46-4603D8095BDE} /qb+ REBOOTPROMPT=""
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3DED0A62-44C8-4E00-A785-5212F297A9D9}
Security Update for Microsoft Office Publisher 2007 (KB2284697)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3A4CDE54-2403-483D-8D9A-15E3264410DF}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Skype™ 5.0-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
SlimStar 220-->C:\Program Files (x86)\InstallShield Installation Information\{ED5DCA6F-5FEA-47CB-83DB-210A468C298B}\setup.exe -runfromtemp -l0x0009 -removeonly
StarCraft II-->C:\Program Files (x86)\Common Files\Blizzard Entertainment\StarCraft II\Uninstall.exe
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Total Commander (Remove or Repair)-->c:\Programy\totalcmd\tcuninst.exe
Update for 2007 Microsoft Office System (KB2284654)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {FB166E7C-8AA6-48C8-B726-1F25BEE7825A}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->c:\Windows\SysWOW64\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office Outlook 2007 (KB2412171)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7961E819-93A5-40A8-8469-4BE2FBBFACEF}
Update for Outlook 2007 Junk Email Filter (KB2466076)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {EE71630C-C756-4343-B620-DB5958609E3D}
Windows Live ID Sign-in Assistant-->MsiExec.exe /X{9B48B0AC-C813-4174-9042-476A887592C7}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
World of Warcraft FREE Trial-->MsiExec.exe /X{02EBDBB9-4600-41D3-B566-40CB861511D2}
World of Warcraft-->C:\Program Files (x86)\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
Xvid 1.1.3 final uninstall-->"C:\Program Files (x86)\Xvid\unins000.exe"

======Hosts File======

127.0.0.1       gosredirector.ea.com
127.0.0.1       blazeserver.blazeemu.org
127.0.0.1       gosgvaprod-qos01.ea.com
127.0.0.1       gosiadprod-qos01.ea.com
127.0.0.1       gossjcprod-qos01.ea.com
127.0.0.1       demangler.ea.com
127.0.0.1       vmp.tools.gos.ea.com
127.0.0.1       gosredirector.ea.com
127.0.0.1       blazeserver.blazeemu.org
127.0.0.1       gosgvaprod-qos01.ea.com

======Security center information======

AV: ESET Smart Security 3.0
FW: ESET personal firewall
AS: ESET Smart Security 3.0
AS: Windows Defender

======System event log======

Computer Name: SGTEAM-PC
Event Code: 4371
Message: Slu·ba Windows Servicing zahájila proces změny stavu balíčku KB976098(Update) z Nainstalováno(Installed) na Nainstalováno(Installed).
Record Number: 338661
Source Name: Microsoft-Windows-Servicing
Time Written: 20100930084441.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: SGTEAM-PC
Event Code: 4371
Message: Slu·ba Windows Servicing zahájila proces změny stavu balíčku KB979306(Update) z Nainstalováno(Installed) na Nainstalováno(Installed).
Record Number: 338660
Source Name: Microsoft-Windows-Servicing
Time Written: 20100930084441.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: SGTEAM-PC
Event Code: 4371
Message: Slu·ba Windows Servicing zahájila proces změny stavu balíčku KB979306(Update) z Nainstalováno(Installed) na Nainstalováno(Installed).
Record Number: 338659
Source Name: Microsoft-Windows-Servicing
Time Written: 20100930084441.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: SGTEAM-PC
Event Code: 4371
Message: Slu·ba Windows Servicing zahájila proces změny stavu balíčku KB981793(Update) z Nainstalováno(Installed) na Nainstalováno(Installed).
Record Number: 338658
Source Name: Microsoft-Windows-Servicing
Time Written: 20100930084441.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: SGTEAM-PC
Event Code: 4371
Message: Slu·ba Windows Servicing zahájila proces změny stavu balíčku KB981793(Update) z Nainstalováno(Installed) na Nainstalováno(Installed).
Record Number: 338657
Source Name: Microsoft-Windows-Servicing
Time Written: 20100930084440.000000-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Application event log=====

Computer Name: SGTEAM-PC
Event Code: 6000
Message: Odběratel oznámení přihla±ování do systému Windows <SessionEnv> nemohl zpracovat událost upozornění.
Record Number: 43454
Source Name: Microsoft-Windows-Winlogon
Time Written: 20091009162039.000000-000
Event Type: Informace
User: 

Computer Name: SGTEAM-PC
Event Code: 4101
Message: Byla ověřena platnost licence systému Windows.
Record Number: 43453
Source Name: Microsoft-Windows-Winlogon
Time Written: 20091009162039.000000-000
Event Type: Informace
User: 

Computer Name: SGTEAM-PC
Event Code: 902
Message: Slu·ba Licencování softwaru byla spu±těna.

