
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosim o kontrolu Logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosim o kontrolu Logu
Prosim o kontrolu logu. dakujem
LOG
Logfile of random's system information tool 1.08 (written by random/random)
Run by LMK at 2011-04-04 22:19:45
Microsoft Windows 7 Home Premium
System drive C: has 118 GB (49%) free of 238 GB
Total RAM: 4095 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:19:47, on 4. 4. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
D:\INSTAL2010\Total Commander\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\LMK.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.extel.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ooVoo Chat Toolbar - {e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: ooVoo Chat Toolbar - {e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: ooVoo Chat Toolbar - {e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O4 - Global Startup: WDSmartWare.lnk = C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: FastBootAgent - ASUSTeK Computer Inc. - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Games\Counter Strike\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD SmartWare Drive Manager Service (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 11162 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
winlogon.exe
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe"
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"D:\Games\Counter Strike\Tunngle\TnglCtrl.exe"
"C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe"
"C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {35526347-B324-4499-BA9D-F4A9B2BB45CD}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe"
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip
"C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe"
"C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe" View=show_in_tray
"C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe"
Atouch64.exe
ATKOSD.exe
KBFiltr.exe
WDC.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2288.7289d00.1330295509 "C:\Windows\system32\Macromed\Flash\NPSWF32.dll" 2288 plugin \\.\pipe\gecko-crash-server-pipe.2288
C:\Windows\system32\wbem\wmiprvse.exe
"D:\INSTAL2010\Total Commander\totalcmd\TOTALCMD.EXE"
"C:\Users\LMK\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
ooVoo Chat Toolbar - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll [2009-10-01 2166296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
{e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - ooVoo Chat Toolbar - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll [2009-10-01 2166296]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 617856]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2009-04-09 320000]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-28 7982112]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2716216]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [2009-04-02 98304]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [2009-07-07 8493624]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [2009-04-20 159744]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\Windows\AsScrProlog.exe [2009-09-15 72248]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2009-09-15 3054136]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{D42F84B6-3709-4A50-8502-6719D16AE6C8}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
WDSmartWare.lnk - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"D:\INSTAL2010\FlashGet\FlashGet3.exe"="D:\INSTAL2010\FlashGet\FlashGet3.exe:*:Enabled:Flashget3"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2011-03-21 00:40:49 ----D---- C:\Users\LMK\AppData\Roaming\Sun
2011-03-19 19:10:44 ----D---- C:\Users\LMK\AppData\Roaming\Tunngle
2011-03-19 19:10:44 ----D---- C:\ProgramData\Tunngle
2011-03-19 19:10:42 ----A---- C:\Windows\system32\drivers\tap0901t.sys
2011-03-19 13:37:49 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-03-19 13:37:49 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-03-19 13:37:49 ----A---- C:\Windows\SYSWOW64\java.exe
2011-03-19 13:36:39 ----D---- C:\ProgramData\McAfee
2011-03-13 15:06:20 ----D---- C:\ProgramData\MDMA
2011-03-11 11:52:21 ----D---- C:\Windows\CheckSur
2011-03-09 09:31:12 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 09:31:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 09:31:11 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 09:31:10 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 09:31:10 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 09:30:31 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 09:30:30 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 09:30:30 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 09:30:30 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 09:30:29 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 09:30:29 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 09:30:26 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 09:30:26 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 09:30:25 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 09:30:25 ----A---- C:\Windows\system32\mstsc.exe
2011-02-24 07:52:55 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-02-24 07:52:55 ----A---- C:\Windows\system32\wcncsvc.dll
2011-02-23 22:00:59 ----A---- C:\Windows\system32\CamCodec.dll
2011-02-23 13:28:16 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-02-23 13:28:16 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-02-23 13:28:16 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-23 13:28:16 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-21 18:15:43 ----D---- C:\Program Files (x86)\FlashGet
2011-02-21 09:31:48 ----A---- C:\Windows\libem.INI
2011-02-21 09:31:39 ----D---- C:\Users\LMK\AppData\Roaming\BITS
2011-02-21 09:31:38 ----D---- C:\Users\LMK\AppData\Roaming\FlashGet
2011-02-21 09:31:36 ----D---- C:\Users\LMK\AppData\Roaming\FlashGetBHO
2011-02-14 12:33:11 ----H---- C:\Users\LMK\AppData\Roaming\Twain.dll
2011-02-14 12:33:11 ----H---- C:\Users\LMK\AppData\Roaming\PornGrabber.exe
2011-02-11 22:31:50 ----D---- C:\Users\LMK\AppData\Roaming\Western Digital
2011-02-11 22:31:44 ----D---- C:\ProgramData\Western Digital
2011-02-11 22:31:10 ----D---- C:\Program Files\Western Digital
2011-02-11 22:31:10 ----D---- C:\Program Files (x86)\Western Digital
2011-02-09 18:32:22 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 18:32:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-09 18:32:14 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-09 18:32:13 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-09 18:32:13 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-09 18:32:13 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 18:32:13 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 18:32:13 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 18:32:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 18:31:59 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 18:31:58 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-09 18:31:58 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 18:31:57 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-09 18:31:57 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 18:31:57 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 18:31:56 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-09 18:31:55 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-09 18:31:55 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-09 18:31:55 ----A---- C:\Windows\system32\cdd.dll
2011-02-09 18:31:54 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 18:31:53 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-09 18:31:53 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 18:31:53 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 18:31:53 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 18:31:52 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-09 18:31:51 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-09 18:31:51 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-09 18:31:51 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 18:31:51 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 18:31:51 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 18:31:50 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-09 18:31:50 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-09 18:31:49 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 18:31:49 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 18:31:48 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-09 18:31:48 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 18:31:48 ----A---- C:\Windows\system32\winsrv.dll
2011-02-09 18:31:48 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 18:30:45 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 18:30:44 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-09 18:30:44 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 18:30:43 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-09 18:30:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-09 18:30:30 ----A---- C:\Windows\system32\atmfd.dll
2011-02-09 18:30:29 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-09 18:30:29 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-09 18:30:29 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 10:48:32 ----RD---- C:\Program Files (x86)\Skype
2011-02-07 20:29:06 ----D---- C:\Program Files\Defraggler
2011-02-07 20:24:56 ----D---- C:\Program Files (x86)\CCleaner
2011-02-07 17:18:54 ----D---- C:\rsit
2011-02-07 17:18:54 ----D---- C:\Program Files\trend micro
2011-02-06 17:48:50 ----D---- C:\ProgramData\HipSoft
2011-02-06 17:25:28 ----D---- C:\Users\LMK\AppData\Roaming\PlayFirst
2011-02-05 21:28:10 ----D---- C:\CaptchaKiller
2011-01-21 14:41:00 ----A---- C:\Windows\Total Commander 7.56a ExtremePack 2010.13 Rus.exe
2011-01-21 12:38:18 ----D---- C:\Users\LMK\AppData\Roaming\BSplayer PRO
2011-01-21 12:26:04 ----A---- C:\Windows\TRNCOM.INI
2011-01-21 12:24:03 ----D---- C:\Users\LMK\AppData\Roaming\LangSoft
2011-01-21 12:24:03 ----D---- C:\ProgramData\LangSoft
2011-01-19 23:04:32 ----D---- C:\Users\LMK\AppData\Roaming\Thinstall
2011-01-12 18:10:52 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-01-12 10:57:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-12 10:57:08 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 10:57:06 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-12 10:57:06 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 10:57:06 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 10:57:05 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-12 10:57:05 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-12 10:57:05 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-12 10:57:05 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 10:57:05 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 10:56:59 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-12 10:56:59 ----A---- C:\Windows\system32\odbc32.dll
