prosím o kontrolu logu díky
Napsal: 14 kvě 2011 23:54
Zdravím, prosím o kontrolu. PC je úplně nový, nově nainstalovaný Windows 7 a všechny ostatní věci. Po spuštění další den začal vždy po chvíli zamrzávat. Spustil jsem v nouzovém režimu a zkusil RSIT.
Logfile of random's system information tool 1.08 (written by random/random)
Run by Home at 2011-05-15 00:50:38
Microsoft Windows 7 Ultimate
System drive C: has 425 GB (89%) free of 477 GB
Total RAM: 3583 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:50:45, on 15.5.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\Desktop\RSIT.exe
C:\Program Files\trend micro\Home.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - ASUSTeK Computer Inc. - C:\Windows\system32\FBAgent.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 6215 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-20964076-2941562915-444353861-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-20964076-2941562915-444353861-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-05-10 819840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-05-10 819840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-05-10 3459712]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2010-01-20 13834856]
"HControlUser"=C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"ATKOSD2"=C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [2009-08-17 6859392]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMedia.exe [2009-08-19 170624]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 497024]
"AmIcoSinglun"=C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [2009-09-01 233472]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"RemoteControl11"=C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-05-13 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-09-15 7739936]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut4_E9C83B3EDF9141A39DA5EC05C79BBB91.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-05-15 00:50:38 ----D---- C:\rsit
2011-05-15 00:47:35 ----A---- C:\Windows\ntbtlog.txt
2011-05-15 00:45:31 ----D---- C:\Windows\system32\log
2011-05-13 22:11:16 ----A---- C:\Windows\AutoKMS.exe
2011-05-13 22:03:06 ----D---- C:\Program Files\Microsoft Synchronization Services
2011-05-13 22:03:04 ----D---- C:\Program Files\Common Files\DESIGNER
2011-05-13 22:02:29 ----D---- C:\Windows\PCHEALTH
2011-05-13 22:02:29 ----D---- C:\Program Files\Microsoft.NET
2011-05-13 22:02:29 ----D---- C:\Program Files\Microsoft Sync Framework
2011-05-13 22:02:29 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-05-13 21:56:50 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-05-13 21:54:45 ----D---- C:\Program Files\Microsoft Analysis Services
2011-05-13 21:54:16 ----D---- C:\Program Files\Microsoft Office
2011-05-13 21:54:15 ----D---- C:\ProgramData\Microsoft Help
2011-05-13 21:53:51 ----RHD---- C:\MSOCache
2011-05-13 21:25:26 ----D---- C:\ProgramData\PDVD
2011-05-13 21:25:17 ----D---- C:\ProgramData\CyberLink
2011-05-13 20:56:18 ----D---- C:\Program Files\Microsoft Virtual PC
2011-05-13 20:39:50 ----D---- C:\Windows\Panther
2011-05-13 20:39:23 ----D---- C:\Windows\system32\oem
2011-05-13 19:49:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-13 19:43:13 ----D---- C:\Windows\SoftwareDistribution
2011-05-13 19:40:34 ----D---- C:\Windows\Prefetch
2011-05-13 19:40:17 ----ASH---- C:\pagefile.sys
2011-05-13 19:40:15 ----SHD---- C:\System Volume Information
2011-05-13 19:40:15 ----ASH---- C:\hiberfil.sys
2011-05-13 15:34:40 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-05-13 15:34:33 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-05-13 15:34:33 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-05-13 15:34:33 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-05-13 15:34:32 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-05-13 15:34:32 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\xinput1_2.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\d3dx10.dll
2011-05-13 15:34:30 ----A---- C:\Windows\system32\xinput1_1.dll
2011-05-13 15:34:30 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-05-13 15:34:30 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-05-13 15:34:25 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-05-13 15:34:25 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-05-13 15:26:05 ----D---- C:\Users\Home\AppData\Roaming\Leadertech
2011-05-13 15:20:47 ----D---- C:\Program Files\CyberLink
2011-05-13 15:20:22 ----D---- C:\ProgramData\Temp
2011-05-13 15:20:18 ----D---- C:\ProgramData\install_clap
2011-05-13 15:15:03 ----D---- C:\Users\Home\AppData\Roaming\BSplayer Pro
2011-05-13 15:15:03 ----D---- C:\Users\Home\AppData\Roaming\BSplayer
2011-05-13 15:15:01 ----D---- C:\Program Files\Webteh
2011-05-13 15:13:17 ----D---- C:\Program Files\VideoLAN
2011-05-13 15:12:22 ----D---- C:\Program Files\EA Sports
2011-05-13 15:12:21 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-05-13 15:12:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-05-13 15:12:20 ----A---- C:\Windows\system32\xinput1_3.dll
2011-05-13 15:12:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-05-13 15:12:20 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-05-13 15:12:19 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-05-13 15:12:18 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-05-13 15:12:14 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-05-13 15:12:12 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-05-13 15:11:39 ----A---- C:\Windows\iun6002.exe
2011-05-13 15:11:35 ----D---- C:\Windows\system32\languages
2011-05-13 15:11:35 ----D---- C:\Program Files\Codec Pack - All In 1
2011-05-13 15:10:49 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-05-13 15:03:57 ----D---- C:\Downloads
2011-05-13 14:59:40 ----A---- C:\Windows\ATKPF.ini
2011-05-13 14:54:31 ----A---- C:\Windows\system32\LogonStart.dll
2011-05-13 14:52:22 ----D---- C:\Program Files\PowerISO
2011-05-13 14:50:57 ----D---- C:\ProgramData\Trend Micro
2011-05-13 14:47:56 ----D---- C:\Program Files\Trend Micro
