
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kryptik.PHU
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Kryptik.PHU
Dobry den. Manzelce se objevil na PC nejaky vir Kryptik.PHU a zahlcuje vykon pocitace a spousteni nejakych aplikaci. Prikladam screen z karanteny Eseta. Nesel jsem zde nekolik temat na Kryptika, ale ne PHU (ani nevim co to znamena). Byl bych taky moc rad za pomoc. Esetem se mi ho nepovedlo odstranit. PC jede na W7 ultimate. Predem moc diky za pripadnou radu.
- Přílohy
-
- kryptik.jpg (12.18 KiB) Zobrazeno 2052 x
Re: Kryptik.PHU
Zdravim a pekny vecer preji
Jelikoz nevime o Vasem PC nic a z kristalove koule se spatne vesti, navic pri zatazenem pocasi jake ted v okrese Kromeriz panuje, neni nic videt
Ale dosti legracek, kouknem na to
Kliknete do meho podpisu na RSIT a dejte log z nej - navod Vas povede...





Re: Kryptik.PHU

Logfile of random's system information tool 1.08 (written by random/random)
Run by Petra at 2011-06-21 21:43:11
Microsoft Windows 7 Ultimate Service Pack 1
System drive D: has 255 GB (85%) free of 300 GB
Total RAM: 3580 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:43:34, on 21.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
D:\Windows\system32\taskhost.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\IDT\WDM\sttray.exe
D:\Program Files\DellTPad\Apoint.exe
D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
D:\Program Files\ESET\ESET Smart Security\egui.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\DellTPad\ApMsgFwd.exe
D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe
D:\Program Files\DellTPad\HidFind.exe
D:\Program Files\DellTPad\Apntex.exe
D:\Windows\system32\conhost.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\ICQ7.5\ICQ.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\Microsoft Office\Office10\WINWORD.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Windows\system32\SearchFilterHost.exe
D:\Users\Petra\Downloads\RSIT.exe
D:\Program Files\trend micro\Petra.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [SysTrayApp] D:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NokiaMServer] D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SiemensAutomationFileStorage] D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe preload
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @D:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @D:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: d:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: d:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\aestsrv.exe
O23 - Service: Automation License Manager Service (almservice) - SIEMENS AG - D:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe
O23 - Service: AMD External Events Utility - AMD - D:\Windows\system32\atiesrxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - D:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXlm License Manager - Acresso Software Inc. - D:\SEFlex\Program\lmgrd.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - D:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: OpcEnum - OPC Foundation - D:\Windows\system32\OpcEnum.exe
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx) - SIEMENS AG - D:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: S7TraceServiceX - SIEMENS AG - D:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - D:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
--
End of file - 9647 bytes
======Scheduled tasks folder======
D:\Windows\tasks\GoogleUpdateTaskMachineCore.job
D:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-02 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickSet"=C:\Program Files\Dell\QuickSet\QuickSet.exe [2008-11-14 1708032]
"IAAnotif"=D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-04 186904]
"StartCCC"=D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-06-25 98304]
"Broadcom Wireless Manager UI"=D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [2009-07-17 4562944]
"SysTrayApp"=D:\Program Files\IDT\WDM\sttray.exe [2009-11-07 495708]
"Apoint"=D:\Program Files\DellTPad\Apoint.exe [2010-01-18 274432]
"NokiaMServer"=D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles []
"egui"=D:\Program Files\ESET\ESET Smart Security\egui.exe [2010-02-26 2140880]
"VirtualCloneDrive"=D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-05-27 85160]
"SiemensAutomationFileStorage"=D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe [2009-11-17 364544]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2008-11-14 1708032]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2011-03-02 149280]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ICQ"=D:\Program Files\ICQ7.5\ICQ.exe [2011-06-16 124216]
D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - D:\Windows\System32\Notepad.exe %1
.js - open - D:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-21 21:43:12 ----D---- D:\Program Files\trend micro
2011-06-21 21:43:11 ----D---- D:\rsit