2011-01-05 10:15:42 ----D---- C:\Users\LMK\AppData\Roaming\GetRightToGo
======List of files/folders modified in the last 3 months======
2011-04-04 22:19:46 ----D---- C:\Windows\Temp
2011-04-04 22:15:00 ----D---- C:\Windows\System32
2011-04-04 22:15:00 ----D---- C:\Windows\inf
2011-04-04 22:15:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-04-04 22:10:40 ----D---- C:\Windows\system32\config
2011-04-04 22:10:06 ----D---- C:\ProgramData\NVIDIA
2011-04-03 11:11:02 ----D---- C:\Users\LMK\AppData\Roaming\Skype
2011-04-03 11:03:30 ----D---- C:\Users\LMK\AppData\Roaming\skypePM
2011-04-02 09:13:47 ----D---- C:\Windows\system32\catroot2
2011-03-31 18:52:30 ----HD---- C:\ProgramData
2011-03-31 18:52:30 ----D---- C:\Windows\SysWOW64
2011-03-30 21:46:39 ----SHD---- C:\Windows\Installer
2011-03-30 21:46:35 ----D---- C:\ProgramData\Microsoft Help
2011-03-30 10:58:54 ----D---- C:\Windows
2011-03-28 20:02:32 ----D---- C:\Windows\system32\wdi
2011-03-25 14:38:37 ----D---- C:\Windows\system32\catroot
2011-03-25 14:36:48 ----SHD---- C:\System Volume Information
2011-03-24 09:23:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-19 19:17:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-19 19:11:20 ----D---- C:\Windows\system32\drivers
2011-03-19 19:11:19 ----D---- C:\Windows\system32\DriverStore
2011-03-19 19:10:42 ----RSD---- C:\Windows\Fonts
2011-03-19 13:38:07 ----D---- C:\Program Files (x86)\Common Files
2011-03-19 13:37:37 ----D---- C:\Program Files (x86)\Java
2011-03-18 23:42:05 ----D---- C:\Windows\debug
2011-03-09 21:18:06 ----D---- C:\Windows\winsxs
2011-03-09 09:30:20 ----A---- C:\Windows\system32\MRT.exe
2011-02-21 18:16:33 ----D---- C:\Downloads
2011-02-21 18:15:43 ----RD---- C:\Program Files (x86)
2011-02-21 18:08:28 ----D---- C:\Users\LMK\AppData\Roaming\GHISLER
2011-02-12 19:54:09 ----D---- C:\Windows\Prefetch
2011-02-11 22:31:10 ----RD---- C:\Program Files
2011-02-10 14:39:28 ----RSD---- C:\Windows\assembly
2011-02-09 18:57:57 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-09 18:57:56 ----D---- C:\Program Files\Internet Explorer
2011-02-09 10:48:35 ----D---- C:\Windows\system32\Tasks
2011-02-09 10:48:27 ----D---- C:\ProgramData\Skype
2011-02-07 20:25:48 ----D---- C:\Windows\Minidump
2011-02-07 18:25:09 ----AD---- C:\ProgramData\Temp
2011-02-02 22:40:23 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-01-26 11:54:18 ----D---- C:\ProgramData\Adobe
2011-01-26 08:57:32 ----D---- C:\Program Files (x86)\ASUS
2011-01-16 11:09:22 ----D---- C:\Windows\Microsoft.NET
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2009-09-15 35384]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-07-30 241696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-20 508472]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 123200]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-09 140800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-28 1966624]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 34032]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 a2kn5abk;a2kn5abk; C:\Windows\system32\drivers\a2kn5abk.sys []
S3 dump_wmimmc;dump_wmimmc; \??\D:\Games\9Dragons\GameGuard\dump_wmimmc.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-04 4682]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM); C:\Windows\system32\DRIVERS\s0017bus.sys [2008-10-21 113704]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 19496]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 152616]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 133160]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS); C:\Windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 34856]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0017obex.sys [2008-10-21 128552]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM); C:\Windows\system32\DRIVERS\s0017unic.sys [2008-10-21 145960]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [2008-08-14 100920]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 FastBootAgent;FastBootAgent; C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R2 TunngleService;TunngleService; D:\Games\Counter Strike\Tunngle\TnglCtrl.exe [2010-11-22 718072]
R2 WDDMService;WD SmartWare Drive Manager Service; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2010-01-21 130048]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 23296]
S3 fsssvc;Bezpečnosť rodiny v službe Windows Live; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-02-01 3461068]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-07 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
LOG
Logfile of random's system information tool 1.08 (written by random/random)
Run by LMK at 2011-04-04 22:19:45
Microsoft Windows 7 Home Premium
System drive C: has 118 GB (49%) free of 238 GB
Total RAM: 4095 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:19:47, on 4. 4. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
D:\INSTAL2010\Total Commander\totalcmd\TOTALCMD.EXE
C:\Program Files\trend micro\LMK.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.extel.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ooVoo Chat Toolbar - {e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: ooVoo Chat Toolbar - {e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: ooVoo Chat Toolbar - {e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O4 - Global Startup: WDSmartWare.lnk = C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - (no file)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: FastBootAgent - ASUSTeK Computer Inc. - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Games\Counter Strike\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WD SmartWare Drive Manager Service (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 11162 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
winlogon.exe
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe"
"C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"D:\Games\Counter Strike\Tunngle\TnglCtrl.exe"
"C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe"
"C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {35526347-B324-4499-BA9D-F4A9B2BB45CD}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe"
"C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe" /f=srs_premium_sound_nopreset.zip
"C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe"
"C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe" View=show_in_tray
"C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe"
"C:\Windows\SysWOW64\ACEngSvr.exe" -Embedding
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe"
Atouch64.exe
ATKOSD.exe
KBFiltr.exe
WDC.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe"
"C:\Windows\AsScrPro.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=2288.7289d00.1330295509 "C:\Windows\system32\Macromed\Flash\NPSWF32.dll" 2288 plugin \\.\pipe\gecko-crash-server-pipe.2288
C:\Windows\system32\wbem\wmiprvse.exe
"D:\INSTAL2010\Total Commander\totalcmd\TOTALCMD.EXE"
"C:\Users\LMK\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
Windows Live Family Safety Browser Helper Class - C:\Program Files\Windows Live\Family Safety\fssbho.dll [2008-12-08 68960]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-09 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
ooVoo Chat Toolbar - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll [2009-10-01 2166296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [2008-12-08 1067352]
{e5a1e26f-0d1d-4307-868f-fbd9a374ab54} - ooVoo Chat Toolbar - C:\Program Files (x86)\ooVoo_Chat\tbooVo.dll [2009-10-01 2166296]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 617856]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2009-04-09 320000]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-28 7982112]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2716216]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [2009-04-02 98304]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [2009-07-07 8493624]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [2009-04-20 159744]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-10-29 249064]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
C:\Windows\AsScrProlog.exe [2009-09-15 72248]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2009-09-15 3054136]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{D42F84B6-3709-4A50-8502-6719D16AE6C8}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
WDSmartWare.lnk - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"D:\INSTAL2010\FlashGet\FlashGet3.exe"="D:\INSTAL2010\FlashGet\FlashGet3.exe:*:Enabled:Flashget3"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2011-03-21 00:40:49 ----D---- C:\Users\LMK\AppData\Roaming\Sun
2011-03-19 19:10:44 ----D---- C:\Users\LMK\AppData\Roaming\Tunngle
2011-03-19 19:10:44 ----D---- C:\ProgramData\Tunngle
2011-03-19 19:10:42 ----A---- C:\Windows\system32\drivers\tap0901t.sys
2011-03-19 13:37:49 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-03-19 13:37:49 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-03-19 13:37:49 ----A---- C:\Windows\SYSWOW64\java.exe
2011-03-19 13:36:39 ----D---- C:\ProgramData\McAfee
2011-03-13 15:06:20 ----D---- C:\ProgramData\MDMA
2011-03-11 11:52:21 ----D---- C:\Windows\CheckSur
2011-03-09 09:31:12 ----A---- C:\Windows\system32\FntCache.dll
2011-03-09 09:31:11 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-03-09 09:31:11 ----A---- C:\Windows\system32\DWrite.dll
2011-03-09 09:31:10 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-03-09 09:31:10 ----A---- C:\Windows\system32\d2d1.dll
2011-03-09 09:30:31 ----A---- C:\Windows\system32\EncDec.dll
2011-03-09 09:30:30 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-03-09 09:30:30 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-03-09 09:30:30 ----A---- C:\Windows\system32\CPFilters.dll
2011-03-09 09:30:29 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-03-09 09:30:29 ----A---- C:\Windows\system32\sbe.dll
2011-03-09 09:30:26 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-03-09 09:30:26 ----A---- C:\Windows\system32\mstscax.dll
2011-03-09 09:30:25 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-03-09 09:30:25 ----A---- C:\Windows\system32\mstsc.exe
2011-02-24 07:52:55 ----A---- C:\Windows\SYSWOW64\wcncsvc.dll
2011-02-24 07:52:55 ----A---- C:\Windows\system32\wcncsvc.dll
2011-02-23 22:00:59 ----A---- C:\Windows\system32\CamCodec.dll
2011-02-23 13:28:16 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-02-23 13:28:16 ----A---- C:\Windows\SYSWOW64\XpsGdiConverter.dll
2011-02-23 13:28:16 ----A---- C:\Windows\system32\XpsPrint.dll
2011-02-23 13:28:16 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-02-21 18:15:43 ----D---- C:\Program Files (x86)\FlashGet
2011-02-21 09:31:48 ----A---- C:\Windows\libem.INI
2011-02-21 09:31:39 ----D---- C:\Users\LMK\AppData\Roaming\BITS