Record Number: 43452
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091009162036.000000-000
Event Type: Informace
User: 

Computer Name: SGTEAM-PC
Event Code: 1005
Message: Výsledek vyu·ití oprávnění systému Windows je: hr=0x0

Record Number: 43451
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091009162036.000000-000
Event Type: Informace
User: 

Computer Name: SGTEAM-PC
Event Code: 1003
Message: Slu·ba Licencování softwaru dokončila kontrolu stavu licencování.
ID aplikace=55c92734-d682-4d71-983e-d6ec3f16059f
Stav licencování=
{1,[0101b69a-85c8-4344-8196-7a16a7790bb5, 8, 0xC004F014,0x0]}

{1,[093e8e65-b6ab-4526-ab64-ae4e8269b656, 8, 0xC004F014,0x0]}

{1,[177df7ed-709f-454a-91bd-947ec8a1e668, 8, 0xC004F014,0x0]}

{1,[212a64dc-43b1-4d3d-a30c-2fc69d2095c6, 8, 0xC004F014,0x0]}

{1,[4871de8b-3adf-4455-a7d3-fd7b6c01c939, 8, 0xC004F014,0x0]}

{1,[4f3d1606-3fea-4c01-be3c-8d671c401e3b, 8, 0xC004F014,0x0]}

{1,[74e464f6-45db-41f6-9356-66260bdf3c65, 8, 0xC004F014,0x0]}

{1,[829a4bc1-2a89-47ba-a638-0b8a206b0986, 8, 0xC004F014,0x0]}

{1,[9de9abe2-d01d-4538-af84-4498bdbc2ba3, 0, 0x0,0x0],[0x0,0x0,0x0,0,0,0x0],[0x0,0xFFFFFFFF,0x0,0,0,0x0],[0x0,0xFFFFFFFF,0x0,0,0,0x0],[0,0,0x0]}

{1,[b13b0123-8661-4ee2-afb7-05c37481686b, 8, 0xC004F014,0x0]}

{1,[f14a0fcc-9198-49d0-9b48-61398a545aae, 8, 0xC004F014,0x0]}

{1,[f758e09b-7c7c-492c-b78c-aba5bd4e3f5b, 8, 0xC004F014,0x0]}

{1,[faba8d9b-3ad6-4529-b11d-d41ec9b5d47b, 8, 0xC004F014,0x0]}

{1,[fd3bcb98-5c55-4b2d-ae32-a4515e3c17a3, 8, 0xC004F014,0x0]}

{1,[afd5f68f-b70f-4000-a21d-28dbc8be8b07, 0, 0xC004F055,0x0]}

Record Number: 43450
Source Name: Microsoft-Windows-Security-Licensing-SLC
Time Written: 20091009162036.000000-000
Event Type: Informace
User: 

=====Security event log=====

Computer Name: SGTEAM-PC
Event Code: 4648
Message: Do±lo k pokusu o přihlá±ení pomocí explicitního pověření.

Předmět:
	ID zabezpečení:		S-1-5-18
	Název účtu:		SGTEAM-PC$
	Doména účtu:		DOMA
	ID přihlá±ení:		0x3e7
	GUID přihlá±ení:		{00000000-0000-0000-0000-000000000000}

Účet, jeho· pověření bylo pou·ito:
	Název účtu:		SYSTEM
	Doména účtu:		NT AUTHORITY
	GUID přihlá±ení:	{00000000-0000-0000-0000-000000000000}

Cílový server:
	Název cílového serveru:	localhost
	Dal±í informace:	localhost

Informace o procesu:
	ID procesu:		0x294
	Název procesu:		C:\Windows\System32\services.exe

Informace o síti:
	Sí¶ová adresa:	-
	Port:			-

Tato událost je generována, pokud se proces pokusí přihlásit k účtu explicitním zadáním pověření tohoto účtu. K tomu nejčastěji dochází v dávkových konfiguracích, například naplánovaných úlohách, nebo při pou·ití příkazu RUNAS.
Record Number: 52989
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100422171047.124925-000
Event Type: Úspěch auditu
User: 

Computer Name: SGTEAM-PC
Event Code: 4672
Message: Novému přihlá±ení byla přiřazena zvlá±tní oprávnění.

Předmět:
	ID zabezpečení:		S-1-5-19
	Název účtu:		LOCAL SERVICE
	Doména účtu:		NT AUTHORITY
	ID přihlá±ení:		0x3e5

Oprávnění:		SeAssignPrimaryTokenPrivilege
			SeAuditPrivilege
			SeImpersonatePrivilege
Record Number: 52988
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100422171047.046925-000
Event Type: Úspěch auditu
User: 

Computer Name: SGTEAM-PC
Event Code: 4624
Message: Účet byl úspě±ně přihlá±en.