2011-05-13 14:47:13 ----A---- C:\Windows\system32\drivers\AsDsm.sys
2011-05-13 14:46:48 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\RemoveFont.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\FBAgent.exe
2011-05-13 14:46:48 ----A---- C:\Windows\system32\FastBoot.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\Defrag.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\BootTime.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-05-13 14:46:41 ----D---- C:\Windows\system32\ASUS_Screensaver dir
2011-05-13 14:46:19 ----D---- C:\Windows\system32\Macromed
2011-05-13 14:46:19 ----A---- C:\Windows\AsScrPro.exe
2011-05-13 14:46:06 ----D---- C:\Program Files\Common Files\Adobe AIR
2011-05-13 14:45:35 ----D---- C:\ProgramData\Adobe
2011-05-13 14:44:52 ----D---- C:\Program Files\Common Files\Adobe
2011-05-13 14:44:52 ----D---- C:\Program Files\Adobe
2011-05-13 14:43:44 ----D---- C:\ProgramData\ASUS
2011-05-13 14:43:13 ----HD---- C:\ASUS.DAT
2011-05-13 14:41:18 ----A---- C:\Windows\system32\ACEngSvr.exe
2011-05-13 14:40:44 ----D---- C:\ProgramData\P4G
2011-05-13 14:40:33 ----D---- C:\Program Files\P4G
2011-05-13 14:40:24 ----D---- C:\ProgramData\AmUStor
2011-05-13 14:40:23 ----D---- C:\Program Files\AmIcoSingLun
2011-05-13 14:39:29 ----D---- C:\Program Files\Elantech
2011-05-13 14:39:27 ----A---- C:\Windows\system32\drivers\ETD.sys
2011-05-13 14:38:48 ----A---- C:\Windows\system32\RTNUninst32.dll
2011-05-13 14:38:48 ----A---- C:\Windows\system32\RtNicProp32.dll
2011-05-13 14:38:29 ----A---- C:\Windows\system32\drivers\Rt86win7.sys
2011-05-13 14:37:37 ----A---- C:\Windows\system32\vsnp2uvc.dll
2011-05-13 14:37:37 ----A---- C:\Windows\system32\drivers\snp2uvc.sys
2011-05-13 14:37:37 ----A---- C:\Windows\system32\drivers\sncduvc.sys
2011-05-13 14:37:37 ----A---- C:\Windows\system32\csnp2uvc.dll
2011-05-13 14:37:37 ----A---- C:\Windows\snuninst.exe
2011-05-13 14:37:37 ----A---- C:\Windows\snp2uvc.ini
2011-05-13 14:37:20 ----D---- C:\Program Files\SRS Labs
2011-05-13 14:37:07 ----D---- C:\Windows\system32\SRSLabs
2011-05-13 14:37:07 ----D---- C:\Windows\system32\RTCOM
2011-05-13 14:36:41 ----A---- C:\Windows\system32\RtkPgExt.dll
2011-05-13 14:36:41 ----A---- C:\Windows\system32\RtkCoInst.dll
2011-05-13 14:36:41 ----A---- C:\Windows\system32\RtkApoApi.dll
2011-05-13 14:36:40 ----A---- C:\Windows\system32\RtkAPO.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEEP32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEEL32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEEG32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEED32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RP3DHT32.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2011-05-13 14:36:34 ----A---- C:\Windows\system32\RP3DAA32.dll
2011-05-13 14:36:31 ----A---- C:\Windows\system32\FMAPO.dll
2011-05-13 14:36:30 ----A---- C:\Windows\system32\AERTARen.dll
2011-05-13 14:36:30 ----A---- C:\Windows\system32\AERTACap.dll
2011-05-13 14:36:29 ----D---- C:\Program Files\Realtek
2011-05-13 14:36:28 ----HD---- C:\Program Files\Temp
2011-05-13 14:36:26 ----RA---- C:\Windows\RtlExUpd.dll
2011-05-13 14:36:22 ----D---- C:\Program Files\Common Files\InstallShield
2011-05-13 14:36:01 ----D---- C:\Program Files\ASUS
2011-05-13 14:35:23 ----D---- C:\Program Files\ATKGFNEX
2011-05-13 14:35:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-13 14:35:05 ----D---- C:\Users\Home\AppData\Roaming\InstallShield
2011-05-13 14:34:59 ----A---- C:\Windows\system32\drivers\kbfiltr.sys
2011-05-13 14:34:41 ----D---- C:\ProgramData\NVIDIA
2011-05-13 14:32:05 ----A---- C:\Windows\system32\nvudisp.exe
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoZht.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoZhc.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoSv.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoRu.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoPtb.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoNo.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoNl.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoKo.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoJa.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoIt.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoFr.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoFi.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoEsm.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoEs.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoENU.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoEng.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoDe.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\nvraiins.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\nvraidco.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\drivers\nvstor32.sys
2011-05-13 14:29:12 ----A---- C:\Windows\system32\NvRCoDa.dll
2011-05-13 14:29:08 ----A---- C:\Windows\system32\NVCOSMU.DLL
2011-05-13 14:29:08 ----A---- C:\Windows\system32\drivers\nvsmu.sys
2011-05-13 14:29:03 ----A---- C:\Windows\system32\NVUNINST.EXE
2011-05-13 14:26:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-05-13 14:26:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-05-13 14:26:03 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-05-13 14:26:03 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-05-13 14:26:02 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-05-13 14:25:59 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-05-13 14:25:36 ----SHD---- C:\Windows\Installer
2011-05-13 14:25:32 ----A---- C:\Windows\system32\aswBoot.exe
2011-05-13 14:25:26 ----D---- C:\ProgramData\AVAST Software
2011-05-13 14:25:26 ----D---- C:\Program Files\AVAST Software
2011-05-13 14:24:26 ----D---- C:\Program Files\Mozilla Firefox
2011-05-13 14:23:22 ----D---- C:\Program Files\CCleaner
2011-05-13 14:23:02 ----N---- C:\Windows\system32\MpSigStub.exe
2011-05-13 14:21:39 ----D---- C:\Users\Home\AppData\Roaming\Macromedia
2011-05-13 14:21:39 ----D---- C:\Users\Home\AppData\Roaming\Adobe
2011-05-13 13:48:35 ----A---- C:\Windows\system32\wintrust.dll