2011-02-21 09:31:38 ----D---- C:\Users\LMK\AppData\Roaming\FlashGet
2011-02-21 09:31:36 ----D---- C:\Users\LMK\AppData\Roaming\FlashGetBHO
2011-02-14 12:33:11 ----H---- C:\Users\LMK\AppData\Roaming\Twain.dll
2011-02-14 12:33:11 ----H---- C:\Users\LMK\AppData\Roaming\PornGrabber.exe
2011-02-11 22:31:50 ----D---- C:\Users\LMK\AppData\Roaming\Western Digital
2011-02-11 22:31:44 ----D---- C:\ProgramData\Western Digital
2011-02-11 22:31:10 ----D---- C:\Program Files\Western Digital
2011-02-11 22:31:10 ----D---- C:\Program Files (x86)\Western Digital
2011-02-09 18:32:22 ----A---- C:\Windows\system32\mshtml.dll
2011-02-09 18:32:21 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-02-09 18:32:14 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-02-09 18:32:13 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-02-09 18:32:13 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-02-09 18:32:13 ----A---- C:\Windows\system32\mstime.dll
2011-02-09 18:32:13 ----A---- C:\Windows\system32\msfeeds.dll
2011-02-09 18:32:13 ----A---- C:\Windows\system32\iedkcs32.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-02-09 18:32:12 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\mshtmled.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\msfeedssync.exe
2011-02-09 18:32:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\licmgr10.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\iertutil.dll
2011-02-09 18:32:12 ----A---- C:\Windows\system32\iepeers.dll
2011-02-09 18:31:59 ----A---- C:\Windows\system32\win32k.sys
2011-02-09 18:31:58 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-02-09 18:31:58 ----A---- C:\Windows\system32\kerberos.dll
2011-02-09 18:31:57 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-02-09 18:31:57 ----A---- C:\Windows\system32\vbscript.dll
2011-02-09 18:31:57 ----A---- C:\Windows\system32\jscript.dll
2011-02-09 18:31:56 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-02-09 18:31:55 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-02-09 18:31:55 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-02-09 18:31:55 ----A---- C:\Windows\system32\cdd.dll
2011-02-09 18:31:54 ----A---- C:\Windows\system32\msxml6.dll
2011-02-09 18:31:53 ----A---- C:\Windows\SYSWOW64\upnp.dll
2011-02-09 18:31:53 ----A---- C:\Windows\system32\urlmon.dll
2011-02-09 18:31:53 ----A---- C:\Windows\system32\upnp.dll
2011-02-09 18:31:53 ----A---- C:\Windows\system32\msxml3.dll
2011-02-09 18:31:52 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-02-09 18:31:51 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-02-09 18:31:51 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2011-02-09 18:31:51 ----A---- C:\Windows\system32\wininet.dll
2011-02-09 18:31:51 ----A---- C:\Windows\system32\winhttp.dll
2011-02-09 18:31:51 ----A---- C:\Windows\system32\WebClnt.dll
2011-02-09 18:31:50 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-02-09 18:31:50 ----A---- C:\Windows\system32\davclnt.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\winhttp.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-02-09 18:31:49 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2011-02-09 18:31:49 ----A---- C:\Windows\system32\wscapi.dll
2011-02-09 18:31:49 ----A---- C:\Windows\system32\ieframe.dll
2011-02-09 18:31:48 ----A---- C:\Windows\SYSWOW64\slwga.dll
2011-02-09 18:31:48 ----A---- C:\Windows\system32\wscsvc.dll
2011-02-09 18:31:48 ----A---- C:\Windows\system32\winsrv.dll
2011-02-09 18:31:48 ----A---- C:\Windows\system32\slwga.dll
2011-02-09 18:30:45 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-02-09 18:30:44 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-02-09 18:30:44 ----A---- C:\Windows\system32\ntdll.dll
2011-02-09 18:30:43 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-02-09 18:30:42 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-02-09 18:30:30 ----A---- C:\Windows\system32\atmfd.dll
2011-02-09 18:30:29 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-02-09 18:30:29 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-02-09 18:30:29 ----A---- C:\Windows\system32\atmlib.dll
2011-02-09 10:48:32 ----RD---- C:\Program Files (x86)\Skype
2011-02-07 20:29:06 ----D---- C:\Program Files\Defraggler
2011-02-07 20:24:56 ----D---- C:\Program Files (x86)\CCleaner
2011-02-07 17:18:54 ----D---- C:\rsit
2011-02-07 17:18:54 ----D---- C:\Program Files\trend micro
2011-02-06 17:48:50 ----D---- C:\ProgramData\HipSoft
2011-02-06 17:25:28 ----D---- C:\Users\LMK\AppData\Roaming\PlayFirst
2011-02-05 21:28:10 ----D---- C:\CaptchaKiller
2011-01-21 14:41:00 ----A---- C:\Windows\Total Commander 7.56a ExtremePack 2010.13 Rus.exe
2011-01-21 12:38:18 ----D---- C:\Users\LMK\AppData\Roaming\BSplayer PRO
2011-01-21 12:26:04 ----A---- C:\Windows\TRNCOM.INI
2011-01-21 12:24:03 ----D---- C:\Users\LMK\AppData\Roaming\LangSoft
2011-01-21 12:24:03 ----D---- C:\ProgramData\LangSoft
2011-01-19 23:04:32 ----D---- C:\Users\LMK\AppData\Roaming\Thinstall
2011-01-12 18:10:52 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-01-12 10:57:08 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-01-12 10:57:08 ----A---- C:\Windows\system32\d3d10warp.dll
2011-01-12 10:57:06 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-01-12 10:57:06 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-01-12 10:57:06 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-01-12 10:57:05 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-01-12 10:57:05 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-01-12 10:57:05 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-01-12 10:57:05 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-01-12 10:57:05 ----A---- C:\Windows\system32\d3d10_1.dll
2011-01-12 10:56:59 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-01-12 10:56:59 ----A---- C:\Windows\system32\odbc32.dll
2011-01-05 10:15:42 ----D---- C:\Users\LMK\AppData\Roaming\GetRightToGo
======List of files/folders modified in the last 3 months======
2011-04-04 22:19:46 ----D---- C:\Windows\Temp
2011-04-04 22:15:00 ----D---- C:\Windows\System32
2011-04-04 22:15:00 ----D---- C:\Windows\inf
2011-04-04 22:15:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-04-04 22:10:40 ----D---- C:\Windows\system32\config
2011-04-04 22:10:06 ----D---- C:\ProgramData\NVIDIA
2011-04-03 11:11:02 ----D---- C:\Users\LMK\AppData\Roaming\Skype
2011-04-03 11:03:30 ----D---- C:\Users\LMK\AppData\Roaming\skypePM
2011-04-02 09:13:47 ----D---- C:\Windows\system32\catroot2
2011-03-31 18:52:30 ----HD---- C:\ProgramData
2011-03-31 18:52:30 ----D---- C:\Windows\SysWOW64
2011-03-30 21:46:39 ----SHD---- C:\Windows\Installer
2011-03-30 21:46:35 ----D---- C:\ProgramData\Microsoft Help
2011-03-30 10:58:54 ----D---- C:\Windows
2011-03-28 20:02:32 ----D---- C:\Windows\system32\wdi
2011-03-25 14:38:37 ----D---- C:\Windows\system32\catroot
2011-03-25 14:36:48 ----SHD---- C:\System Volume Information
2011-03-24 09:23:19 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-19 19:17:18 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-19 19:11:20 ----D---- C:\Windows\system32\drivers
2011-03-19 19:11:19 ----D---- C:\Windows\system32\DriverStore
2011-03-19 19:10:42 ----RSD---- C:\Windows\Fonts
2011-03-19 13:38:07 ----D---- C:\Program Files (x86)\Common Files
2011-03-19 13:37:37 ----D---- C:\Program Files (x86)\Java
2011-03-18 23:42:05 ----D---- C:\Windows\debug
2011-03-09 21:18:06 ----D---- C:\Windows\winsxs
2011-03-09 09:30:20 ----A---- C:\Windows\system32\MRT.exe
2011-02-21 18:16:33 ----D---- C:\Downloads
2011-02-21 18:15:43 ----RD---- C:\Program Files (x86)
2011-02-21 18:08:28 ----D---- C:\Users\LMK\AppData\Roaming\GHISLER
2011-02-12 19:54:09 ----D---- C:\Windows\Prefetch
2011-02-11 22:31:10 ----RD---- C:\Program Files
2011-02-10 14:39:28 ----RSD---- C:\Windows\assembly
2011-02-09 18:57:57 ----D---- C:\Program Files (x86)\Internet Explorer
2011-02-09 18:57:56 ----D---- C:\Program Files\Internet Explorer
2011-02-09 10:48:35 ----D---- C:\Windows\system32\Tasks
2011-02-09 10:48:27 ----D---- C:\ProgramData\Skype
2011-02-07 20:25:48 ----D---- C:\Windows\Minidump
2011-02-07 18:25:09 ----AD---- C:\ProgramData\Temp
2011-02-02 22:40:23 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2011-01-26 11:54:18 ----D---- C:\ProgramData\Adobe
2011-01-26 08:57:32 ----D---- C:\Program Files (x86)\ASUS
2011-01-16 11:09:22 ----D---- C:\Windows\Microsoft.NET
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2009-09-15 35384]
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys [2009-07-30 241696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-20 508472]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 145336]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 123200]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-10-05 1542656]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-09 140800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-28 1966624]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATK64AMD.sys [2009-05-13 15928]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 28704]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-05-22 215040]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 34032]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-06-05 1806400]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
S3 a2kn5abk;a2kn5abk; C:\Windows\system32\drivers\a2kn5abk.sys []
S3 dump_wmimmc;dump_wmimmc; \??\D:\Games\9Dragons\GameGuard\dump_wmimmc.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 61792]
S3 NPPTNT2;NPPTNT2; \??\C:\Windows\syswow64\npptNT2.sys [2005-01-04 4682]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM); C:\Windows\system32\DRIVERS\s0017bus.sys [2008-10-21 113704]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0017mdfl.sys [2008-10-21 19496]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0017mdm.sys [2008-10-21 152616]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0017mgmt.sys [2008-10-21 133160]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS); C:\Windows\system32\DRIVERS\s0017nd5.sys [2008-10-21 34856]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0017obex.sys [2008-10-21 128552]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM); C:\Windows\system32\DRIVERS\s0017unic.sys [2008-10-21 145960]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ADSMService;ADSM Service; C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe [2008-08-14 100920]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
R2 FastBootAgent;FastBootAgent; C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-10-16 989800]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
R2 TunngleService;TunngleService; D:\Games\Counter Strike\Tunngle\TnglCtrl.exe [2010-11-22 718072]
R2 WDDMService;WD SmartWare Drive Manager Service; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2010-01-21 130048]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service; C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 23296]