Předmět:
	ID zabezpečení:		S-1-5-18
	Název účtu:		SGTEAM-PC$
	Doména účtu:		DOMA
	ID přihlá±ení:		0x3e7

Typ přihlá±ení:			5

Nové přihlá±ení:
	ID zabezpečení:		S-1-5-19
	Název účtu:		LOCAL SERVICE
	Doména účtu:		NT AUTHORITY
	ID přihlá±ení:		0x3e5
	GUID přihlá±ení:		{00000000-0000-0000-0000-000000000000}

Informace o procesu:
	ID procesu:		0x294
	Název procesu:		C:\Windows\System32\services.exe

Informace o síti:
	Název pracovní stanice:	
	Adresa zdrojové sítě	-
	Zdrojový port:		-

Podrobné informace o ověření:
	Proces přihlá±ení:		Advapi  
	Balíček ověření:	Negotiate
	Přenosové slu·by:	-
	Název balíčku (pouze NTLM):	-
	Délka klíče:		0

Tato událost je generována po vytvoření relace přihlá±ení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který po·adoval přihlá±ení. Jedná se nejčastěji o slu·bu, například slu·bu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlá±ení označuje, k jakému typu přihlá±ení do±lo. Nejbě·něj±í typy jsou 2 (interaktivní) a 3 (sí¶).

Pole Nové přihlá±ení označují účet, pro který bylo nové přihlá±ení vytvořeno, tj. účet, který byl přihlá±en.

Pole Sí¶ označují původ po·adavku na vzdálené přihlá±ení. Název pracovní stanice není v·dy k dispozici a v některých případech mů·e být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním po·adavku na přihlá±ení.
	- GUID přihlá±ení je jednoznačný identifikátor, který je mo·né pou·ít ke spojení této události s událostí KDC.
	- Přenosové slu·by označují, které pomocné slu·by se podílely na tomto po·adavku na přihlá±ení.
	- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl pou·it.
	- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl po·adován ·ádný klíč relace.
Record Number: 52987
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100422171047.046925-000
Event Type: Úspěch auditu
User: 

Computer Name: SGTEAM-PC
Event Code: 4672
Message: Novému přihlá±ení byla přiřazena zvlá±tní oprávnění.

Předmět:
	ID zabezpečení:		S-1-5-18
	Název účtu:		SYSTEM
	Doména účtu:		NT AUTHORITY
	ID přihlá±ení:		0x3e7

Oprávnění:		SeAssignPrimaryTokenPrivilege
			SeTcbPrivilege
			SeSecurityPrivilege
			SeTakeOwnershipPrivilege
			SeLoadDriverPrivilege
			SeBackupPrivilege
			SeRestorePrivilege
			SeDebugPrivilege
			SeAuditPrivilege
			SeSystemEnvironmentPrivilege
			SeImpersonatePrivilege
Record Number: 52986
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100422171046.859724-000
Event Type: Úspěch auditu
User: 

Computer Name: SGTEAM-PC
Event Code: 4624
Message: Účet byl úspě±ně přihlá±en.

Předmět:
	ID zabezpečení:		S-1-5-18
	Název účtu:		SGTEAM-PC$
	Doména účtu:		DOMA
	ID přihlá±ení:		0x3e7

Typ přihlá±ení:			5

Nové přihlá±ení:
	ID zabezpečení:		S-1-5-18
	Název účtu:		SYSTEM
	Doména účtu:		NT AUTHORITY
	ID přihlá±ení:		0x3e7
	GUID přihlá±ení:		{00000000-0000-0000-0000-000000000000}

Informace o procesu:
	ID procesu:		0x294
	Název procesu:		C:\Windows\System32\services.exe

Informace o síti:
	Název pracovní stanice:	
	Adresa zdrojové sítě	-
	Zdrojový port:		-

Podrobné informace o ověření:
	Proces přihlá±ení:		Advapi  
	Balíček ověření:	Negotiate
	Přenosové slu·by:	-
	Název balíčku (pouze NTLM):	-
	Délka klíče:		0

Tato událost je generována po vytvoření relace přihlá±ení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který po·adoval přihlá±ení. Jedná se nejčastěji o slu·bu, například slu·bu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlá±ení označuje, k jakému typu přihlá±ení do±lo. Nejbě·něj±í typy jsou 2 (interaktivní) a 3 (sí¶).

Pole Nové přihlá±ení označují účet, pro který bylo nové přihlá±ení vytvořeno, tj. účet, který byl přihlá±en.