2011-06-21 19:56:34 ----A---- D:\Windows\system32\wininet.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\wextract.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\webcheck.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\vbscript.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\urlmon.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\url.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\SetIEInstalledDate.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\RegisterIEPKEYs.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\pngfilt.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\occache.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msrating.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msls31.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtmler.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtmled.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtml.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshta.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeedssync.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeedsbs.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeeds.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\licmgr10.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jsproxy.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jscript9.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jscript.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\inseng.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\imgutil.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iexpress.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieUnatt.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieui.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iesysprep.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iesetup.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iertutil.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iernonce.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iepeers.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieframe.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iedkcs32.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieapfltr.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieakui.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieaksie.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieakeng.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\IEAdvpack.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ie4uinit.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\icardie.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\dxtrans.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\dxtmsft.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\admparse.dll
2011-06-21 19:24:37 ----A---- D:\Windows\system32\poqexec.exe
2011-06-21 19:24:32 ----A---- D:\Windows\system32\prevhost.exe
2011-06-20 20:52:13 ----SHD---- D:\Config.Msi
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb20.sys
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb10.sys
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb.sys
2011-06-20 20:45:26 ----A---- D:\Windows\system32\XpsGdiConverter.dll
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srvnet.sys
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srv2.sys
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srv.sys
2011-06-20 20:44:51 ----A---- D:\Windows\system32\dnsrslvr.dll
2011-06-20 20:44:51 ----A---- D:\Windows\system32\dnsapi.dll
2011-06-20 20:44:50 ----A---- D:\Windows\system32\dnscacheugc.exe
2011-06-20 20:44:46 ----A---- D:\Windows\system32\drivers\tcpip.sys
2011-06-20 20:44:45 ----A---- D:\Windows\system32\drivers\afd.sys
2011-06-20 20:44:44 ----A---- D:\Windows\system32\inetcomm.dll
2011-06-20 20:44:42 ----A---- D:\Windows\system32\oleaut32.dll
2011-06-20 20:44:40 ----A---- D:\Windows\system32\atmlib.dll
2011-06-20 20:44:40 ----A---- D:\Windows\system32\atmfd.dll
2011-06-20 20:44:39 ----A---- D:\Windows\system32\win32k.sys
2011-06-20 20:44:35 ----A---- D:\Windows\explorer.exe
2011-06-20 20:44:34 ----A---- D:\Windows\system32\FXSCOVER.exe
2011-06-20 20:44:32 ----A---- D:\Windows\system32\XpsPrint.dll
2011-06-20 20:44:31 ----A---- D:\Windows\system32\mfc42.dll
2011-06-20 20:44:30 ----A---- D:\Windows\system32\mfc42u.dll
2011-06-20 20:44:23 ----A---- D:\Windows\system32\ntkrnlpa.exe
2011-06-20 20:44:22 ----A---- D:\Windows\system32\ntoskrnl.exe
2011-06-20 20:44:10 ----A---- D:\Windows\system32\drivers\bowser.sys
2011-06-20 20:43:57 ----A---- D:\Windows\system32\d3d10_1.dll
2011-06-20 20:42:25 ----A---- D:\Windows\system32\drivers\Diskdump.sys
2011-06-20 19:10:09 ----D---- D:\ProgramData\bD42900LoEhE42900
2011-06-20 19:09:07 ----D---- D:\Windows\Sun
2011-06-19 19:35:39 ----D---- D:\ProgramData\tmp
2011-06-19 19:35:38 ----D---- D:\ProgramData\hps
2011-06-19 15:25:50 ----D---- D:\Program Files\Schlecker
2011-06-16 20:22:15 ----D---- D:\Users\Petra\AppData\Roaming\Mozilla
2011-06-16 20:22:04 ----D---- D:\Users\Petra\AppData\Roaming\ICQ
2011-06-16 20:21:56 ----D---- D:\Program Files\ICQ7.5
2011-06-07 21:25:56 ----D---- D:\Program Files\Pokluda
2011-05-25 20:47:51 ----A---- D:\Windows\NeroDigital.ini
2011-05-25 20:47:36 ----D---- D:\Users\Petra\AppData\Roaming\Nero
2011-05-25 20:05:34 ----D---- D:\Users\Petra\AppData\Roaming\Macromedia
2011-05-25 20:04:44 ----D---- D:\Users\Petra\AppData\Roaming\Adobe