S3 fsssvc;Bezpečnosť rodiny v službe Windows Live; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2010-02-01 3461068]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-07-07 1255736]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: Prosim o kontrolu Logu
INFO
info.txt logfile of random's system information tool 1.08 2011-04-04 22:19:49
======Uninstall list======
-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
AccessDiver v4.402-->"D:\INSTAL2010\EC\AccessDiver\Accessdiver\unins000.exe"
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe AIR-->c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.2 MUI-->MsiExec.exe /I{AC76BA86-7AD7-FFFF-7B44-A91000000001}
Aktualizácia Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {9A8C39B0-D27F-4F81-BE74-2FECF164707E}
Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {CE23B3DC-18CC-46FC-A309-81D6670F8D3D}
Aktualizácia Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {D6DBF512-87C0-4F6A-8FB9-AC3A389D9DE5}
Alcor Micro USB Card Reader-->C:\Program Files (x86)\InstallShield Installation Information\{5A22D889-FBDD-4AE8-86EC-089D45FC133E}\SETUP.EXE -runfromtemp -l0x0409
Asistent pri prihlasovaní v sieti Windows Live-->MsiExec.exe /I{97A58F57-5F50-4B0E-92BA-D41AF806E1B3}
ASUS Data Security Manager-->MsiExec.exe /X{FA2092C5-7979-412D-A962-6485274AE1EE}
ASUS FancyStart-->MsiExec.exe /I{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}
ASUS LifeFrame3-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Live Update-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe" -l0x9
ASUS MultiFrame-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\setup.exe" -l0x9
ASUS Power4Gear Hybrid-->MsiExec.exe /I{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}
ASUS SmartLogon-->MsiExec.exe /I{64452561-169F-4A36-A2FF-B5E118EC65F5}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /I{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS Virtual Camera-->MsiExec.exe /I{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
Asus_Camera_ScreenSaver-->"C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe"
Atheros Client Installation Program-->C:\Program Files (x86)\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Generic Function Service-->C:\Program Files (x86)\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Hotkey-->MsiExec.exe /I{7C05592D-424B-46CB-B505-E0013E8E75C9}
ATK Media-->MsiExec.exe /I{D1E5870E-E3E5-4475-98A6-ADD614524ADF}
ATKOSD2-->MsiExec.exe /I{3B05F2FB-745B-4012-ADF2-439F36B2E70B}
Bezpečnosť rodiny v službe Windows Live-->MsiExec.exe /X{AB0F0272-07A7-470B-B163-6279BB836F60}
BitComet 1.16-->C:\Soft\Bt\uninst.exe
BS.Player PRO-->"D:\INSTAL2010\BsPlayer\BSplayerPro\uninstall.exe"
Build A Lot Free Trial-->"D:\Games\BuildALot_at\unins000.exe"
Caesar 3-->C:\Windows\IsUninst.exe -fd:\games\caesar\Caesar3\Uninst.isu
CamStudio OSS Desktop Recorder-->"D:\INSTAL2010\CamStudio 2.6b\unins000.exe"
CCleaner-->"C:\Program Files (x86)\CCleaner\uninst.exe"
ControlDeck-->MsiExec.exe /I{5B65EF64-1DFA-414A-8C94-7BB726158E21}
Counter-Strike 1.6-->D:\Games\Counter Strike\Uninstal.exe
CyberLink LabelPrint-->"C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
CyberLink LabelPrint-->"C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
Diablo II-->C:\Windows\DIIUnin.exe C:\Windows\DIIUnin.dat
Dump Escape Free Trial-->"D:\Games\DumpEscape_at\unins000.exe"
ETDWare PS/2-x64 7.0.5.7_WHQL-->C:\Program Files\Elantech\ETDUninst.exe
Farm Frenzy Free Trial-->"D:\Games\FarmFrenzy_at\unins000.exe"
Fast Boot-->MsiExec.exe /I{A16656CE-4B17-4484-A13F-22B9500E5223}
FIFA 10-->MsiExec.exe /X{11202615-E557-4ECF-9B86-F59C81E52909}
FIFA 11-->MsiExec.exe /X{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}
Chicken Prox v3-->"D:\INSTAL2010\EC\Chicken Prox\unins000.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Image Grabber II.NET-->MsiExec.exe /I{F343FA04-CFC0-487C-A617-A5E8CF4D7B10}
Image Grabber II-->"D:\INSTAL2010\IG2\Image Grabber II\uninstall.exe"
ImgBurn-->"C:\Program Files (x86)\ImgBurn\uninstall.exe"
IrfanView (remove only)-->C:\Program Files (x86)\IrfanView\iv_uninstall.exe
Java(TM) 6 Update 24-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}
Junk Mail filter update-->MsiExec.exe /I{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /x64 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{8E34682C-8118-31F1-BC4C-98CD9675E1C2}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {E64BA721-2310-4B55-BE5A-2925F9706192}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-041B-1000-0000000FF1CE} /uninstall {8AF3A9EB-FBB9-449F-AC11-94CE39930037}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-041B-0000-0000000FF1CE} /uninstall {8AF3A9EB-FBB9-449F-AC11-94CE39930037}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office Access MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0015-041B-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0016-041B-0000-0000000FF1CE}
Microsoft Office Groove MUI (Slovak) 2007-->MsiExec.exe /X{90120000-00BA-041B-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0044-041B-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2007-->MsiExec.exe /X{90120000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Slovak) 2007-->MsiExec.exe /X{90120000-00A1-041B-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001A-041B-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0018-041B-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Hungarian) 2007-->MsiExec.exe /X{90120000-001F-040E-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2007-->MsiExec.exe /X{90120000-002C-041B-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040E-0000-0000000FF1CE} /uninstall {573CA1BB-C8A3-46C4-993E-DB4043D9BFCD}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Publisher MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0019-041B-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Slovak) 2007-->MsiExec.exe /X{90120000-002A-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2007-->MsiExec.exe /X{90120000-006E-041B-0000-0000000FF1CE}
Microsoft Office Word MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001B-041B-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{06E6E30D-B498-442F-A943-07DE41D7F785}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft XNA Framework Redistributable 4.0-->MsiExec.exe /I{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}
Monopoly Free Trial-->"D:\Games\Monopoly_at\unins000.exe"
Mozilla Firefox (3.6.16)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA Grafický ovládač 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA Ovládač 3D Vision 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Softvér systému s podporou technológie PhysX 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
Odovzdávací nástroj lokality Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
ooVoo_Chat Toolbar-->C:\PROGRA~2\OOVOO_~1\UNWISE.EXE /U C:\PROGRA~2\OOVOO_~1\INSTALL.LOG
ooVoo-->"C:\Program Files (x86)\InstallShield Installation Information\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}\setup.exe" -runfromtemp -l0x0009 -removeonly
OpenAL-->"C:\Program Files (x86)\OpenAL\oalinst.exe" /U
OpenTTD 1.0.5-->D:\Games\TTD\uninstall.exe
Plantasia Free Trial-->"D:\Games\Plantasia_at\unins000.exe"
Realtek 8136 8168 8169 Ethernet Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -removeonly
Revelation Natural Art SK-->MsiExec.exe /I{78BF8D44-E631-44AC-9EAD-33A28D0E0F1F}
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2289158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {210B16C0-CEBD-4DE9-B474-04A7E8735E16}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {3162617C-537F-3BB6-8D0C-C6021F442391} /parameterfolder Extended
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office Groove 2007 (KB2494047)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B91E2AEC-7F93-4E33-ACF6-EC90640CBE4F}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3DED0A62-44C8-4E00-A785-5212F297A9D9}
Security Update for Microsoft Office Publisher 2007 (KB2284697)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3A4CDE54-2403-483D-8D9A-15E3264410DF}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Skype™ 5.1-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Sony Ericsson PC Suite 6.009.00-->"C:\Program Files (x86)\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\ISAdmin.exe" -runfromtemp -l0x0009 -removeonly
SRS Premium Sound Control Panel-->MsiExec.exe /I{D42F84B6-3709-4A50-8502-6719D16AE6C8}
StAPH ver 1.25 - "Rise Of The Themes"-->"D:\INSTAL2010\EC\StAPH\unins000.exe"
Stronghold Crusader Extreme-->"C:\Program Files (x86)\InstallShield Installation Information\{8C3727F2-8E37-49E4-820C-03B1677F53B6}\setup.exe" -runfromtemp -l0x0009 -removeonly
Synthesia (remove only)-->"C:\Program Files (x86)\Synthesia\uninstall.exe"
System Requirements Lab-->C:\Program Files (x86)\SystemRequirementsLab\Uninstall.exe
TheNurrrs Skin Pack for CS 1.6-->D:\Games\Counter Strike\cstrike\Uninstal.exe
Total Commander (Remove or Repair)-->D:\INSTAL2010\Total Commander\totalcmd\tcuninst.exe
Tunngle beta-->"D:\Games\Counter Strike\Tunngle\unins000.exe"
Update for 2007 Microsoft Office System (KB2284654)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {FB166E7C-8AA6-48C8-B726-1F25BEE7825A}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {A45DD0BE-3CD9-3F1E-B233-B90C6983AE77} /parameterfolder Client
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office Outlook 2007 (KB2412171)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {752A0B7C-BD24-4362-AC86-AB63FEE6F46F}
Update for Outlook 2007 Junk Email Filter (KB2508979)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {D2137BBA-250B-4548-BC1C-19E5009893D7}
USB 2.0 1.3M UVC WebCam-->C:\Windows\Uninstsxga.bat
WD SmartWare-->MsiExec.exe /X{604CB4FC-3D32-405F-A109-165F170529B6}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{67101EAB-B558-45B1-A902-28290F15CC75}
Windows Live Fotogaléria-->MsiExec.exe /X{7FF19D53-CC31-4062-AE1D-5F398407E635}
Windows Live Mail-->MsiExec.exe /I{6F238EFB-D502-4164-9D32-A98E96F092F6}
Windows Live Messenger-->MsiExec.exe /X{3D5BD9A0-F790-467A-9940-B26927F77C01}
Windows Live Sync-->MsiExec.exe /X{754F35A5-CFC3-4D30-9B7F-BC74E6C3CB8C}
Windows Live Toolbar-->MsiExec.exe /X{25941F8E-15EA-4C0A-B993-54CE71709450}
Windows Live Writer-->MsiExec.exe /X{EB2243F0-351C-4405-B2A6-2B28466AE684}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
WinRAR archivátor-->C:\Program Files\WinRAR\uninstall.exe
Wireless Console 3-->MsiExec.exe /I{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}
======System event log======
Computer Name: LMK-PC
Event Code: 41
Message: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Record Number: 126570
Source Name: Microsoft-Windows-Kernel-Power
Time Written: 20101217113014.335600-000
Event Type: Critical
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 6008
Message: The previous system shutdown at 10:43:47 on ?17. ?12. ?2010 was unexpected.