Pole Sí¶ označují původ po·adavku na vzdálené přihlá±ení. Název pracovní stanice není v·dy k dispozici a v některých případech mů·e být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním po·adavku na přihlá±ení.
	- GUID přihlá±ení je jednoznačný identifikátor, který je mo·né pou·ít ke spojení této události s událostí KDC.
	- Přenosové slu·by označují, které pomocné slu·by se podílely na tomto po·adavku na přihlá±ení.
	- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl pou·it.
	- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl po·adován ·ádný klíč relace.
Record Number: 52985
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100422171046.859724-000
Event Type: Úspěch auditu
User: 

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Programy\MySQL\MySQL Server 5.1\bin;C:\Program Files (x86)\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=4
"asl.log"=Destination=file;OnFirstLog=command,environment,parent
"CLASSPATH"=.;C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files (x86)\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------

Re: kontrola Logu, díky

Napsal: 31 pro 2010 12:48
od vyosek
Zdravim a pekny den preji :)

:arrow: Nedavejte prosim logy do code, spatne se to lusti a boli z toho oci

:arrow: Poprosim i o druhy log z RSIT s nazvem log.txt, je ulozen v c:\rsit

:arrow: Predpokladam ze balicek ESET Smart Security mate legalni = zakoupena licence :???:

:arrow: Tohle asi moc legalni aplikace nebude co - PDF Password Cracker Pro v3.2 :?:

Re: kontrola Logu, díky

Napsal: 31 pro 2010 18:42
od SGTEAM
Za code se omlouvám, druhý log přikládám, ESET SS bohužel už legální není, PDF Password Cracker byl pro otestování prolomení vlastní knihy v PDF, jestli je legální už netuším :) Předem díky.

Logfile of random's system information tool 1.08 (written by random/random)
Run by SGTEAM at 2010-12-31 11:12:41
MicrosoftŽ Windows Vista™ Business Service Pack 2
System drive C: has 272 GB (57%) free of 477 GB
Total RAM: 4094 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:12:50, on 31.12.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Windows\MHotKey.exe
C:\Programy\FeedReader30\feedreader.exe
C:\Programy\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Windows\HKExt3.exe
C:\Program Files (x86)\Acronis - disk_hlidac\DriveMonitor\adm_tray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\real\realplayer\Update\realsched.exe
C:\Users\SGTEAM\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\ChiFuncExt.exe
C:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Programy\Skype\Plugin Manager\skypePM.exe
C:\Programy\QIP Infium\infium.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\SGTEAM.exe
c:\program files\real\realplayer\RealPlay.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LchDrvKey] LchDrvKey.exe
O4 - HKLM\..\Run: [HKExt3] HKExt3.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [adm_tray.exe] C:\Program Files (x86)\Acronis - disk_hlidac\DriveMonitor\adm_tray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programy\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE /FU "C:\Windows\TEMP\E_S204C.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [feedreader.exe] "C:\Programy\FeedReader30\feedreader.exe"
O4 - HKCU\..\Run: [EPSON SX100 Series (kopie 1)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE /FU "C:\Windows\TEMP\E_S9B20.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Skype] "C:\Programy\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: CurseClientStartup.ccip
O4 - Startup: Dropbox.lnk = C:\Users\SGTEAM\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: Noto.lnk = C:\Programy\Window Gadgets\Noto.exe
O4 - Startup: SAM.lnk = C:\Programy\SAM\SAM.exe
O4 - Global Startup: vpngui.exe.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Hry\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Hry\PartyGaming\PartyPoker\RunApp.exe (file missing)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7ACF8902-163E-4A9A-880B-B46B3FF13F09}: NameServer = 62.129.50.20,85.135.32.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{7ACF8902-163E-4A9A-880B-B46B3FF13F09}: NameServer = 62.129.50.20,85.135.32.100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programy\VPN Client\cvpnd.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\Programy\MySQL\MySQL.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Programy\MySQL\MySQL.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11774 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"
C:\Windows\system32\svchost.exe -k netsvcs
"c:\program files (x86)\common files\logishrd\lvmvfm\LVPrS64H.exe" -Embedding
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe"
atieclxx
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-a484b417-b43b-4557-9742-3cb9234f0f01 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-b30baab2-2a50-41f7-a628-2b471683933d -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-9df02d10-57da-470b-8526-5f0149024e0a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f661453c-3c39-49d3-9100-583f824f97de
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Programy\VPN Client\cvpnd.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe"
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-78eb1130-c3d2-4852-b526-2060242ae024 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-83347231-a10d-4e75-adef-56175ff74c25 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-cd21bc70-bbef-4133-bf87-145468f19ce5 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a7fbe271-1d65-425a-ad67-573d12bcef5c
WLIDSvcM.exe 2288
taskeng.exe {658379A4-7DC6-445B-B322-BB29DECE425D}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe" /keymon
taskeng.exe {21EC37AA-80C1-4C02-A91D-035547DFDD07}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\MHotKey.exe
"C:\Windows\RAVCpl64.exe"
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
"C:\Programy\FeedReader30\feedreader.exe"
"C:\Programy\Skype\Phone\Skype.exe" /nosplash /minimized
"C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
"C:\Windows\HKExt3.exe"
"C:\Program Files (x86)\Acronis - disk_hlidac\DriveMonitor\adm_tray.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\real\realplayer\Update\realsched.exe" -osboot
"C:\Users\SGTEAM\AppData\Roaming\Dropbox\bin\Dropbox.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\ChiFuncExt.exe
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\iTunes\iTunes.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe" --pipe \\.\pipe\3012423313213761016104968 --parentPipe
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe"
"C:\Users\SGTEAM\AppData\Local\Apps\2.0\HXOP1C6D.1DD\8Y00XD78.J5K\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\CurseClient.exe"
C:\Windows\system32\conime.exe
C:\Windows\system32\conime.exe
"C:\Programy\Skype\Plugin Manager\skypePM.exe" /SILENT
"C:\Programy\QIP Infium\infium.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe8_ Global\UsGthrCtrlFltPipeMssGthrPipe8 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 656 660 668 65536 664
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=7116.dda44a0.23040156 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" 7116 plugin \\.\pipe\gecko-crash-server-pipe.7116
"C:\Users\SGTEAM\Desktop\RSITx64.exe"
"c:\program files\real\realplayer\\RealPlay.exe" /runevent "c:\program files\real\realplayer\rpwa3260.dll" WatchFolders_Timer