2011-05-13 13:48:31 ----A---- C:\Windows\system32\cabview.dll
2011-05-13 13:47:20 ----D---- C:\Users\Home\AppData\Roaming\Identities
2011-05-13 13:47:13 ----SD---- C:\Users\Home\AppData\Roaming\Microsoft
2011-05-13 13:47:13 ----D---- C:\Users\Home\AppData\Roaming\Media Center Programs
2011-05-13 13:47:02 ----SHD---- C:\Recovery
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Šablony
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Plocha
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Oblíbené položky
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Nabídka Start
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Dokumenty
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Data aplikací
======List of files/folders modified in the last 1 months======
2011-05-15 00:50:45 ----D---- C:\Windows\Temp
2011-05-15 00:47:35 ----D---- C:\Windows
2011-05-15 00:45:31 ----D---- C:\Windows\System32
2011-05-15 00:44:54 ----D---- C:\Windows\system32\wdi
2011-05-15 00:44:11 ----HD---- C:\ProgramData
2011-05-15 00:40:32 ----D---- C:\Windows\system32\Tasks
2011-05-13 22:08:23 ----RSD---- C:\Windows\assembly
2011-05-13 22:04:23 ----RSD---- C:\Windows\Fonts
2011-05-13 22:04:08 ----D---- C:\Windows\ShellNew
2011-05-13 22:04:06 ----D---- C:\Program Files\Common Files\microsoft shared
2011-05-13 22:03:50 ----D---- C:\Program Files\MSBuild
2011-05-13 22:03:06 ----RD---- C:\Program Files
2011-05-13 22:03:04 ----D---- C:\Program Files\Common Files
2011-05-13 22:02:30 ----SD---- C:\ProgramData\Microsoft
2011-05-13 21:55:48 ----A---- C:\Windows\win.ini
2011-05-13 21:55:42 ----D---- C:\Program Files\Common Files\System
2011-05-13 21:34:20 ----D---- C:\Windows\system32\config
2011-05-13 21:34:16 ----D---- C:\Windows\winsxs
2011-05-13 21:25:25 ----D---- C:\Windows\system32\catroot
2011-05-13 20:57:34 ----D---- C:\Windows\inf
2011-05-13 20:56:44 ----D---- C:\Windows\system32\DriverStore
2011-05-13 20:56:27 ----D---- C:\Windows\system32\drivers
2011-05-13 20:39:24 ----D---- C:\Windows\system32\oobe
2011-05-13 20:39:23 ----D---- C:\Windows\Setup
2011-05-13 19:49:16 ----D---- C:\Windows\rescache
2011-05-13 19:48:58 ----D---- C:\Windows\system32\wbem
2011-05-13 19:48:51 ----D---- C:\Windows\debug
2011-05-13 19:42:47 ----D---- C:\Windows\system32\sysprep
2011-05-13 19:41:01 ----D---- C:\Windows\CSC
2011-05-13 15:40:34 ----D---- C:\Windows\Microsoft.NET
2011-05-13 15:34:12 ----D---- C:\Windows\Logs
2011-05-13 15:10:01 ----D---- C:\Windows\system32\catroot2
2011-05-13 14:37:39 ----D---- C:\Windows\twain_32
2011-05-13 14:32:48 ----D---- C:\Windows\Help
2011-05-13 14:20:54 ----D---- C:\Windows\Tasks
2011-05-13 13:48:37 ----D---- C:\Windows\system32\restore
2011-05-13 13:48:26 ----D---- C:\Windows\system32\CodeIntegrity
2011-05-13 13:47:19 ----SHD---- C:\$Recycle.Bin
2011-05-13 13:47:10 ----RD---- C:\Users
2011-05-13 13:47:02 ----D---- C:\Windows\system32\Recovery
2011-05-13 13:47:02 ----D---- C:\Program Files\Windows NT
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-05-13 30264]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2009-07-30 213024]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 25432]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2009-05-13 14392]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 17920]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-30 187392]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 441176]
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 307928]
S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 49240]
S1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388]
S1 tmtdi;Trend Micro TDI Driver; C:\Windows\system32\DRIVERS\tmtdi.sys [2009-08-22 89872]
S1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2008-02-12 232472]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2011/05/13 21:25:25]; \??\C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 77296]
S2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 19544]
S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 53592]
S2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
S2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [2011-04-20 71664]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S2 tmcomm;tmcomm; C:\Windows\system32\DRIVERS\tmcomm.sys [2009-08-22 158224]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-09-15 2772192]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-08-12 1759872]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 tmactmon;tmactmon; C:\Windows\system32\DRIVERS\tmactmon.sys [2009-08-22 59920]
S3 tmevtmgr;tmevtmgr; C:\Windows\system32\DRIVERS\tmevtmgr.sys [2009-08-22 50704]
S3 tmpreflt;tmpreflt; C:\Windows\system32\DRIVERS\tmpreflt.sys [2009-08-22 36368]
S3 tmxpflt;tmxpflt; C:\Windows\system32\DRIVERS\tmxpflt.sys [2009-08-22 225808]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vsapint;vsapint; C:\Windows\system32\DRIVERS\vsapint.sys [2009-08-22 1223832]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 131000]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 283264]
S2 ASLDRService;ASLDR Service; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536]
S2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-05-10 42184]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-20 219752]
S2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2009-08-22 715368]
S3 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S3 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2009-08-22 345352]
S3 TmProxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2009-08-22 689416]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2011-05-15 00:50:48
======Uninstall list======
Acrobat.com-->MsiExec.exe /X{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Reader 9.0.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90100000001}
Alcor Micro USB Card Reader-->C:\Program Files\InstallShield Installation Information\{F4BF5F6B-F695-4762-AEB2-D095A4C34D89}\Setup.exe -runfromtemp -l0x0409
ASUS AI Recovery-->MsiExec.exe /I{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}