Record Number: 126565
Source Name: EventLog
Time Written: 20101217113023.000000-000
Event Type: Error
User:
Computer Name: LMK-PC
Event Code: 1014
Message: Name resolution for the name wwry.antifa.net timed out after none of the configured DNS servers responded.
Record Number: 126560
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20101217093510.153000-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: LMK-PC
Event Code: 1014
Message: Name resolution for the name www.ipujcka.cz timed out after none of the configured DNS servers responded.
Record Number: 126545
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20101217085047.035650-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: LMK-PC
Event Code: 4001
Message: Služba automatickej konfigurácie siete WLAN sa úspešne zastavila.
Record Number: 126433
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20101217071617.418950-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1676 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5492
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100116072131.173050-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1640 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5456
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115235245.119400-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1656 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5419
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115200035.683000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1644 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5382
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115144351.414800-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1608 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5346
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115124221.829400-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: LMK-PC
Event Code: 4648
Message: A logon was attempted using explicit credentials.
Subject:
Security ID: S-1-5-18
Account Name: LMK-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Account Whose Credentials Were Used:
Account Name: LMK
Account Domain: LMK-PC
Logon GUID: {00000000-0000-0000-0000-000000000000}
Target Server:
Target Server Name: localhost
Additional Information: localhost
Process Information:
Process ID: 0x268
Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Network Address: 127.0.0.1
Port: 0
This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 26243
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090117.842200-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
New Logon:
Security ID: S-1-5-7
Account Name: ANONYMOUS LOGON
Account Domain: NT AUTHORITY
Logon ID: 0x266f5
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x0
Process Name: -
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): NTLM V1
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 26242
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090113.568800-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 5024
Message: The Windows Firewall service started successfully.
Record Number: 26241
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090111.356800-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 5033
Message: The Windows Firewall Driver started successfully.
Record Number: 26240
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090110.504800-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 4672
Message: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26239
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090108.348800-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"configsetroot"=%SystemRoot%\ConfigSetRoot
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2011-04-04 22:19:49
======Uninstall list======
-->MsiExec /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
AccessDiver v4.402-->"D:\INSTAL2010\EC\AccessDiver\Accessdiver\unins000.exe"
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe AIR-->c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.2 MUI-->MsiExec.exe /I{AC76BA86-7AD7-FFFF-7B44-A91000000001}
Aktualizácia Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {9A8C39B0-D27F-4F81-BE74-2FECF164707E}
Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {CE23B3DC-18CC-46FC-A309-81D6670F8D3D}
Aktualizácia Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {D6DBF512-87C0-4F6A-8FB9-AC3A389D9DE5}
Alcor Micro USB Card Reader-->C:\Program Files (x86)\InstallShield Installation Information\{5A22D889-FBDD-4AE8-86EC-089D45FC133E}\SETUP.EXE -runfromtemp -l0x0409
Asistent pri prihlasovaní v sieti Windows Live-->MsiExec.exe /I{97A58F57-5F50-4B0E-92BA-D41AF806E1B3}
ASUS Data Security Manager-->MsiExec.exe /X{FA2092C5-7979-412D-A962-6485274AE1EE}
ASUS FancyStart-->MsiExec.exe /I{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}
ASUS LifeFrame3-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Live Update-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe" -l0x9
ASUS MultiFrame-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\setup.exe" -l0x9
ASUS Power4Gear Hybrid-->MsiExec.exe /I{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}
ASUS SmartLogon-->MsiExec.exe /I{64452561-169F-4A36-A2FF-B5E118EC65F5}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /I{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS Virtual Camera-->MsiExec.exe /I{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
Asus_Camera_ScreenSaver-->"C:\Windows\ASUS Camera ScreenSaver Uninstaller.exe"
Atheros Client Installation Program-->C:\Program Files (x86)\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Generic Function Service-->C:\Program Files (x86)\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Hotkey-->MsiExec.exe /I{7C05592D-424B-46CB-B505-E0013E8E75C9}
ATK Media-->MsiExec.exe /I{D1E5870E-E3E5-4475-98A6-ADD614524ADF}
ATKOSD2-->MsiExec.exe /I{3B05F2FB-745B-4012-ADF2-439F36B2E70B}
Bezpečnosť rodiny v službe Windows Live-->MsiExec.exe /X{AB0F0272-07A7-470B-B163-6279BB836F60}
BitComet 1.16-->C:\Soft\Bt\uninst.exe
BS.Player PRO-->"D:\INSTAL2010\BsPlayer\BSplayerPro\uninstall.exe"
Build A Lot Free Trial-->"D:\Games\BuildALot_at\unins000.exe"
Caesar 3-->C:\Windows\IsUninst.exe -fd:\games\caesar\Caesar3\Uninst.isu
CamStudio OSS Desktop Recorder-->"D:\INSTAL2010\CamStudio 2.6b\unins000.exe"
CCleaner-->"C:\Program Files (x86)\CCleaner\uninst.exe"
ControlDeck-->MsiExec.exe /I{5B65EF64-1DFA-414A-8C94-7BB726158E21}
Counter-Strike 1.6-->D:\Games\Counter Strike\Uninstal.exe
CyberLink LabelPrint-->"C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
CyberLink LabelPrint-->"C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
CyberLink Power2Go-->"C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" /z-uninstall
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
Diablo II-->C:\Windows\DIIUnin.exe C:\Windows\DIIUnin.dat
Dump Escape Free Trial-->"D:\Games\DumpEscape_at\unins000.exe"
ETDWare PS/2-x64 7.0.5.7_WHQL-->C:\Program Files\Elantech\ETDUninst.exe
Farm Frenzy Free Trial-->"D:\Games\FarmFrenzy_at\unins000.exe"
Fast Boot-->MsiExec.exe /I{A16656CE-4B17-4484-A13F-22B9500E5223}
FIFA 10-->MsiExec.exe /X{11202615-E557-4ECF-9B86-F59C81E52909}
FIFA 11-->MsiExec.exe /X{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}
Chicken Prox v3-->"D:\INSTAL2010\EC\Chicken Prox\unins000.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Image Grabber II.NET-->MsiExec.exe /I{F343FA04-CFC0-487C-A617-A5E8CF4D7B10}
Image Grabber II-->"D:\INSTAL2010\IG2\Image Grabber II\uninstall.exe"
ImgBurn-->"C:\Program Files (x86)\ImgBurn\uninstall.exe"
IrfanView (remove only)-->C:\Program Files (x86)\IrfanView\iv_uninstall.exe
Java(TM) 6 Update 24-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216020FF}
Junk Mail filter update-->MsiExec.exe /I{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /x64 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{8E34682C-8118-31F1-BC4C-98CD9675E1C2}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {E64BA721-2310-4B55-BE5A-2925F9706192}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-002A-041B-1000-0000000FF1CE} /uninstall {8AF3A9EB-FBB9-449F-AC11-94CE39930037}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-041B-0000-0000000FF1CE} /uninstall {8AF3A9EB-FBB9-449F-AC11-94CE39930037}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-041B-0000-0000000FF1CE} /uninstall {F69A7281-8297-47E2-B583-36EAA37C89EE}
Microsoft Office Access MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0015-041B-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0016-041B-0000-0000000FF1CE}
Microsoft Office Groove MUI (Slovak) 2007-->MsiExec.exe /X{90120000-00BA-041B-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0044-041B-0000-0000000FF1CE}
Microsoft Office Office 64-bit Components 2007-->MsiExec.exe /X{90120000-002A-0000-1000-0000000FF1CE}
Microsoft Office OneNote MUI (Slovak) 2007-->MsiExec.exe /X{90120000-00A1-041B-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001A-041B-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0018-041B-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Hungarian) 2007-->MsiExec.exe /X{90120000-001F-040E-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2007-->MsiExec.exe /X{90120000-002C-041B-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0405-0000-0000000FF1CE} /uninstall {294B4278-CF7B-40B9-86A1-2D3FF0C2C524}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040E-0000-0000000FF1CE} /uninstall {573CA1BB-C8A3-46C4-993E-DB4043D9BFCD}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-041B-0000-0000000FF1CE} /uninstall {10EC59E5-9BCE-4884-BB1A-E28627220232}
Microsoft Office Publisher MUI (Slovak) 2007-->MsiExec.exe /X{90120000-0019-041B-0000-0000000FF1CE}
Microsoft Office Shared 64-bit MUI (Slovak) 2007-->MsiExec.exe /X{90120000-002A-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2007-->MsiExec.exe /X{90120000-006E-041B-0000-0000000FF1CE}
Microsoft Office Word MUI (Slovak) 2007-->MsiExec.exe /X{90120000-001B-041B-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{06E6E30D-B498-442F-A943-07DE41D7F785}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft XNA Framework Redistributable 4.0-->MsiExec.exe /I{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}
Monopoly Free Trial-->"D:\Games\Monopoly_at\unins000.exe"
Mozilla Firefox (3.6.16)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA Grafický ovládač 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA Ovládač 3D Vision 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA PhysX-->MsiExec.exe /X{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}
NVIDIA Softvér systému s podporou technológie PhysX 260.99-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.PhysX
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
Odovzdávací nástroj lokality Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
ooVoo_Chat Toolbar-->C:\PROGRA~2\OOVOO_~1\UNWISE.EXE /U C:\PROGRA~2\OOVOO_~1\INSTALL.LOG
ooVoo-->"C:\Program Files (x86)\InstallShield Installation Information\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}\setup.exe" -runfromtemp -l0x0009 -removeonly