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-03 49440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-11-27 382720]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-09-15 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RAVCpl64.exe [2008-06-27 6453760]
"Skytel"=C:\Windows\Skytel.exe [2008-06-25 1826816]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-10-07 1923640]
"Acronis Scheduler2 Service"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2009-10-27 462328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EPSON SX100 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [2008-02-05 221696]
"feedreader.exe"=C:\Programy\FeedReader30\feedreader.exe [2009-03-29 2058240]
"EPSON SX100 Series (kopie 1)"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEDE.EXE [2008-02-05 221696]
"Skype"=C:\Programy\Skype\Phone\Skype.exe [2010-10-11 14940040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Programy\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files (x86)\Logitech\QuickCam10\QuickCam10.exe [2007-05-17 780312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Java\jre6\bin\jusched.exe []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"LogitechCommunicationsManager"=C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-05-17 505368]
"LchDrvKey"=C:\Windows\LchDrvKey.exe [2007-03-28 36864]
"HKExt3"=C:\Windows\HKExt3.exe [2008-09-16 313856]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-07-30 98304]
"adm_tray.exe"=C:\Program Files (x86)\Acronis - disk_hlidac\DriveMonitor\adm_tray.exe [2010-06-04 530768]
"Adobe Reader Speed Launcher"=C:\Programy\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"AppleSyncNotifier"=C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [2010-10-08 47904]
"TkBellExe"=C:\Program Files\real\realplayer\update\realsched.exe [2010-11-27 274608]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2010-12-13 421160]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
vpngui.exe.lnk - C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe

C:\Users\SGTEAM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
CurseClientStartup.ccip
Dropbox.lnk - C:\Users\SGTEAM\AppData\Roaming\Dropbox\bin\Dropbox.exe
Noto.lnk - C:\Programy\Window Gadgets\Noto.exe
SAM.lnk - C:\Programy\SAM\SAM.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"BindDirectlyToPropertySetStorage"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======List of files/folders created in the last 1 months======