ASUS Data Security Manager-->MsiExec.exe /X{FA2092C5-7979-412D-A962-6485274AE1EE}
ASUS FancyStart-->MsiExec.exe /I{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}
ASUS LifeFrame3-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Live Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe" -l0x9
ASUS MultiFrame-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\setup.exe" -l0x9
ASUS Power4Gear Hybrid-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS SmartLogon-->MsiExec.exe /I{64452561-169F-4A36-A2FF-B5E118EC65F5}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /I{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS USB2.0 UVC VGA WebCam-->C:\Windows\snuninst.exe /name='ASUS USB2.0 UVC VGA WebCam'
ASUS Virtual Camera-->MsiExec.exe /I{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
ASUS_Screensaver-->C:\Windows\system32\ASUS_Screensaver.scr /u
ATK Generic Function Service-->C:\Program Files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Hotkey-->MsiExec.exe /I{7C05592D-424B-46CB-B505-E0013E8E75C9}
ATK Media-->MsiExec.exe /I{D1E5870E-E3E5-4475-98A6-ADD614524ADF}
ATKOSD2-->MsiExec.exe /I{3B05F2FB-745B-4012-ADF2-439F36B2E70B}
avast! Free Antivirus-->C:\Program Files\AVAST Software\Avast\aswRunDll.exe "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
BS.Player FREE-->"C:\Program Files\Webteh\BSplayer\uninstall.exe"
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Codec Pack - All In 1 6.0.3.0-->C:\Windows\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
ControlDeck-->MsiExec.exe /I{5B65EF64-1DFA-414A-8C94-7BB726158E21}
CyberLink PowerDVD 11-->"C:\Program Files\InstallShield Installation Information\{F232C87C-6E92-4775-8210-DFE90B7777D9}\setup.exe" /z-uninstall
CyberLink PowerDVD 11-->"C:\Program Files\InstallShield Installation Information\{F232C87C-6E92-4775-8210-DFE90B7777D9}\setup.exe" /z-uninstall
ETDWare PS/2-x86 7.0.5.7_WHQL-->C:\Program Files\Elantech\ETDUninst.exe
Fast Boot-->MsiExec.exe /I{13F4A7F3-EABC-4261-AF6B-1317777F0755}
FIFA 10-->MsiExec.exe /X{11202615-E557-4ECF-9B86-F59C81E52909}
FIFA 11-->MsiExec.exe /X{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}
Microsoft Office Access MUI (Czech) 2010-->MsiExec.exe /X{90140000-0015-0405-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2010-->MsiExec.exe /X{90140000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2010-->MsiExec.exe /X{90140000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2010-->MsiExec.exe /X{90140000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2010-->MsiExec.exe /X{90140000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2010-->MsiExec.exe /X{90140000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2010-->MsiExec.exe /X{90140000-0018-0405-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2010-->MsiExec.exe /X{90140000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2010-->MsiExec.exe /X{90140000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2010-->MsiExec.exe /X{90140000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2010-->MsiExec.exe /X{90140000-001B-0405-0000-0000000FF1CE}
Microsoft Virtual PC 2007 SP1-->MsiExec.exe /X{AD483998-2E9A-4405-83FF-6E503AF49CBB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox 4.0.1 (x86 cs)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
NB Probe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\Setup.exe" -l0x9
Net4Switch-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D6D7811-43B3-463C-BC79-5D1755269989}\setup.exe" -l0x9
NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
Realtek Ethernet Controller Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
SRS Premium Sound Control Panel-->MsiExec.exe /I{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}
Trend Micro Internet Security-->C:\Program Files\Trend Micro\Internet Security\remove.exe
Trend Micro Internet Security-->MsiExec.exe /X{9D2B0322-44AE-460E-9283-4D2D7A9205AE}
VLC media player 1.1.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
Wireless Console 3-->MsiExec.exe /I{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}
======System event log======
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247D28-05
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPDriverNotFound
Reakce: Není k dispozici
ID souboru CAB: 0
Podpis problému:
P1: x86
P2: ACPI\ATK0100
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:
Připojené soubory:
C:\Windows\Temp\DMIAB7A.tmp.log.xml
Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_e3aed78fa5326e284d9379e9e532681a71d64aea_cab_0799abf7
Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: 48d93e80-7d88-11e0-b517-e86e9d91966a
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20110513174152.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20110513174109.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20110513174106.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110513174101.689600-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20110513174101.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174035.122800-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174035.122800-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x22347
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174034.842000-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174033.516000-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174033.422400-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"SAFEBOOT_OPTION"=NETWORK
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Home at 2011-05-15 00:50:38
Microsoft Windows 7 Ultimate
System drive C: has 425 GB (89%) free of 477 GB
Total RAM: 3583 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:50:45, on 15.5.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Home\Desktop\RSIT.exe
C:\Program Files\trend micro\Home.exe