OpenAL-->"C:\Program Files (x86)\OpenAL\oalinst.exe" /U
OpenTTD 1.0.5-->D:\Games\TTD\uninstall.exe
Plantasia Free Trial-->"D:\Games\Plantasia_at\unins000.exe"
Realtek 8136 8168 8169 Ethernet Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -removeonly
Revelation Natural Art SK-->MsiExec.exe /I{78BF8D44-E631-44AC-9EAD-33A28D0E0F1F}
Security Update for 2007 Microsoft Office System (KB2288621)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5C497F0B-2061-4CC9-A61C-6B45B867354D}
Security Update for 2007 Microsoft Office System (KB2288931)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CD769337-C8AC-46DB-A7DC-643E50089263}
Security Update for 2007 Microsoft Office System (KB2289158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {210B16C0-CEBD-4DE9-B474-04A7E8735E16}
Security Update for 2007 Microsoft Office System (KB2344875)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6FC5C4C1-D7AE-44C3-94B7-6424FC3E752F}
Security Update for 2007 Microsoft Office System (KB2345043)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {536FB502-775F-4494-BACE-C02CC90B7A5B}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB976321)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7F207DCA-3399-40CB-A968-6E5991B1421A}
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD8D7C9A-E56A-3E7B-BA6D-FE68F13296E3} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {3162617C-537F-3BB6-8D0C-C6021F442391} /parameterfolder Extended
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1142CCEC-ACA9-484B-BA90-C3A5CA1988C5}
Security Update for Microsoft Office Access 2007 (KB979440)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5A4E43D5-858F-49BD-BA72-8F30E1793060}
Security Update for Microsoft Office Excel 2007 (KB2345035)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B23002DD-34EC-4988-B810-A5E2A0BF04F1}
Security Update for Microsoft Office Groove 2007 (KB2494047)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B91E2AEC-7F93-4E33-ACF6-EC90640CBE4F}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1109D0B3-EFA3-4553-AAED-4C3E9AD130E8}
Security Update for Microsoft Office InfoPath 2007 (KB979441)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8CCB781A-CF6B-4FCB-B6D8-59C64DF5C6DB}
Security Update for Microsoft Office PowerPoint 2007 (KB982158)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F5B70033-E79C-4569-90BF-BC9B4E4F3F46}
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3DED0A62-44C8-4E00-A785-5212F297A9D9}
Security Update for Microsoft Office Publisher 2007 (KB2284697)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3A4CDE54-2403-483D-8D9A-15E3264410DF}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB2344993)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {7A5B74FA-7A92-4FC9-821A-2DD5D4E73E48}
Skype™ 5.1-->MsiExec.exe /X{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}
Sony Ericsson PC Suite 6.009.00-->"C:\Program Files (x86)\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\ISAdmin.exe" -runfromtemp -l0x0009 -removeonly
SRS Premium Sound Control Panel-->MsiExec.exe /I{D42F84B6-3709-4A50-8502-6719D16AE6C8}
StAPH ver 1.25 - "Rise Of The Themes"-->"D:\INSTAL2010\EC\StAPH\unins000.exe"
Stronghold Crusader Extreme-->"C:\Program Files (x86)\InstallShield Installation Information\{8C3727F2-8E37-49E4-820C-03B1677F53B6}\setup.exe" -runfromtemp -l0x0009 -removeonly
Synthesia (remove only)-->"C:\Program Files (x86)\Synthesia\uninstall.exe"
System Requirements Lab-->C:\Program Files (x86)\SystemRequirementsLab\Uninstall.exe
TheNurrrs Skin Pack for CS 1.6-->D:\Games\Counter Strike\cstrike\Uninstal.exe
Total Commander (Remove or Repair)-->D:\INSTAL2010\Total Commander\totalcmd\tcuninst.exe
Tunngle beta-->"D:\Games\Counter Strike\Tunngle\unins000.exe"
Update for 2007 Microsoft Office System (KB2284654)-->msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {FB166E7C-8AA6-48C8-B726-1F25BEE7825A}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)-->c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {A45DD0BE-3CD9-3F1E-B233-B90C6983AE77} /parameterfolder Client
Update for Microsoft Office OneNote 2007 (KB980729)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {329050A9-EF80-40F9-B633-74508F54C1FF}
Update for Microsoft Office Outlook 2007 (KB2412171)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {752A0B7C-BD24-4362-AC86-AB63FEE6F46F}
Update for Outlook 2007 Junk Email Filter (KB2508979)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {D2137BBA-250B-4548-BC1C-19E5009893D7}
USB 2.0 1.3M UVC WebCam-->C:\Windows\Uninstsxga.bat
WD SmartWare-->MsiExec.exe /X{604CB4FC-3D32-405F-A109-165F170529B6}
Windows Live Communications Platform-->MsiExec.exe /I{F69E83CF-B440-43F8-89E6-6EA80712109B}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{67101EAB-B558-45B1-A902-28290F15CC75}
Windows Live Fotogaléria-->MsiExec.exe /X{7FF19D53-CC31-4062-AE1D-5F398407E635}
Windows Live Mail-->MsiExec.exe /I{6F238EFB-D502-4164-9D32-A98E96F092F6}
Windows Live Messenger-->MsiExec.exe /X{3D5BD9A0-F790-467A-9940-B26927F77C01}
Windows Live Sync-->MsiExec.exe /X{754F35A5-CFC3-4D30-9B7F-BC74E6C3CB8C}
Windows Live Toolbar-->MsiExec.exe /X{25941F8E-15EA-4C0A-B993-54CE71709450}
Windows Live Writer-->MsiExec.exe /X{EB2243F0-351C-4405-B2A6-2B28466AE684}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
WinRAR archivátor-->C:\Program Files\WinRAR\uninstall.exe
Wireless Console 3-->MsiExec.exe /I{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}
======System event log======
Computer Name: LMK-PC
Event Code: 41
Message: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Record Number: 126570
Source Name: Microsoft-Windows-Kernel-Power
Time Written: 20101217113014.335600-000
Event Type: Critical
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 6008
Message: The previous system shutdown at 10:43:47 on ?17. ?12. ?2010 was unexpected.
Record Number: 126565
Source Name: EventLog
Time Written: 20101217113023.000000-000
Event Type: Error
User:
Computer Name: LMK-PC
Event Code: 1014
Message: Name resolution for the name wwry.antifa.net timed out after none of the configured DNS servers responded.
Record Number: 126560
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20101217093510.153000-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: LMK-PC
Event Code: 1014
Message: Name resolution for the name www.ipujcka.cz timed out after none of the configured DNS servers responded.
Record Number: 126545
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20101217085047.035650-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: LMK-PC
Event Code: 4001
Message: Služba automatickej konfigurácie siete WLAN sa úspešne zastavila.
Record Number: 126433
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20101217071617.418950-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1676 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1868 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5492
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100116072131.173050-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1640 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5456
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115235245.119400-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1656 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1844 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5419
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115200035.683000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1644 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5382
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115144351.414800-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: LMK-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
30 user registry handles leaked from \Registry\User\S-1-5-21-2422293349-1813714993-3853358830-1000:
Process 1608 (\Device\HarddiskVolume2\Windows\SysWOW64\Fast Boot\FastBootAgent.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServices
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\ShellNoRoam\MUICache
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServiceOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Windows
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Run
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Search Assistant
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Policies
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\RunService
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx
Process 1860 (\Device\HarddiskVolume2\Program Files\Trend Micro\Internet Security\SfCtlCom.exe) has opened key \REGISTRY\USER\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunServices
Record Number: 5346
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100115124221.829400-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: LMK-PC
Event Code: 4648
Message: A logon was attempted using explicit credentials.
Subject:
Security ID: S-1-5-18
Account Name: LMK-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Account Whose Credentials Were Used:
Account Name: LMK
Account Domain: LMK-PC
Logon GUID: {00000000-0000-0000-0000-000000000000}
Target Server:
Target Server Name: localhost
Additional Information: localhost
Process Information:
Process ID: 0x268
Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Network Address: 127.0.0.1
Port: 0
This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 26243
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090117.842200-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
New Logon:
Security ID: S-1-5-7
Account Name: ANONYMOUS LOGON
Account Domain: NT AUTHORITY
Logon ID: 0x266f5
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x0
Process Name: -
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): NTLM V1
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 26242
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090113.568800-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 5024
Message: The Windows Firewall service started successfully.
Record Number: 26241
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090111.356800-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 5033
Message: The Windows Firewall Driver started successfully.
Record Number: 26240
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090110.504800-000
Event Type: Audit Success
User:
Computer Name: LMK-PC
Event Code: 4672
Message: Special privileges assigned to new logon.
Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 26239
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101003090108.348800-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"configsetroot"=%SystemRoot%\ConfigSetRoot
-----------------EOF-----------------
Re: Prosim o kontrolu Logu
Dobrý večer
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.


- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

-nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
-po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.