2011-05-25 19:59:31 ----D---- D:\Program Files\SMART Technologies Inc
2011-05-25 19:59:23 ----D---- D:\Program Files\Slovíčka 2.0
2011-05-25 19:58:29 ----D---- D:\Program Files\LINGUA
2011-05-25 19:58:21 ----D---- D:\Program Files\Fraus
2011-05-25 19:46:59 ----D---- D:\Users\Petra\AppData\Roaming\ESET
2011-05-25 19:46:54 ----D---- D:\Users\Petra\AppData\Roaming\ATI
2011-05-25 19:45:42 ----D---- D:\Users\Petra\AppData\Roaming\Identities
2011-05-25 19:45:23 ----SD---- D:\Users\Petra\AppData\Roaming\Microsoft
2011-05-25 19:45:23 ----D---- D:\Users\Petra\AppData\Roaming\Media Center Programs
======List of files/folders modified in the last 1 months======
2011-06-21 21:43:29 ----D---- D:\Windows\Temp
2011-06-21 21:43:25 ----D---- D:\Windows\Prefetch
2011-06-21 21:43:12 ----RD---- D:\Program Files
2011-06-21 21:24:17 ----D---- D:\Windows\system32\config
2011-06-21 21:01:01 ----D---- D:\Windows\Microsoft.NET
2011-06-21 21:01:00 ----RSD---- D:\Windows\assembly
2011-06-21 20:19:28 ----D---- D:\Windows\System32
2011-06-21 20:19:27 ----D---- D:\Windows\inf
2011-06-21 20:19:27 ----A---- D:\Windows\system32\PerfStringBackup.INI
2011-06-21 20:13:39 ----D---- D:\Windows\winsxs
2011-06-21 20:11:46 ----D---- D:\Windows\system32\sk-SK
2011-06-21 20:11:46 ----D---- D:\Program Files\Internet Explorer
2011-06-21 20:11:45 ----D---- D:\Windows\system32\migration
2011-06-21 20:11:45 ----D---- D:\Windows\system32\cs-CZ
2011-06-21 20:11:45 ----D---- D:\Windows\PolicyDefinitions
2011-06-21 20:11:44 ----D---- D:\Windows\system32\en-US
2011-06-21 20:11:44 ----D---- D:\Windows\AppPatch
2011-06-21 19:57:37 ----D---- D:\Windows\Logs
2011-06-21 19:57:27 ----D---- D:\Windows\system32\catroot
2011-06-21 19:57:23 ----D---- D:\Windows\system32\catroot2
2011-06-21 19:35:40 ----D---- D:\Windows
2011-06-21 19:35:12 ----SHD---- D:\Windows\Installer
2011-06-21 19:25:59 ----SHD---- D:\System Volume Information
2011-06-21 07:23:20 ----D---- D:\Program Files\Microsoft Silverlight
2011-06-21 07:22:05 ----D---- D:\Windows\system32\drivers
2011-06-20 20:24:36 ----D---- D:\Program Files\ICQ6Toolbar
2011-06-20 19:10:09 ----HD---- D:\ProgramData
2011-06-16 20:22:15 ----HD---- D:\Program Files\InstallShield Installation Information
2011-06-16 20:22:14 ----D---- D:\ProgramData\ICQ
2011-06-13 20:31:42 ----A---- D:\Windows\ODBC.INI
2011-06-12 14:59:01 ----D---- D:\Windows\system32\NDF
2011-06-07 21:16:21 ----D---- D:\Program Files\Moje slovíčka
2011-06-03 17:56:44 ----A---- D:\Windows\system32\MRT.exe
2011-05-25 19:45:39 ----SHD---- D:\$Recycle.Bin
2011-05-25 19:45:21 ----RD---- D:\Users
2011-05-24 19:14:10 ----N---- D:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; D:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 330264]
R0 rdyboost;ReadyBoost; D:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; D:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; D:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ehdrv;ehdrv; D:\Windows\system32\DRIVERS\ehdrv.sys [2010-02-26 114984]
R1 ElbyCDIO;ElbyCDIO Driver; D:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 truecrypt;truecrypt; D:\Windows\System32\drivers\truecrypt.sys [2010-03-17 223440]
R1 vwififlt;Virtual WiFi Filter Driver; D:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 eamonm;eamonm; D:\Windows\system32\DRIVERS\eamonm.sys [2010-02-26 133512]
R2 epfw;epfw; D:\Windows\system32\DRIVERS\epfw.sys [2010-02-26 134488]
R2 epfwwfp;epfwwfp; D:\Windows\system32\DRIVERS\epfwwfp.sys [2010-02-26 41312]
R2 S7opcsrtx;PROFINET IO RT-Protocol (LLDP); D:\Windows\system32\DRIVERS\s7opcsrtx.sys [2009-06-30 31232]
R2 s7snsrtx;PROFINET IO RT-Protocol V1.0; D:\Windows\system32\DRIVERS\s7snsrtx.sys [2009-02-24 73088]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); D:\Windows\system32\DRIVERS\sntie.sys [2009-06-05 311424]
R2 WinDriver;WinDriver; D:\Windows\System32\drivers\WINDRVR.SYS [2007-10-04 205220]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x86; D:\Windows\system32\DRIVERS\Apfiltr.sys [2009-12-26 237104]
R3 atikmdag;atikmdag; D:\Windows\system32\DRIVERS\atikmdag.sys [2009-06-25 4993536]
R3 BCM42RLY;BCM42RLY; D:\Windows\system32\drivers\BCM42RLY.sys [2009-07-17 18424]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; D:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-17 2506232]
R3 BthEnum;Ovladač pro Bluetooth Request Block; D:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); D:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; D:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 btwaudio;Bluetooth Audio Device Service; D:\Windows\system32\drivers\btwaudio.sys [2009-07-21 86056]
R3 btwavdt;Bluetooth AVDT Service; D:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-21 108072]
R3 btwl2cap;Bluetooth L2CAP Service; D:\Windows\system32\DRIVERS\btwl2cap.sys [2009-07-21 29472]
R3 btwrchid;btwrchid; D:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-21 18344]
R3 Epfwndis;Eset Personal Firewall; D:\Windows\system32\DRIVERS\Epfwndis.sys [2010-02-26 32584]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); D:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; D:\Windows\System32\Drivers\RtsUStor.sys [2009-05-08 165888]