2010-12-31 11:12:42 ----D---- C:\Program Files\trend micro
2010-12-31 11:12:41 ----D---- C:\rsit
2010-12-19 14:47:36 ----D---- C:\Program Files\iPod
2010-12-19 14:47:34 ----D---- C:\Program Files\iTunes
2010-12-19 14:47:34 ----D---- C:\Program Files (x86)\iTunes
2010-12-15 12:36:07 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2010-12-15 12:36:07 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2010-12-15 12:36:07 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2010-12-15 12:36:07 ----A---- C:\Windows\system32\fontsub.dll
2010-12-15 12:36:07 ----A---- C:\Windows\system32\atmlib.dll
2010-12-15 12:36:07 ----A---- C:\Windows\system32\atmfd.dll
2010-12-15 12:36:00 ----A---- C:\Windows\system32\consent.exe
2010-12-15 12:35:58 ----A---- C:\Windows\system32\win32k.sys
2010-12-15 12:35:54 ----A---- C:\Windows\system32\mshtml.dll
2010-12-15 12:35:53 ----A---- C:\Windows\system32\mstime.dll
2010-12-15 12:35:53 ----A---- C:\Windows\system32\ieframe.dll
2010-12-15 12:35:52 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-12-15 12:35:52 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-12-15 12:35:51 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-12-15 12:35:51 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2010-12-15 12:35:51 ----A---- C:\Windows\system32\msfeeds.dll
2010-12-15 12:35:50 ----A---- C:\Windows\system32\mshtmled.dll
2010-12-15 12:35:49 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-12-15 12:35:49 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-12-15 12:35:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2010-12-15 12:35:49 ----A---- C:\Windows\system32\wininet.dll
2010-12-15 12:35:49 ----A---- C:\Windows\system32\urlmon.dll
2010-12-15 12:35:49 ----A---- C:\Windows\system32\iepeers.dll
2010-12-15 12:35:48 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-12-15 12:35:48 ----A---- C:\Windows\SYSWOW64\ieencode.dll
2010-12-15 12:35:48 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2010-12-15 12:35:48 ----A---- C:\Windows\system32\ieencode.dll
2010-12-15 12:35:48 ----A---- C:\Windows\system32\ieapfltr.dll
2010-12-15 12:35:40 ----A---- C:\Windows\SYSWOW64\tzres.dll
2010-12-15 12:35:40 ----A---- C:\Windows\system32\tzres.dll
2010-12-15 12:35:30 ----A---- C:\Windows\system32\schedsvc.dll
2010-12-15 12:35:29 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2010-12-15 12:35:29 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2010-12-15 12:35:29 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2010-12-15 12:35:29 ----A---- C:\Windows\system32\wmicmiplugin.dll
2010-12-15 12:35:29 ----A---- C:\Windows\system32\taskschd.dll
2010-12-15 12:35:29 ----A---- C:\Windows\system32\taskeng.exe
2010-12-15 12:35:29 ----A---- C:\Windows\system32\taskcomp.dll
2010-12-13 04:08:52 ----A---- C:\Windows\crackpdf.INI
2010-12-13 03:52:39 ----D---- C:\Program Files (x86)\ElcomSoft
2010-12-12 12:32:39 ----D---- C:\Program Files\glassfish-3.0.1

======List of files/folders modified in the last 1 months======

2010-12-31 11:12:50 ----D---- C:\Windows\Prefetch
2010-12-31 11:12:49 ----D---- C:\Windows\Temp
2010-12-31 11:12:42 ----RD---- C:\Program Files
2010-12-31 11:08:17 ----D---- C:\Windows\system32\Tasks
2010-12-31 11:00:02 ----D---- C:\Users\SGTEAM\AppData\Roaming\Skype
2010-12-31 10:00:21 ----D---- C:\Users\SGTEAM\AppData\Roaming\Dropbox
2010-12-31 10:00:19 ----D---- C:\Users\SGTEAM\AppData\Roaming\skypePM
2010-12-31 02:01:41 ----D---- C:\Users\SGTEAM\AppData\Roaming\FileZilla
2010-12-31 01:02:36 ----SHD---- C:\System Volume Information
2010-12-27 13:38:46 ----D---- C:\Users\SGTEAM\AppData\Roaming\vlc
2010-12-26 19:34:11 ----D---- C:\ProgramData\Blizzard Entertainment
2010-12-26 19:34:05 ----D---- C:\Hry
2010-12-26 19:33:33 ----RD---- C:\Program Files (x86)
2010-12-24 15:33:03 ----D---- C:\Program Files (x86)\Steam
2010-12-24 00:20:58 ----D---- C:\Users\SGTEAM\AppData\Roaming\Adobe
2010-12-19 14:48:36 ----SHD---- C:\Windows\Installer
2010-12-19 14:43:15 ----D---- C:\Program Files (x86)\QuickTime
2010-12-19 14:43:03 ----D---- C:\Windows\SysWOW64
2010-12-16 10:26:46 ----D---- C:\Windows\system32\catroot2
2010-12-16 00:32:11 ----D---- C:\Windows
2010-12-15 23:03:38 ----D---- C:\Users\SGTEAM\AppData\Roaming\SQL Developer
2010-12-15 14:14:02 ----D---- C:\Windows\rescache
2010-12-15 14:08:30 ----D---- C:\Windows\winsxs
2010-12-15 13:58:23 ----D---- C:\Windows\system32\catroot
2010-12-15 13:55:28 ----D---- C:\Windows\System32
2010-12-15 13:55:28 ----D---- C:\Program Files\Windows Mail
2010-12-15 13:55:28 ----D---- C:\Program Files (x86)\Windows Mail
2010-12-15 13:55:26 ----D---- C:\Windows\SYSWOW64\cs-CZ
2010-12-15 13:55:26 ----D---- C:\Windows\system32\cs-CZ
2010-12-15 13:15:52 ----D---- C:\ProgramData\Microsoft Help
2010-12-15 13:13:23 ----A---- C:\Windows\system32\mrt.exe
2010-12-14 13:31:57 ----D---- C:\Windows\inf
2010-12-14 13:31:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-12-13 04:08:41 ----D---- C:\Programy
2010-12-12 12:32:37 ----D---- C:\Program Files\NetBeans 6.9.1
2010-12-10 18:33:41 ----D---- C:\Program Files (x86)\Mozilla Firefox
2010-12-07 18:42:50 ----HD---- C:\ProgramData
2010-12-07 15:31:04 ----D---- C:\Users\SGTEAM\AppData\Roaming\dvdcss