-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosim o kontrolu Logu
Dal som len rychlu kontrolu, dokladnejsiu spustim zajtra ale vyhodilo toto:
Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Verzia databázy: 6270
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
4. 4. 2011 23:58:09
mbam-log-2011-04-04 (23-58-05).txt
Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 169421
Uplynutý čas: 2 min, 50 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 3
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\Users\LMK\AppData\Roaming\Twain.dll (Trojan.MSIL) -> No action taken.
http://www.virustotal.com/file-scan/rep ... 1301954438
c:\Windows\System32\secushr.dat (Malware.Trace) -> No action taken.
http://www.virustotal.com/file-scan/rep ... 1301954887
c:\Windows\SysWOW64\secushr.dat (Malware.Trace) -> No action taken.
http://www.virustotal.com/file-scan/rep ... 1301954706
Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Verzia databázy: 6270
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
4. 4. 2011 23:58:09
mbam-log-2011-04-04 (23-58-05).txt
Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 169421
Uplynutý čas: 2 min, 50 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 3
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\Users\LMK\AppData\Roaming\Twain.dll (Trojan.MSIL) -> No action taken.
http://www.virustotal.com/file-scan/rep ... 1301954438
c:\Windows\System32\secushr.dat (Malware.Trace) -> No action taken.
http://www.virustotal.com/file-scan/rep ... 1301954887
c:\Windows\SysWOW64\secushr.dat (Malware.Trace) -> No action taken.
http://www.virustotal.com/file-scan/rep ... 1301954706
Re: Prosim o kontrolu Logu
To pak smažete při důkladné kontrole.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosim o kontrolu Logu
LOG Z UPLNEJ KONTROLY
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verzia databázy: 6270
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
6. 4. 2011 8:49:55
mbam-log-2011-04-06 (08-49-48).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 304302
Uplynutý čas: 41 min, 53 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 5
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\Users\LMK\AppData\Local\Twain.dll (Trojan.MSIL) -> No action taken.
c:\Users\LMK\AppData\Local\thinstall\Cache\Stubs\2e16d370105aeb3342f1ac62d0d66754f36c6\splash screen.exe (Trojan.Backdoor) -> No action taken.
c:\Users\LMK\AppData\Roaming\Twain.dll (Trojan.MSIL) -> No action taken.
c:\Windows\System32\secushr.dat (Malware.Trace) -> No action taken.
c:\Windows\SysWOW64\secushr.dat (Malware.Trace) -> No action taken.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verzia databázy: 6270
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
6. 4. 2011 8:49:55
mbam-log-2011-04-06 (08-49-48).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 304302
Uplynutý čas: 41 min, 53 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 5
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
c:\Users\LMK\AppData\Local\Twain.dll (Trojan.MSIL) -> No action taken.
c:\Users\LMK\AppData\Local\thinstall\Cache\Stubs\2e16d370105aeb3342f1ac62d0d66754f36c6\splash screen.exe (Trojan.Backdoor) -> No action taken.
c:\Users\LMK\AppData\Roaming\Twain.dll (Trojan.MSIL) -> No action taken.
c:\Windows\System32\secushr.dat (Malware.Trace) -> No action taken.
c:\Windows\SysWOW64\secushr.dat (Malware.Trace) -> No action taken.
Re: Prosim o kontrolu Logu
V mbamu vše smažte.
Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix

http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosim o kontrolu Logu
Vsetko zmazane.
COmbofix stale pracuje tak, ze po skonceni kontroly restartuje PC??
COmbofix stale pracuje tak, ze po skonceni kontroly restartuje PC??
Re: Prosim o kontrolu Logu
Jak kdy.
Poprosím o log z něj, při ukončení combofixu na Vás měl bafnout
.
Poprosím o log z něj, při ukončení combofixu na Vás měl bafnout

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosim o kontrolu Logu
Ja som to nespustil este, pretoze ak mi to po skonceni kontroly hodi restart PC, Nod32 sa automaticky zapne a vznikne problem s tym ze combofix padne.
Viem vypnut nod32 len docasne a po reboot systemu sa vsak vzdy automaticky zapina
Viem vypnut nod32 len docasne a po reboot systemu sa vsak vzdy automaticky zapina
Re: Prosim o kontrolu Logu
Můžete nod odinstalovat?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosim o kontrolu Logu
PRI KONTROLE COMBOFIXOM MI TO VYHODILO PROBLEM SO SUBOROM PEV.EXE
- notebook casto krat mrzne poslednou dobou
COMBOFIX LOG:
ComboFix 11-04-09.01 - LMK . 04. 2011 18:47:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4095.2718 [GMT 2:00]
Running from: c:\users\LMK\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\captchakiller\CaptchaKiller.exe
C:\Install.exe
c:\programdata\hpe783B.dll
c:\users\LMK\AppData\Roaming\.#
c:\users\LMK\AppData\Roaming\.#\MBX@780@10C1F48.###
c:\users\LMK\AppData\Roaming\.#\MBX@780@10C1F58.###
c:\users\LMK\AppData\Roaming\.#\MBX@780@10C1F68.###
c:\users\LMK\AppData\Roaming\chrtmp
.
.
((((((((((((((((((((((((( Files Created from 2011-03-10 to 2011-04-10 )))))))))))))))))))))))))))))))
.
.
2011-04-10 16:53 . 2011-04-10 16:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-10 16:44 . 2011-04-10 16:44 -------- d-----w- C:\32788R22FWJFW
2011-04-07 14:05 . 2011-04-07 14:05 -------- d-----w- c:\users\LMK\AppData\Local\Panoptic_by_RoyDJ
2011-04-04 21:54 . 2011-04-04 21:54 -------- d-----w- c:\users\LMK\AppData\Roaming\Malwarebytes
2011-04-04 21:53 . 2011-04-04 21:53 -------- d-----w- c:\programdata\Malwarebytes
2011-04-04 21:53 . 2010-12-20 16:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-04 21:53 . 2011-04-06 06:49 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-04 21:53 . 2010-12-20 16:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-04 21:40 . 2011-04-04 21:40 -------- d-----w- c:\users\LMK\AppData\Roaming\PDF Writer
2011-04-04 21:40 . 2011-04-04 21:40 -------- d-----w- c:\users\LMK\AppData\Local\PDF Writer
2011-04-04 21:40 . 2011-04-04 21:40 -------- d-----w- c:\programdata\PDF Writer
2011-04-04 21:40 . 2009-07-14 01:41 101376 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPWN7.DLL
2011-04-04 21:38 . 2011-04-04 21:38 -------- d-----w- c:\program files\Common Files\Bullzip
2011-04-04 21:38 . 2010-09-27 13:27 135168 ----a-w- c:\windows\SysWow64\bzpdfc.dll
2011-04-04 21:38 . 2008-10-30 21:15 227840 ----a-w- c:\windows\SysWow64\bzFlRdr.dll
2011-04-04 21:38 . 2008-07-09 22:19 103424 ----a-w- c:\windows\SysWow64\bzDCT.dll
2011-04-04 21:38 . 2010-09-27 13:28 214016 ----a-w- c:\windows\system32\bzpdf.dll
2011-04-04 21:38 . 2011-04-04 21:38 -------- d-----w- c:\program files\Bullzip
2011-04-04 21:38 . 1999-05-06 22:00 140288 ----a-w- c:\windows\SysWow64\comdlg32.OCX
2011-03-26 22:00 . 2011-03-26 22:00 -------- d-----w- c:\users\LMK\AppData\Local\A
2011-03-24 07:54 . 2011-03-24 07:54 -------- d-----w- c:\users\LMK\AppData\Local\ProxyTester
2011-03-22 20:57 . 2011-03-22 20:57 -------- d-----w- c:\users\LMK\AppData\Local\CaptchaSaver
2011-03-19 17:10 . 2011-04-06 21:24 -------- d-----w- c:\programdata\Tunngle
2011-03-19 17:10 . 2011-03-25 23:22 -------- d-----w- c:\users\LMK\AppData\Roaming\Tunngle
2011-03-19 17:10 . 2009-09-16 06:02 31232 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2011-03-19 11:38 . 2011-03-19 11:38 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-03-19 11:36 . 2011-03-19 11:36 -------- d-----w- c:\programdata\McAfee
2011-03-13 13:06 . 2011-03-13 13:06 -------- d-----w- c:\programdata\MDMA
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-19 06:37 . 2011-03-09 07:31 1135104 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 07:31 1540608 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 07:31 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 07:31 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 07:31 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-02-02 20:40 . 2010-05-07 17:54 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-01-26 06:53 . 2011-02-09 16:31 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:53 . 2011-02-09 16:31 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:31 . 2011-02-09 16:31 144384 ----a-w- c:\windows\system32\cdd.dll
2011-01-21 12:41 . 2011-01-21 12:41 209591808 ----a-w- c:\windows\Total Commander 7.56a ExtremePack 2010.13 Rus.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}"= "c:\program files (x86)\ooVoo_Chat\tbooVo.dll" [2009-10-01 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
2009-10-01 16:29 2166296 ----a-w- c:\program files (x86)\ooVoo_Chat\tbooVo.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}"= "c:\program files (x86)\ooVoo_Chat\tbooVo.dll" [2009-10-01 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-04-02 98304]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2009-9-15 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{D42F84B6-3709-4A50-8502-6719D16AE6C8}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2009-9-15 156880]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-1-21 2119488]
WDSmartWare.lnk - c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2010-1-21 9136960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
2009-06-24 19:30 272952 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2009-09-15 18:23 72248 ----a-w- c:\windows\AsScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2009-09-15 18:23 3054136 ----a-w- c:\windows\AsScrPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-19 02:52 104936 ----a-w- c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 dump_wmimmc;dump_wmimmc;d:\games\9Dragons\GameGuard\dump_wmimmc.sys [x]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 FastBootAgent;FastBootAgent;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TunngleService;TunngleService;d:\games\Counter Strike\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S2 WDDMService;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2010-01-21 130048]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000Core.job
- c:\users\LMK\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-21 19:02]
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000UA.job
- c:\users\LMK\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-21 19:02]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 617856]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2716216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.extel.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - c:\users\LMK\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\LMK\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
FF - ProfilePath - c:\users\LMK\AppData\Roaming\Mozilla\Firefox\Profiles\zy6ny6x4.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar
FF - Ext: Add N Edit Cookies: {038dc421-b19e-4711-a218-1fd10de9163b} - %profile%\extensions\{038dc421-b19e-4711-a218-1fd10de9163b}
FF - Ext: Link Gopher: linkgopher@oooninja.com - %profile%\extensions\linkgopher@oooninja.com
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
WebBrowser-{E5A1E26F-0D1D-4307-868F-FBD9A374AB54} - (no file)
AddRemove-FolderLock6 - c:\program files\Folder Lock\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\LMK\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\LMK\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-04-10 18:55:27
ComboFix-quarantined-files.txt 2011-04-10 16:55
.