R3 STHDA;IDT High Definition Audio CODEC; D:\Windows\system32\DRIVERS\stwrt.sys [2009-11-07 420864]
R3 VClone;VClone; D:\Windows\system32\DRIVERS\VClone.sys [2009-05-23 29696]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; D:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 WinDriver6;WinDriver6; D:\Windows\system32\drivers\windrvr6.sys [2007-10-04 166912]
S2 MLPTDR_N;MLPTDR_N; \??\D:\Windows\system32\MLPTDR_N.sys [2003-07-19 18848]
S2 Parvdm;Parvdm; D:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; D:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; D:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; D:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; D:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 fssfltr;FssFltr; D:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 FTDIBUS;USB Serial Converter Driver; D:\Windows\system32\drivers\ftdibus.sys [2010-07-12 60104]
S3 FTSER2K;USB Serial Port Driver; D:\Windows\system32\drivers\ftser2k.sys [2010-07-12 73032]
S3 jusb;jusb; D:\Windows\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 nmwcd;Nokia USB Phone Parent; D:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; D:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; D:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; D:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; D:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; D:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 RtsUIR;Realtek IR Driver; D:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 s3cap;s3cap; D:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; D:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 StarOpen;StarOpen; D:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; D:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; D:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; D:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; D:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; D:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 USBCCID;Realtek Smartcard Reader Driver; D:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbser;Sony Ericsson USB Serial Port; D:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; D:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 VGPU;VGPU; D:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; D:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; D:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; D:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; D:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\aestsrv.exe [2009-03-03 81920]
R2 almservice;Automation License Manager Service; D:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe [2009-04-23 1200128]
R2 AMD External Events Utility;AMD External Events Utility; D:\Windows\system32\atiesrxx.exe [2009-06-25 176128]
R2 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 582944]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; D:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; D:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-02-26 810120]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-04 354840]
R2 ICQ Service;ICQ Service; D:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MSSQL$WINCCPLUS;SQL Server (WINCCPLUS); d:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 s7oiehsx;SIMATIC IEPG Help Service; D:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe [2009-06-30 1576072]
R2 S7TraceServiceX;S7TraceServiceX; D:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe [2009-06-30 240776]
R2 SQLBrowser;SQL Server Browser; d:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; d:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 STacSV;Audio Service; D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\STacSV.exe [2009-11-07 229458]
R2 wlidsvc;Windows Live ID Sign-in Assistant; D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 wltrysvc;Dell Wireless WLAN Tray Service; D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [2009-07-17 26112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 FLEXlm License Manager;FLEXlm License Manager; D:\SEFlex\Program\lmgrd.exe [2009-08-01 1431440]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 AppMgmt;@appmgmts.dll,-3250; D:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EhttpSrv;ESET HTTP Server; D:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-02-26 33560]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; D:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 OpcEnum;OpcEnum; D:\Windows\system32\OpcEnum.exe [2007-04-17 135168]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; D:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; d:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
-----------------EOF-----------------
Re: Kryptik.PHU
Poprosim jeste i o druhy log z RSIT s nazvem info.txt, je ulozen v c:\rsit
Predpokladam, ze ten ESET Smart Security mate legalni = zakoupena licence
Predpokladam, ze ten ESET Smart Security mate legalni = zakoupena licence

Re: Kryptik.PHU
No, EsetSS je legalni licence z prace a nainstalovana i na domaci pocitac. Takze nelegalni postup ale s legalnim licencnim cislem. Ale tvari se, ze jede normalne....snad.