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-01-29 868848]
R1 easdrv;easdrv; C:\Windows\system32\DRIVERS\easdrv.sys [2009-10-07 54232]
R1 epfwtdi;epfwtdi; C:\Windows\system32\DRIVERS\epfwtdi.sys [2009-10-07 68616]
R2 eamon;EAMON; C:\Windows\system32\DRIVERS\eamon.sys [2009-10-07 44944]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2009-10-07 82536]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-07-30 7195648]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-07-30 265728]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 122384]
R3 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [2010-03-23 304784]
R3 DNE;Deterministic Network Enhancer Miniport; C:\Windows\system32\DRIVERS\dne64x.sys [2008-11-16 157968]
R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys [2009-10-07 33608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2008-06-27 1474840]
R3 LVcKap64;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap64.sys [2007-05-11 1548832]
R3 lvpepf64;Volume Adapter; C:\Windows\system32\DRIVERS\lv302a64.sys [2007-05-10 16032]
R3 LVPr2M64;Logitech LVPr2M64 Driver; C:\Windows\system32\DRIVERS\LVPr2M64.sys [2007-05-11 30496]
R3 LVUSBS64;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBS64.sys [2007-05-12 50208]
R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V64.SYS [2007-05-10 1127328]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [2008-02-14 160768]
R3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2010-09-28 51712]
R3 usbaudio;Ovladač zvuků USB (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 98944]
R3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 46592]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 108544]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-07-30 7195648]
S3 ay7j6se1;ay7j6se1; C:\Windows\system32\drivers\ay7j6se1.sys []
S3 CVirtA;Cisco Systems VPN Adapter for 64-bit Windows; C:\Windows\system32\DRIVERS\CVirtA64.sys [2010-02-08 14992]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-02-04 20544]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Programy\Garena\plugins\UI\safedrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2010-02-03 33856]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro slu·bu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 275456]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-05-11 2034208]
S3 MSKSSRV;Server proxy slu·by datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 11008]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 7936]
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2010-04-19 22528]
S3 RDPDISPM;RDPDISPM; C:\Windows\system32\DRIVERS\rdpdispm.sys [2010-06-24 10576]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 41984]
S3 vpnva;Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64; C:\Windows\system32\DRIVERS\vpnva64.sys [2010-08-16 22752]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2009-10-27 881688]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-07-30 203264]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-10-16 37664]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Programy\VPN Client\cvpnd.exe [2010-03-23 1528616]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2009-10-07 472280]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe [2007-05-11 254752]
R2 LVPrcS64;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-05-11 172320]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2009-01-30 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2009-01-30 103736]
R2 vpnagent;Cisco AnyConnect VPN Agent; C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2010-08-16 592120]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-12-13 932640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-05-11 171296]
S2 MySQL;MySQL; C:\Programy\MySQL\MySQL Server 5.1\bin\mysqld --defaults-file=C:\Programy\MySQL\MySQL Server 5.1\my.ini MySQL []
S2 MySQL5;MySQL5; C:\Programy\MySQL\MySQL Server 5.1\bin\mysqld --defaults-file=C:\Programy\MySQL\MySQL Server 5.1\my.ini MySQL5 []
S3 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-07-27 345376]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-10-07 23296]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-04-16 654848]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 27648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-19 19968]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2010-11-17 403240]
S3 WPFFontCache_v0400;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]

-----------------EOF-----------------

Re: kontrola Logu, díky

Napsal: 31 pro 2010 19:14
od vyosek
SGTEAM píše:...ESET SS bohužel už legální není..
Dle pravidel fora (viz zde a a zde bod c.3 ) se nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava Obrázek, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora :!:
Obstarejte si proto legalni ochranu Vaseho PC (antivir), pote sem vlozte novy log z RSITu a CKScanneru - viz nize.