C:\Users\Home\AppData\Local\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: SRS Premium Sound.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: AFBAgent - ASUSTeK Computer Inc. - C:\Windows\system32\FBAgent.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 6215 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-20964076-2941562915-444353861-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-20964076-2941562915-444353861-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-05-10 819840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-05-10 819840]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-05-10 3459712]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2010-01-20 13834856]
"HControlUser"=C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"ATKOSD2"=C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [2009-08-17 6859392]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMedia.exe [2009-08-19 170624]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 497024]
"AmIcoSinglun"=C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [2009-09-01 233472]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
"RemoteControl11"=C:\Program Files\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADSMTray]
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [2009-06-24 272952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
C:\Windows\AsScrPro.exe [2011-05-13 3058304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-09-15 7739936]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut4_E9C83B3EDF9141A39DA5EC05C79BBB91.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-05-15 00:50:38 ----D---- C:\rsit
2011-05-15 00:47:35 ----A---- C:\Windows\ntbtlog.txt
2011-05-15 00:45:31 ----D---- C:\Windows\system32\log
2011-05-13 22:11:16 ----A---- C:\Windows\AutoKMS.exe
2011-05-13 22:03:06 ----D---- C:\Program Files\Microsoft Synchronization Services
2011-05-13 22:03:04 ----D---- C:\Program Files\Common Files\DESIGNER
2011-05-13 22:02:29 ----D---- C:\Windows\PCHEALTH
2011-05-13 22:02:29 ----D---- C:\Program Files\Microsoft.NET
2011-05-13 22:02:29 ----D---- C:\Program Files\Microsoft Sync Framework
2011-05-13 22:02:29 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-05-13 21:56:50 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-05-13 21:54:45 ----D---- C:\Program Files\Microsoft Analysis Services
2011-05-13 21:54:16 ----D---- C:\Program Files\Microsoft Office
2011-05-13 21:54:15 ----D---- C:\ProgramData\Microsoft Help
2011-05-13 21:53:51 ----RHD---- C:\MSOCache
2011-05-13 21:25:26 ----D---- C:\ProgramData\PDVD
2011-05-13 21:25:17 ----D---- C:\ProgramData\CyberLink
2011-05-13 20:56:18 ----D---- C:\Program Files\Microsoft Virtual PC
2011-05-13 20:39:50 ----D---- C:\Windows\Panther
2011-05-13 20:39:23 ----D---- C:\Windows\system32\oem
2011-05-13 19:49:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-05-13 19:43:13 ----D---- C:\Windows\SoftwareDistribution
2011-05-13 19:40:34 ----D---- C:\Windows\Prefetch
2011-05-13 19:40:17 ----ASH---- C:\pagefile.sys
2011-05-13 19:40:15 ----SHD---- C:\System Volume Information
2011-05-13 19:40:15 ----ASH---- C:\hiberfil.sys
2011-05-13 15:34:40 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-05-13 15:34:40 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-05-13 15:34:39 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-05-13 15:34:38 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-05-13 15:34:37 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-05-13 15:34:36 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-05-13 15:34:35 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-05-13 15:34:33 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-05-13 15:34:33 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-05-13 15:34:33 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-05-13 15:34:32 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-05-13 15:34:32 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\xinput1_2.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-05-13 15:34:31 ----A---- C:\Windows\system32\d3dx10.dll
2011-05-13 15:34:30 ----A---- C:\Windows\system32\xinput1_1.dll
2011-05-13 15:34:30 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-05-13 15:34:30 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-05-13 15:34:25 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-05-13 15:34:25 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-05-13 15:26:05 ----D---- C:\Users\Home\AppData\Roaming\Leadertech
2011-05-13 15:20:47 ----D---- C:\Program Files\CyberLink
2011-05-13 15:20:22 ----D---- C:\ProgramData\Temp
2011-05-13 15:20:18 ----D---- C:\ProgramData\install_clap
2011-05-13 15:15:03 ----D---- C:\Users\Home\AppData\Roaming\BSplayer Pro
2011-05-13 15:15:03 ----D---- C:\Users\Home\AppData\Roaming\BSplayer
2011-05-13 15:15:01 ----D---- C:\Program Files\Webteh
2011-05-13 15:13:17 ----D---- C:\Program Files\VideoLAN
2011-05-13 15:12:22 ----D---- C:\Program Files\EA Sports
2011-05-13 15:12:21 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-05-13 15:12:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-05-13 15:12:20 ----A---- C:\Windows\system32\xinput1_3.dll
2011-05-13 15:12:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-05-13 15:12:20 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-05-13 15:12:19 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-05-13 15:12:18 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-05-13 15:12:14 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-05-13 15:12:13 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-05-13 15:12:12 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-05-13 15:11:39 ----A---- C:\Windows\iun6002.exe
2011-05-13 15:11:35 ----D---- C:\Windows\system32\languages
2011-05-13 15:11:35 ----D---- C:\Program Files\Codec Pack - All In 1
2011-05-13 15:10:49 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2011-05-13 15:03:57 ----D---- C:\Downloads
2011-05-13 14:59:40 ----A---- C:\Windows\ATKPF.ini
2011-05-13 14:54:31 ----A---- C:\Windows\system32\LogonStart.dll
2011-05-13 14:52:22 ----D---- C:\Program Files\PowerISO
2011-05-13 14:50:57 ----D---- C:\ProgramData\Trend Micro
2011-05-13 14:47:56 ----D---- C:\Program Files\Trend Micro
2011-05-13 14:47:13 ----A---- C:\Windows\system32\drivers\AsDsm.sys