tady je info.txt
info.txt logfile of random's system information tool 1.08 2011-06-21 21:43:37
======Uninstall list======
7-Zip 4.65-->"D:\Program Files\7-Zip\Uninstall.exe"
Activation (Nero 9 HD)-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="5EA0-EM11-98K2-380M-MX8X-AXC9-20AA"
Adobe Flash Player 10 ActiveX-->D:\Windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe -maintain activex
Adobe Photoshop 7.0 CE-->D:\WINDOWS\ISUN0405.EXE -f"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.dll"
Avanquest update-->"D:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->D:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u D:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
Blu-ray Disc Authoring Plug-in-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M13-0083-2710-5622-98W3-TL0A-THW4-9A0T"
Catalyst Control Center - Branding-->MsiExec.exe /I{69533745-1E2D-4C98-8B4A-B7643EF9E1A2}
CDA to MP3 Converter v2.8 build 839-->"D:\Program Files\HooTech CDA to MP3 Converter\unins000.exe"
CDBurnerXP-->MsiExec.exe /X{5932A5C4-BB44-4CFB-AD66-1B826F4D788B}
Cisco EAP-FAST Module-->MsiExec.exe /I{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
Cisco LEAP Module-->MsiExec.exe /I{51C7AD07-C3F6-4635-8E8A-231306D810FE}
Cisco PEAP Module-->MsiExec.exe /I{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
CodeWarrior Development Studio for Freescale Digital Signal Controllers, Version 8.2.3-->MsiExec.exe /I{7C816C26-FDB7-4AE5-9816-47E55CBBB564}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell Touchpad-->D:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
Dell Wireless WLAN Card Utility-->"D:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Dell\Dell Wireless WLAN Card"
EAGLE 5.11.0-->cmd.exe /c start "EAGLE Uninstaller" /min "D:\Program Files\EAGLE-5.11.0\bin\uninstall.bat" D:\Program Files\EAGLE-5.11.0\bin
FLIP 2.4.6-->D:\Windows\IsUninst.exe -f"D:\Program Files\ATMEL\FLIP 2.4.6\Uninst.isu"
Flip 3.3.4-->D:\Program Files\Atmel\Flip 3.3.4\uninstall.exe
FOTOSVET Schlecker 3-->"D:\Program Files\Schlecker\FOTOSVET Schlecker 3\uninstall.exe"
Foxit Reader-->D:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
Google Earth-->MsiExec.exe /X{4286E640-B5FB-11DF-AC4B-005056C00008}
Google Chrome-->"D:\Program Files\Google\Chrome\Application\12.0.742.100\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
ICQ Toolbar-->D:\Program Files\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.5-->"D:\Program Files\InstallShield Installation Information\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
IDT Audio-->"D:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -remove -removeonly
Intel® Matrix Storage Manager-->D:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
JabloTool-->"D:\Windows\JabloTool Uninstaller.exe"
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Keil µVision3-->D:\Keil\Uninstall.exe
KONICA MINOLTA PagePro 1300W-->MUINST_N.EXE /PRN:"KONICA MINOLTA PagePro 1300W"
Marvell Miniport Driver-->D:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office Live Add-in 1.5-->MsiExec.exe /I{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}
Microsoft Office XP Professional s aplikací FrontPage-->MsiExec.exe /I{90280405-6000-11D3-8CFE-0050048383C9}
Microsoft Primary Interoperability Assemblies 2005-->MsiExec.exe /X{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SOAP Toolkit 3.0-->MsiExec.exe /I{BCB4C18A-ACA6-4383-8688-E19933A705DD}
Microsoft SQL Server 2005 Backward compatibility-->MsiExec.exe /I{0D61D68B-DF5E-4635-82C7-B0C53F0A581B}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server 2005 Express Edition (WINCCPLUS)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005-->"d:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Native Client-->MsiExec.exe /I{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}
Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{E7084B89-69E0-46B3-A118-8F99D06988CD}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{6AFCA4E1-9B78-3640-8F72-A7BF33448200}
Moje slovíčka 1.3-->"D:\Program Files\Moje slovíčka\unins000.exe"
Mozilla Thunderbird (3.1.7)-->D:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nástroj pro odesílání služby Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Nero 9-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
nLite 1.4.9.1-->"D:\Program Files\nLite\unins000.exe"