Osobne Vam doporucuji Avast ci Aviru. Prehled antiviru mate ZDE.

:arrow: Log z RSITu - viz muj podpis
:arrow: Stahnete na plochu CKScanner
  • Spustte a kliknete na Search for files
  • Po dokonceni skenu kliknete na Save List to File a nasledne OK
  • Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte

Re: kontrola Logu, díky

Napsal: 01 led 2011 12:54
od SGTEAM
Avast mám předplacený z firemní licence na další 3 roky, dělal neplechu, odinstaloval sem minulý rok.
Objednána licence na 1 rok pro Eset SS, pro klid svědomí.

CKScanner - Additional Security Risks - These are not necessarily bad
c:\hry\call of duty - black ops\zone\common\mp_cracked.ff
c:\hry\call of duty - black ops\zone\english\en_mp_cracked.ff
c:\hry\partygaming\partycasino\language\en_us\images\flashlobby\lobby\safecrackerkeno.swf
c:\hry\partygaming\partycasino\language\en_us\images\flashlobby\lobby\safecrackerkeno_popup.swf
c:\hry\warcraft iii\replay\bonecracker._vs_gaze._1_finale.w3g
c:\hry\warcraft iii\replay\bonecracker._vs_gaze._2_finale.w3g
c:\hry\warcraft iii\replay\bonecracker._vs_gaze._3_finale.w3g
c:\hry\warcraft iii\replay\bonecracker._vs_gaze._4_finale.w3g
c:\hry\warcraft iii\replay\bonecracker._vs_gaze._5_finale.w3g
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\fp-1.1\java\security\spec\rsakeygenparameterspec.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\fp-1.1\java\security\spec\class-use\rsakeygenparameterspec.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\jce10\javax\crypto\keygenerator.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\jce10\javax\crypto\keygeneratorspi.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\jce10\javax\crypto\class-use\keygenerator.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\jce10\javax\crypto\class-use\keygeneratorspi.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\pbp11\java\security\spec\rsakeygenparameterspec.html
c:\program files\netbeans 6.9.1\mobility\java_me_platform_sdk_3.0\docs\api\pbp11\java\security\spec\class-use\rsakeygenparameterspec.html
c:\programy\garena\plugins\ui\avoidcrackplugin.dll
c:\programy\pdf password cracker pro v3.2\crackpdf.exe
c:\programy\pdf password cracker pro v3.2\crackpdf.log
c:\programy\pdf password cracker pro v3.2\crackpdf.url
c:\programy\pdf password cracker pro v3.2\help.htm
c:\programy\pdf password cracker pro v3.2\password.dic
c:\programy\pdf password cracker pro v3.2\skinmagic.dll
c:\programy\pdf password cracker pro v3.2\unins000.dat
c:\programy\pdf password cracker pro v3.2\unins000.exe
c:\programy\pdf password cracker pro v3.2\xpgrean.smf
c:\programy\qip infium\profiles\sgteam\rcvdfiles\inficq_278593067\sdmenu\rufull.ru.crack.sothink_dhtml_menu_8.3_build_71210.rar
c:\windows\crackpdf.ini
scanner sequence 3.ZZ.11
----- EOF -----

Re: kontrola Logu, díky

Napsal: 01 led 2011 14:58
od vyosek
:arrow: Ke crackum nema cenu se vyjadrovat ze Obrázek

:arrow: Havet v logu videt neni, jeste na to mrknem skenerem primo na havet

:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) (viz muj podpis)
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni

Re: kontrola Logu, díky

Napsal: 01 led 2011 19:43
od SGTEAM
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Verze databáze: 5437

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

1.1.2011 19:43:14
mbam-log-2011-01-01 (19-43-08).txt

Typ kontroly: Rychlý test
Testované objekty: 159391
Uplynulý čas: 5 minut, 2 sekund

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 2

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
c:\Windows\System32\homepage.txt (Stolen.Data) -> No action taken.
c:\Windows\SysWOW64\homepage.txt (Stolen.Data) -> No action taken.

Re: kontrola Logu, díky

Napsal: 01 led 2011 19:46
od vyosek
:arrow: Dle meho se jedna o falesnou detekci MBAM, navic txt soubory nejsou nebezpecne...mohl byste mi je presto prosim zabalit a poslat na vyosek@forum.viry.cz

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za 14 dni

:arrow: Napiste jak se chova PC

Re: kontrola Logu, díky

Napsal: 02 led 2011 10:31
od SGTEAM
Snad vyřešeno. Díky

Re: kontrola Logu, díky

Napsal: 02 led 2011 11:15
od vyosek
Nemate zac, rad jsem pomohl :)