2011-05-13 14:46:48 ----A---- C:\Windows\system32\ServiceFilter.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\RemoveFont.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\FBAgent.exe
2011-05-13 14:46:48 ----A---- C:\Windows\system32\FastBoot.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\Defrag.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\BootTime.ini
2011-05-13 14:46:48 ----A---- C:\Windows\system32\AutoRunFilter.ini
2011-05-13 14:46:41 ----D---- C:\Windows\system32\ASUS_Screensaver dir
2011-05-13 14:46:19 ----D---- C:\Windows\system32\Macromed
2011-05-13 14:46:19 ----A---- C:\Windows\AsScrPro.exe
2011-05-13 14:46:06 ----D---- C:\Program Files\Common Files\Adobe AIR
2011-05-13 14:45:35 ----D---- C:\ProgramData\Adobe
2011-05-13 14:44:52 ----D---- C:\Program Files\Common Files\Adobe
2011-05-13 14:44:52 ----D---- C:\Program Files\Adobe
2011-05-13 14:43:44 ----D---- C:\ProgramData\ASUS
2011-05-13 14:43:13 ----HD---- C:\ASUS.DAT
2011-05-13 14:41:18 ----A---- C:\Windows\system32\ACEngSvr.exe
2011-05-13 14:40:44 ----D---- C:\ProgramData\P4G
2011-05-13 14:40:33 ----D---- C:\Program Files\P4G
2011-05-13 14:40:24 ----D---- C:\ProgramData\AmUStor
2011-05-13 14:40:23 ----D---- C:\Program Files\AmIcoSingLun
2011-05-13 14:39:29 ----D---- C:\Program Files\Elantech
2011-05-13 14:39:27 ----A---- C:\Windows\system32\drivers\ETD.sys
2011-05-13 14:38:48 ----A---- C:\Windows\system32\RTNUninst32.dll
2011-05-13 14:38:48 ----A---- C:\Windows\system32\RtNicProp32.dll
2011-05-13 14:38:29 ----A---- C:\Windows\system32\drivers\Rt86win7.sys
2011-05-13 14:37:37 ----A---- C:\Windows\system32\vsnp2uvc.dll
2011-05-13 14:37:37 ----A---- C:\Windows\system32\drivers\snp2uvc.sys
2011-05-13 14:37:37 ----A---- C:\Windows\system32\drivers\sncduvc.sys
2011-05-13 14:37:37 ----A---- C:\Windows\system32\csnp2uvc.dll
2011-05-13 14:37:37 ----A---- C:\Windows\snuninst.exe
2011-05-13 14:37:37 ----A---- C:\Windows\snp2uvc.ini
2011-05-13 14:37:20 ----D---- C:\Program Files\SRS Labs
2011-05-13 14:37:07 ----D---- C:\Windows\system32\SRSLabs
2011-05-13 14:37:07 ----D---- C:\Windows\system32\RTCOM
2011-05-13 14:36:41 ----A---- C:\Windows\system32\RtkPgExt.dll
2011-05-13 14:36:41 ----A---- C:\Windows\system32\RtkCoInst.dll
2011-05-13 14:36:41 ----A---- C:\Windows\system32\RtkApoApi.dll
2011-05-13 14:36:40 ----A---- C:\Windows\system32\RtkAPO.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEEP32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEEL32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEEG32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RTEED32A.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\RP3DHT32.dll
2011-05-13 14:36:35 ----A---- C:\Windows\system32\drivers\RTKVHDA.sys
2011-05-13 14:36:34 ----A---- C:\Windows\system32\RP3DAA32.dll
2011-05-13 14:36:31 ----A---- C:\Windows\system32\FMAPO.dll
2011-05-13 14:36:30 ----A---- C:\Windows\system32\AERTARen.dll
2011-05-13 14:36:30 ----A---- C:\Windows\system32\AERTACap.dll
2011-05-13 14:36:29 ----D---- C:\Program Files\Realtek
2011-05-13 14:36:28 ----HD---- C:\Program Files\Temp
2011-05-13 14:36:26 ----RA---- C:\Windows\RtlExUpd.dll
2011-05-13 14:36:22 ----D---- C:\Program Files\Common Files\InstallShield
2011-05-13 14:36:01 ----D---- C:\Program Files\ASUS
2011-05-13 14:35:23 ----D---- C:\Program Files\ATKGFNEX
2011-05-13 14:35:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-05-13 14:35:05 ----D---- C:\Users\Home\AppData\Roaming\InstallShield
2011-05-13 14:34:59 ----A---- C:\Windows\system32\drivers\kbfiltr.sys
2011-05-13 14:34:41 ----D---- C:\ProgramData\NVIDIA
2011-05-13 14:32:05 ----A---- C:\Windows\system32\nvudisp.exe
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoZht.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoZhc.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoSv.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoRu.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoPtb.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoNo.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoNl.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoKo.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoJa.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoIt.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoFr.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoFi.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoEsm.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoEs.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoENU.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoEng.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\NvRCoDe.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\nvraiins.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\nvraidco.dll
2011-05-13 14:29:13 ----A---- C:\Windows\system32\drivers\nvstor32.sys
2011-05-13 14:29:12 ----A---- C:\Windows\system32\NvRCoDa.dll
2011-05-13 14:29:08 ----A---- C:\Windows\system32\NVCOSMU.DLL
2011-05-13 14:29:08 ----A---- C:\Windows\system32\drivers\nvsmu.sys
2011-05-13 14:29:03 ----A---- C:\Windows\system32\NVUNINST.EXE
2011-05-13 14:26:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-05-13 14:26:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-05-13 14:26:03 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-05-13 14:26:03 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-05-13 14:26:02 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-05-13 14:25:59 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-05-13 14:25:36 ----SHD---- C:\Windows\Installer
2011-05-13 14:25:32 ----A---- C:\Windows\system32\aswBoot.exe
2011-05-13 14:25:26 ----D---- C:\ProgramData\AVAST Software
2011-05-13 14:25:26 ----D---- C:\Program Files\AVAST Software
2011-05-13 14:24:26 ----D---- C:\Program Files\Mozilla Firefox
2011-05-13 14:23:22 ----D---- C:\Program Files\CCleaner
2011-05-13 14:23:02 ----N---- C:\Windows\system32\MpSigStub.exe
2011-05-13 14:21:39 ----D---- C:\Users\Home\AppData\Roaming\Macromedia
2011-05-13 14:21:39 ----D---- C:\Users\Home\AppData\Roaming\Adobe
2011-05-13 13:48:35 ----A---- C:\Windows\system32\wintrust.dll