Pre-Run: 123 096 653 824 bytes free
Post-Run: 209 515 220 992 bytes free
.
- - End Of File - - DAB66603D55A3881B1BBE1E2F3E1185C
- notebook casto krat mrzne poslednou dobou
COMBOFIX LOG:
ComboFix 11-04-09.01 - LMK . 04. 2011 18:47:49.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.421.1051.18.4095.2718 [GMT 2:00]
Running from: c:\users\LMK\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\captchakiller\CaptchaKiller.exe
C:\Install.exe
c:\programdata\hpe783B.dll
c:\users\LMK\AppData\Roaming\.#
c:\users\LMK\AppData\Roaming\.#\MBX@780@10C1F48.###
c:\users\LMK\AppData\Roaming\.#\MBX@780@10C1F58.###
c:\users\LMK\AppData\Roaming\.#\MBX@780@10C1F68.###
c:\users\LMK\AppData\Roaming\chrtmp
.
.
((((((((((((((((((((((((( Files Created from 2011-03-10 to 2011-04-10 )))))))))))))))))))))))))))))))
.
.
2011-04-10 16:53 . 2011-04-10 16:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-10 16:44 . 2011-04-10 16:44 -------- d-----w- C:\32788R22FWJFW
2011-04-07 14:05 . 2011-04-07 14:05 -------- d-----w- c:\users\LMK\AppData\Local\Panoptic_by_RoyDJ
2011-04-04 21:54 . 2011-04-04 21:54 -------- d-----w- c:\users\LMK\AppData\Roaming\Malwarebytes
2011-04-04 21:53 . 2011-04-04 21:53 -------- d-----w- c:\programdata\Malwarebytes
2011-04-04 21:53 . 2010-12-20 16:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-04 21:53 . 2011-04-06 06:49 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-04-04 21:53 . 2010-12-20 16:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-04 21:40 . 2011-04-04 21:40 -------- d-----w- c:\users\LMK\AppData\Roaming\PDF Writer
2011-04-04 21:40 . 2011-04-04 21:40 -------- d-----w- c:\users\LMK\AppData\Local\PDF Writer
2011-04-04 21:40 . 2011-04-04 21:40 -------- d-----w- c:\programdata\PDF Writer
2011-04-04 21:40 . 2009-07-14 01:41 101376 ----a-w- c:\windows\system32\Spool\prtprocs\x64\HPZPPWN7.DLL
2011-04-04 21:38 . 2011-04-04 21:38 -------- d-----w- c:\program files\Common Files\Bullzip
2011-04-04 21:38 . 2010-09-27 13:27 135168 ----a-w- c:\windows\SysWow64\bzpdfc.dll
2011-04-04 21:38 . 2008-10-30 21:15 227840 ----a-w- c:\windows\SysWow64\bzFlRdr.dll
2011-04-04 21:38 . 2008-07-09 22:19 103424 ----a-w- c:\windows\SysWow64\bzDCT.dll
2011-04-04 21:38 . 2010-09-27 13:28 214016 ----a-w- c:\windows\system32\bzpdf.dll
2011-04-04 21:38 . 2011-04-04 21:38 -------- d-----w- c:\program files\Bullzip
2011-04-04 21:38 . 1999-05-06 22:00 140288 ----a-w- c:\windows\SysWow64\comdlg32.OCX
2011-03-26 22:00 . 2011-03-26 22:00 -------- d-----w- c:\users\LMK\AppData\Local\A
2011-03-24 07:54 . 2011-03-24 07:54 -------- d-----w- c:\users\LMK\AppData\Local\ProxyTester
2011-03-22 20:57 . 2011-03-22 20:57 -------- d-----w- c:\users\LMK\AppData\Local\CaptchaSaver
2011-03-19 17:10 . 2011-04-06 21:24 -------- d-----w- c:\programdata\Tunngle
2011-03-19 17:10 . 2011-03-25 23:22 -------- d-----w- c:\users\LMK\AppData\Roaming\Tunngle
2011-03-19 17:10 . 2009-09-16 06:02 31232 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2011-03-19 11:38 . 2011-03-19 11:38 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-03-19 11:36 . 2011-03-19 11:36 -------- d-----w- c:\programdata\McAfee
2011-03-13 13:06 . 2011-03-13 13:06 -------- d-----w- c:\programdata\MDMA
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-19 06:37 . 2011-03-09 07:31 1135104 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:37 . 2011-03-09 07:31 1540608 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:36 . 2011-03-09 07:31 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-02-19 05:32 . 2011-03-09 07:31 1074176 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-02-19 05:32 . 2011-03-09 07:31 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-02-02 20:40 . 2010-05-07 17:54 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-01-26 06:53 . 2011-02-09 16:31 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-26 06:53 . 2011-02-09 16:31 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-01-26 06:31 . 2011-02-09 16:31 144384 ----a-w- c:\windows\system32\cdd.dll
2011-01-21 12:41 . 2011-01-21 12:41 209591808 ----a-w- c:\windows\Total Commander 7.56a ExtremePack 2010.13 Rus.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}"= "c:\program files (x86)\ooVoo_Chat\tbooVo.dll" [2009-10-01 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
2009-10-01 16:29 2166296 ----a-w- c:\program files (x86)\ooVoo_Chat\tbooVo.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}"= "c:\program files (x86)\ooVoo_Chat\tbooVo.dll" [2009-10-01 2166296]
.
[HKEY_CLASSES_ROOT\clsid\{e5a1e26f-0d1d-4307-868f-fbd9a374ab54}]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HControlUser"="c:\program files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-04-02 98304]
"ATKOSD2"="c:\program files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-07-07 8493624]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Media\DMedia.exe" [2009-04-20 159744]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - c:\windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe [2009-9-15 12862]
SRS Premium Sound.lnk - c:\windows\Installer\{D42F84B6-3709-4A50-8502-6719D16AE6C8}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2009-9-15 156880]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-1-21 2119488]
WDSmartWare.lnk - c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2010-1-21 9136960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
2009-06-24 19:30 272952 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Camera ScreenSaver]
2009-09-15 18:23 72248 ----a-w- c:\windows\AsScrProlog.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2009-09-15 18:23 3054136 ----a-w- c:\windows\AsScrPro.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-19 02:52 104936 ----a-w- c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 dump_wmimmc;dump_wmimmc;d:\games\9Dragons\GameGuard\dump_wmimmc.sys [x]
R3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\DRIVERS\s0017bus.sys [x]
R3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0017mdfl.sys [x]
R3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0017mdm.sys [x]
R3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0017mgmt.sys [x]
R3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\DRIVERS\s0017nd5.sys [x]
R3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0017obex.sys [x]
R3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\DRIVERS\s0017unic.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [x]
S2 FastBootAgent;FastBootAgent;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TunngleService;TunngleService;d:\games\Counter Strike\Tunngle\TnglCtrl.exe [2010-11-22 718072]
S2 WDDMService;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2010-01-21 130048]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000Core.job
- c:\users\LMK\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-21 19:02]
.
2011-04-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2422293349-1813714993-3853358830-1000UA.job
- c:\users\LMK\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-21 19:02]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 617856]
"AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-04-09 320000]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-28 7982112]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2716216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.extel.sk/
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: ????3?? - c:\users\LMK\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: ????3?????? - c:\users\LMK\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
FF - ProfilePath - c:\users\LMK\AppData\Roaming\Mozilla\Firefox\Profiles\zy6ny6x4.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: vShare: vshare@toolbar - %profile%\extensions\vshare@toolbar
FF - Ext: Add N Edit Cookies: {038dc421-b19e-4711-a218-1fd10de9163b} - %profile%\extensions\{038dc421-b19e-4711-a218-1fd10de9163b}
FF - Ext: Link Gopher: linkgopher@oooninja.com - %profile%\extensions\linkgopher@oooninja.com
FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
WebBrowser-{E5A1E26F-0D1D-4307-868F-FBD9A374AB54} - (no file)
AddRemove-FolderLock6 - c:\program files\Folder Lock\Uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}Ź]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\LMK\\AppData\\Roaming\\FlashGetBHO\\GetUrl.htm"
"contexts"=dword:00000022
.
[HKEY_USERS\S-1-5-21-2422293349-1813714993-3853358830-1000\Software\Microsoft\Internet Explorer\MenuExt\O(uë_fŹ3*N}ŹhQčţ”Ąc]
@Allowed: (Read) (RestrictedCode)
@="c:\\Users\\LMK\\AppData\\Roaming\\FlashGetBHO\\GetAllUrl.htm"
"contexts"=dword:000000f3
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-04-10 18:55:27
ComboFix-quarantined-files.txt 2011-04-10 16:55
.
Pre-Run: 123 096 653 824 bytes free
Post-Run: 209 515 220 992 bytes free
.
- - End Of File - - DAB66603D55A3881B1BBE1E2F3E1185C
Re: Prosim o kontrolu Logu
Stále mrzne?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosim o kontrolu Logu
Zamrzol pred kontrolou combofixu, po restarte to vyhadzalo problem s PEV.exe no a odvtedy to vyzera ze je vsetko v poriadku.
Combofix nastatsie zmazal aj tmp subory ktore zaberali xy GB, neviete mi poradit aky program pouzit na cistenie tmp suborov?? ccleaner ich sice ukaze ze su na vycistenie avsak ich nezmaze
Je log cisty??
Combofix nastatsie zmazal aj tmp subory ktore zaberali xy GB, neviete mi poradit aky program pouzit na cistenie tmp suborov?? ccleaner ich sice ukaze ze su na vycistenie avsak ich nezmaze
Je log cisty??
Re: Prosim o kontrolu Logu
Log je ok.
Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Otc by měl ty tempy taky smazat.

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://tharifas.sweb.cz/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

Otc by měl ty tempy taky smazat.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.