Nokia Connectivity Cable Driver-->MsiExec.exe /I{82427977-8776-4087-90CA-9F65174D3C4D}
Nokia Flashing Cable Driver-->MsiExec.exe /X{A4E0CA0F-1903-440A-9B98-FEA6CB049999}
Nokia Ovi Application Installer 6.85.3011-->msiexec /qn /x {42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Application Installer-->MsiExec.exe /I{42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Content Copier 6.85.3011-->msiexec /qn /x {6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi Content Copier-->MsiExec.exe /X{6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi One Touch Access 6.85.3011-->msiexec /qn /x {4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi One Touch Access-->MsiExec.exe /I{4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi Suite-->MsiExec.exe /I{B5264B25-8908-49BB-A708-5A70DFBF8094}
Nokia Ovi System Utilities 6.85.3016-->msiexec /qn /x {FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Ovi System Utilities-->MsiExec.exe /X{FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Software Updater-->MsiExec.exe /X{2FA28330-2028-4033-BD10-425C87EB4D54}
Nvu 1.0-->D:\Program Files\Nvu\uninst.exe
OPC Core Components Redistributable-->MsiExec.exe /I{75F9DAD1-792C-44E9-B48B-2E22C76E0CBF}
PC Connectivity Solution-->MsiExec.exe /I{B7CB0BF3-791E-44D3-9F04-786E36D51C9D}
PDFCreator-->D:\Program Files\PDFCreator\unins000.exe
Pomocník pro přihlášení ke službě Windows Live ID-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
Prosave V7.4 incl. SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
Prosave V7.4 SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
QuickSet32-->MsiExec.exe /I{C4972073-2BFE-475D-8441-564EA97DA161}
Realtek USB 2.0 Card Reader-->"D:\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe" -runfromtemp -l0x0005 -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Siemens Totally Integrated Automation Portal V10-->D:\Program Files\Common Files\Siemens\Automation\Siemens Totally Integrated Automation Portal V10\SIA.exe /arpmode
Siemens Automation License Manager V4.0 + SP3 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Siemens Automation License Manager-->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Slovnik verze 3.5-->"D:\Program Files\Pokluda\Slovnik\unins000.exe"
Software Bluetooth WIDCOMM-->MsiExec.exe /X{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
Solid Edge License Manager-->MsiExec.exe /X{531C1B44-611D-4909-B35E-34A11C40163E}
Solid Edge ST2-->MsiExec.exe /X{CC185D10-5C0E-40C3-91F2-63314BB365AF}
Sony Ericsson PC Companion 2.01.148-->"D:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
TIA Portal Single SetupPackage - HW Module Base Package V10.5 + HF1-->MsiExec.exe /X{F1D4FDEE-BB94-4C17-8BB0-AC06DAF854BD}
TIA Portal Single SetupPackage - HWConfig Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{047BC977-015A-4339-B571-44CA33901F63}
TIA Portal Single SetupPackage - S7BASUCL V10.5 + SP12-->MsiExec.exe /X{37F822E3-B56D-4131-8E3D-0A6753DFB8A5}
TIA Portal Single SetupPackage - STEP 7 Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{DC62C484-A0B2-421A-9A0F-1ABFE1E10D71}
TIA Portal Single SetupPackage - WinCC Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{3EB30640-F847-4F59-AF74-837D0FD02B73}
TIA Portal Single SetupPackage - WINCCBASUCL V10.5 + SP12-->MsiExec.exe /X{ABE2EE7E-11F7-4374-B86B-CB75A5F276B0}
Total Commander (Remove or Repair)-->d:\totalcmd\tcuninst.exe
Totally Integrated Automation Portal V10 - TIA Portal Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{31C1839C-7967-469C-921D-0BEB49AC0652}
TrueCrypt-->"D:\Program Files\TrueCrypt\TrueCrypt Setup.exe" /u
VC User 71 RTL X86 ----->MsiExec.exe /I{A4A4567C-5C29-4756-992D-F84D8250C435}
VirtualCloneDrive-->"D:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="D:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Essentials-->D:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{E3F328E4-EB9F-4ABF-8FF3-5AD0472743D8}
Windows Live Fotogalerie-->MsiExec.exe /X{1D097338-B4FA-4F29-9C43-8D7A970A007E}
Windows Live Mail-->MsiExec.exe /I{E5A10EF8-DBF3-4251-A9CA-423311DBBFC8}
Windows Live Sync-->MsiExec.exe /X{068B46A0-8858-4CEB-80BC-A4AE787A05FC}
Windows Live Zabezpečení rodiny-->MsiExec.exe /X{F86AD773-5BC0-499B-9F48-4E0D5FED759D}
======System event log======
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247D28-05
Event Code: 900
Message: Služba Ochrana softwaru se spouští.
Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100316192712.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192513.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192509.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100316192505.750502-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20100316192505.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.246055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.230455-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x27072
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192438.934055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.578451-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.484850-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;D:\Program Files\Nokia\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;D:\Program Files\ATI Technologies\ATI.ACE\Core-Static;D:\Program Files\Dell\Dell Wireless WLAN Card;D:\Program Files\WIDCOMM\Bluetooth Software\;d:\Program Files\Microsoft SQL Server\90\Tools\binn\;D:\Program Files\Microsoft SQL Server\80\Tools\Binn\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"AutInstLog"=D:\ProgramData\Siemens\Automation\Logfiles\Setup\
"P_SCHEMA"=D:\Program Files\Solid Edge ST2\Schema
"LM_LICENSE_FILE"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\license.dat
"MW56800ELibraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MW56800ELibraryFiles"=Runtime 56800E.Lib;MSL C 56800E.lib
"MW56800Libraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MW56800LibraryFiles"=FP56800.lib;MSL C 56800.Lib
"MWAsm56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MWAsm56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
-----------------EOF-----------------
tady je info.txt
info.txt logfile of random's system information tool 1.08 2011-06-21 21:43:37
======Uninstall list======
7-Zip 4.65-->"D:\Program Files\7-Zip\Uninstall.exe"
Activation (Nero 9 HD)-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="5EA0-EM11-98K2-380M-MX8X-AXC9-20AA"
Adobe Flash Player 10 ActiveX-->D:\Windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe -maintain activex
Adobe Photoshop 7.0 CE-->D:\WINDOWS\ISUN0405.EXE -f"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.dll"
Avanquest update-->"D:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->D:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u D:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
Blu-ray Disc Authoring Plug-in-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M13-0083-2710-5622-98W3-TL0A-THW4-9A0T"
Catalyst Control Center - Branding-->MsiExec.exe /I{69533745-1E2D-4C98-8B4A-B7643EF9E1A2}
CDA to MP3 Converter v2.8 build 839-->"D:\Program Files\HooTech CDA to MP3 Converter\unins000.exe"
CDBurnerXP-->MsiExec.exe /X{5932A5C4-BB44-4CFB-AD66-1B826F4D788B}
Cisco EAP-FAST Module-->MsiExec.exe /I{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
Cisco LEAP Module-->MsiExec.exe /I{51C7AD07-C3F6-4635-8E8A-231306D810FE}
Cisco PEAP Module-->MsiExec.exe /I{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
CodeWarrior Development Studio for Freescale Digital Signal Controllers, Version 8.2.3-->MsiExec.exe /I{7C816C26-FDB7-4AE5-9816-47E55CBBB564}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell Touchpad-->D:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
Dell Wireless WLAN Card Utility-->"D:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Dell\Dell Wireless WLAN Card"
EAGLE 5.11.0-->cmd.exe /c start "EAGLE Uninstaller" /min "D:\Program Files\EAGLE-5.11.0\bin\uninstall.bat" D:\Program Files\EAGLE-5.11.0\bin
FLIP 2.4.6-->D:\Windows\IsUninst.exe -f"D:\Program Files\ATMEL\FLIP 2.4.6\Uninst.isu"
Flip 3.3.4-->D:\Program Files\Atmel\Flip 3.3.4\uninstall.exe
FOTOSVET Schlecker 3-->"D:\Program Files\Schlecker\FOTOSVET Schlecker 3\uninstall.exe"
Foxit Reader-->D:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
Google Earth-->MsiExec.exe /X{4286E640-B5FB-11DF-AC4B-005056C00008}
Google Chrome-->"D:\Program Files\Google\Chrome\Application\12.0.742.100\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
ICQ Toolbar-->D:\Program Files\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.5-->"D:\Program Files\InstallShield Installation Information\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