2011-05-13 13:48:31 ----A---- C:\Windows\system32\cabview.dll
2011-05-13 13:47:20 ----D---- C:\Users\Home\AppData\Roaming\Identities
2011-05-13 13:47:13 ----SD---- C:\Users\Home\AppData\Roaming\Microsoft
2011-05-13 13:47:13 ----D---- C:\Users\Home\AppData\Roaming\Media Center Programs
2011-05-13 13:47:02 ----SHD---- C:\Recovery
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Šablony
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Plocha
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Oblíbené položky
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Nabídka Start
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Dokumenty
2011-05-13 13:47:02 ----SHD---- C:\ProgramData\Data aplikací
======List of files/folders modified in the last 1 months======
2011-05-15 00:50:45 ----D---- C:\Windows\Temp
2011-05-15 00:47:35 ----D---- C:\Windows
2011-05-15 00:45:31 ----D---- C:\Windows\System32
2011-05-15 00:44:54 ----D---- C:\Windows\system32\wdi
2011-05-15 00:44:11 ----HD---- C:\ProgramData
2011-05-15 00:40:32 ----D---- C:\Windows\system32\Tasks
2011-05-13 22:08:23 ----RSD---- C:\Windows\assembly
2011-05-13 22:04:23 ----RSD---- C:\Windows\Fonts
2011-05-13 22:04:08 ----D---- C:\Windows\ShellNew
2011-05-13 22:04:06 ----D---- C:\Program Files\Common Files\microsoft shared
2011-05-13 22:03:50 ----D---- C:\Program Files\MSBuild
2011-05-13 22:03:06 ----RD---- C:\Program Files
2011-05-13 22:03:04 ----D---- C:\Program Files\Common Files
2011-05-13 22:02:30 ----SD---- C:\ProgramData\Microsoft
2011-05-13 21:55:48 ----A---- C:\Windows\win.ini
2011-05-13 21:55:42 ----D---- C:\Program Files\Common Files\System
2011-05-13 21:34:20 ----D---- C:\Windows\system32\config
2011-05-13 21:34:16 ----D---- C:\Windows\winsxs
2011-05-13 21:25:25 ----D---- C:\Windows\system32\catroot
2011-05-13 20:57:34 ----D---- C:\Windows\inf
2011-05-13 20:56:44 ----D---- C:\Windows\system32\DriverStore
2011-05-13 20:56:27 ----D---- C:\Windows\system32\drivers
2011-05-13 20:39:24 ----D---- C:\Windows\system32\oobe
2011-05-13 20:39:23 ----D---- C:\Windows\Setup
2011-05-13 19:49:16 ----D---- C:\Windows\rescache
2011-05-13 19:48:58 ----D---- C:\Windows\system32\wbem
2011-05-13 19:48:51 ----D---- C:\Windows\debug
2011-05-13 19:42:47 ----D---- C:\Windows\system32\sysprep
2011-05-13 19:41:01 ----D---- C:\Windows\CSC
2011-05-13 15:40:34 ----D---- C:\Windows\Microsoft.NET
2011-05-13 15:34:12 ----D---- C:\Windows\Logs
2011-05-13 15:10:01 ----D---- C:\Windows\system32\catroot2
2011-05-13 14:37:39 ----D---- C:\Windows\twain_32
2011-05-13 14:32:48 ----D---- C:\Windows\Help
2011-05-13 14:20:54 ----D---- C:\Windows\Tasks
2011-05-13 13:48:37 ----D---- C:\Windows\system32\restore
2011-05-13 13:48:26 ----D---- C:\Windows\system32\CodeIntegrity
2011-05-13 13:47:19 ----SHD---- C:\$Recycle.Bin
2011-05-13 13:47:10 ----RD---- C:\Users
2011-05-13 13:47:02 ----D---- C:\Windows\system32\Recovery
2011-05-13 13:47:02 ----D---- C:\Program Files\Windows NT
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2011-05-13 30264]
R0 nvstor32;nvstor32; C:\Windows\system32\DRIVERS\nvstor32.sys [2009-07-30 213024]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 25432]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2009-05-13 14392]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2009-06-29 17920]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-30 187392]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\Windows\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 441176]
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 307928]
S1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 49240]
S1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 59388]
S1 tmtdi;Trend Micro TDI Driver; C:\Windows\system32\DRIVERS\tmtdi.sys [2009-08-22 89872]
S1 vmm;Virtual Machine Monitor; \??\C:\Windows\system32\Drivers\vmm.sys [2008-02-12 232472]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2011/05/13 21:25:25]; \??\C:\Program Files\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 77296]
S2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
S2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 19544]
S2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 53592]
S2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
S2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD.sys [2011-04-20 71664]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S2 tmcomm;tmcomm; C:\Windows\system32\DRIVERS\tmcomm.sys [2009-08-22 158224]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-09-15 2772192]
S3 ipswuio;ipswuio; C:\Windows\System32\DRIVERS\ipswuio.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2009-08-12 1759872]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 tmactmon;tmactmon; C:\Windows\system32\DRIVERS\tmactmon.sys [2009-08-22 59920]
S3 tmevtmgr;tmevtmgr; C:\Windows\system32\DRIVERS\tmevtmgr.sys [2009-08-22 50704]
S3 tmpreflt;tmpreflt; C:\Windows\system32\DRIVERS\tmpreflt.sys [2009-08-22 36368]
S3 tmxpflt;tmxpflt; C:\Windows\system32\DRIVERS\tmxpflt.sys [2009-08-22 225808]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vsapint;vsapint; C:\Windows\system32\DRIVERS\vsapint.sys [2009-08-22 1223832]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 131000]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 AFBAgent;AFBAgent; C:\Windows\system32\FBAgent.exe [2009-09-17 283264]
S2 ASLDRService;ASLDR Service; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [2009-06-15 84536]
S2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-05-10 42184]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-01-20 219752]
S2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2009-08-22 715368]
S3 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
S3 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2009-08-22 345352]
S3 TmProxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2009-08-22 689416]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2011-05-15 00:50:48
======Uninstall list======
Acrobat.com-->MsiExec.exe /X{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Reader 9.0.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90100000001}
Alcor Micro USB Card Reader-->C:\Program Files\InstallShield Installation Information\{F4BF5F6B-F695-4762-AEB2-D095A4C34D89}\Setup.exe -runfromtemp -l0x0409
ASUS AI Recovery-->MsiExec.exe /I{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}
ASUS Data Security Manager-->MsiExec.exe /X{FA2092C5-7979-412D-A962-6485274AE1EE}
ASUS FancyStart-->MsiExec.exe /I{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}
ASUS LifeFrame3-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
ASUS Live Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe" -l0x9
ASUS MultiFrame-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\setup.exe" -l0x9
ASUS Power4Gear Hybrid-->MsiExec.exe /I{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}
ASUS SmartLogon-->MsiExec.exe /I{64452561-169F-4A36-A2FF-B5E118EC65F5}
ASUS Splendid Video Enhancement Technology-->MsiExec.exe /I{0969AF05-4FF6-4C00-9406-43599238DE0D}
ASUS USB2.0 UVC VGA WebCam-->C:\Windows\snuninst.exe /name='ASUS USB2.0 UVC VGA WebCam'
ASUS Virtual Camera-->MsiExec.exe /I{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}
ASUS_Screensaver-->C:\Windows\system32\ASUS_Screensaver.scr /u
ATK Generic Function Service-->C:\Program Files\InstallShield Installation Information\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}\setup.exe -runfromtemp -l0x0009 -removeonly
ATK Hotkey-->MsiExec.exe /I{7C05592D-424B-46CB-B505-E0013E8E75C9}
ATK Media-->MsiExec.exe /I{D1E5870E-E3E5-4475-98A6-ADD614524ADF}
ATKOSD2-->MsiExec.exe /I{3B05F2FB-745B-4012-ADF2-439F36B2E70B}
avast! Free Antivirus-->C:\Program Files\AVAST Software\Avast\aswRunDll.exe "C:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
BS.Player FREE-->"C:\Program Files\Webteh\BSplayer\uninstall.exe"
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Codec Pack - All In 1 6.0.3.0-->C:\Windows\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
ControlDeck-->MsiExec.exe /I{5B65EF64-1DFA-414A-8C94-7BB726158E21}
CyberLink PowerDVD 11-->"C:\Program Files\InstallShield Installation Information\{F232C87C-6E92-4775-8210-DFE90B7777D9}\setup.exe" /z-uninstall
CyberLink PowerDVD 11-->"C:\Program Files\InstallShield Installation Information\{F232C87C-6E92-4775-8210-DFE90B7777D9}\setup.exe" /z-uninstall
ETDWare PS/2-x86 7.0.5.7_WHQL-->C:\Program Files\Elantech\ETDUninst.exe
Fast Boot-->MsiExec.exe /I{13F4A7F3-EABC-4261-AF6B-1317777F0755}
FIFA 10-->MsiExec.exe /X{11202615-E557-4ECF-9B86-F59C81E52909}
FIFA 11-->MsiExec.exe /X{3FEA6CD1-EA13-4CE7-A74E-A74A4A0A7B5C}
Microsoft Office Access MUI (Czech) 2010-->MsiExec.exe /X{90140000-0015-0405-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2010-->MsiExec.exe /X{90140000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2010-->MsiExec.exe /X{90140000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2010-->MsiExec.exe /X{90140000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2010-->MsiExec.exe /X{90140000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2010-->MsiExec.exe /X{90140000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2010-->MsiExec.exe /X{90140000-0018-0405-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2010-->MsiExec.exe /X{90140000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2010-->MsiExec.exe /X{90140000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2010-->MsiExec.exe /X{90140000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2010-->MsiExec.exe /X{90140000-001B-0405-0000-0000000FF1CE}
Microsoft Virtual PC 2007 SP1-->MsiExec.exe /X{AD483998-2E9A-4405-83FF-6E503AF49CBB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox 4.0.1 (x86 cs)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
NB Probe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\Setup.exe" -l0x9
Net4Switch-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D6D7811-43B3-463C-BC79-5D1755269989}\setup.exe" -l0x9
NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
Realtek Ethernet Controller Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe -runfromtemp -removeonly
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -removeonly
SRS Premium Sound Control Panel-->MsiExec.exe /I{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}
Trend Micro Internet Security-->C:\Program Files\Trend Micro\Internet Security\remove.exe
Trend Micro Internet Security-->MsiExec.exe /X{9D2B0322-44AE-460E-9283-4D2D7A9205AE}
VLC media player 1.1.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WinFlash-->MsiExec.exe /X{8F21291E-0444-4B1D-B9F9-4370A73E346D}
Wireless Console 3-->MsiExec.exe /I{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}
======System event log======
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247D28-05
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPDriverNotFound
Reakce: Není k dispozici
ID souboru CAB: 0
Podpis problému:
P1: x86
P2: ACPI\ATK0100
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:
Připojené soubory:
C:\Windows\Temp\DMIAB7A.tmp.log.xml
Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_e3aed78fa5326e284d9379e9e532681a71d64aea_cab_0799abf7
Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: 48d93e80-7d88-11e0-b517-e86e9d91966a
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20110513174152.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20110513174109.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20110513174106.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110513174101.689600-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20110513174101.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174035.122800-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174035.122800-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x22347
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174034.842000-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174033.516000-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110513174033.422400-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"SAFEBOOT_OPTION"=NETWORK
-----------------EOF-----------------