IDT Audio-->"D:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -remove -removeonly
Intel® Matrix Storage Manager-->D:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
JabloTool-->"D:\Windows\JabloTool Uninstaller.exe"
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Keil µVision3-->D:\Keil\Uninstall.exe
KONICA MINOLTA PagePro 1300W-->MUINST_N.EXE /PRN:"KONICA MINOLTA PagePro 1300W"
Marvell Miniport Driver-->D:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office Live Add-in 1.5-->MsiExec.exe /I{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}
Microsoft Office XP Professional s aplikací FrontPage-->MsiExec.exe /I{90280405-6000-11D3-8CFE-0050048383C9}
Microsoft Primary Interoperability Assemblies 2005-->MsiExec.exe /X{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SOAP Toolkit 3.0-->MsiExec.exe /I{BCB4C18A-ACA6-4383-8688-E19933A705DD}
Microsoft SQL Server 2005 Backward compatibility-->MsiExec.exe /I{0D61D68B-DF5E-4635-82C7-B0C53F0A581B}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server 2005 Express Edition (WINCCPLUS)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005-->"d:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Native Client-->MsiExec.exe /I{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}
Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{E7084B89-69E0-46B3-A118-8F99D06988CD}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{6AFCA4E1-9B78-3640-8F72-A7BF33448200}
Moje slovíčka 1.3-->"D:\Program Files\Moje slovíčka\unins000.exe"
Mozilla Thunderbird (3.1.7)-->D:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nástroj pro odesílání služby Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Nero 9-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
nLite 1.4.9.1-->"D:\Program Files\nLite\unins000.exe"
Nokia Connectivity Cable Driver-->MsiExec.exe /I{82427977-8776-4087-90CA-9F65174D3C4D}
Nokia Flashing Cable Driver-->MsiExec.exe /X{A4E0CA0F-1903-440A-9B98-FEA6CB049999}
Nokia Ovi Application Installer 6.85.3011-->msiexec /qn /x {42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Application Installer-->MsiExec.exe /I{42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Content Copier 6.85.3011-->msiexec /qn /x {6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi Content Copier-->MsiExec.exe /X{6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi One Touch Access 6.85.3011-->msiexec /qn /x {4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi One Touch Access-->MsiExec.exe /I{4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi Suite-->MsiExec.exe /I{B5264B25-8908-49BB-A708-5A70DFBF8094}
Nokia Ovi System Utilities 6.85.3016-->msiexec /qn /x {FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Ovi System Utilities-->MsiExec.exe /X{FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Software Updater-->MsiExec.exe /X{2FA28330-2028-4033-BD10-425C87EB4D54}
Nvu 1.0-->D:\Program Files\Nvu\uninst.exe
OPC Core Components Redistributable-->MsiExec.exe /I{75F9DAD1-792C-44E9-B48B-2E22C76E0CBF}
PC Connectivity Solution-->MsiExec.exe /I{B7CB0BF3-791E-44D3-9F04-786E36D51C9D}
PDFCreator-->D:\Program Files\PDFCreator\unins000.exe
Pomocník pro přihlášení ke službě Windows Live ID-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
Prosave V7.4 incl. SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
Prosave V7.4 SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
QuickSet32-->MsiExec.exe /I{C4972073-2BFE-475D-8441-564EA97DA161}
Realtek USB 2.0 Card Reader-->"D:\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe" -runfromtemp -l0x0005 -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Siemens Totally Integrated Automation Portal V10-->D:\Program Files\Common Files\Siemens\Automation\Siemens Totally Integrated Automation Portal V10\SIA.exe /arpmode
Siemens Automation License Manager V4.0 + SP3 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Siemens Automation License Manager-->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Slovnik verze 3.5-->"D:\Program Files\Pokluda\Slovnik\unins000.exe"
Software Bluetooth WIDCOMM-->MsiExec.exe /X{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
Solid Edge License Manager-->MsiExec.exe /X{531C1B44-611D-4909-B35E-34A11C40163E}
Solid Edge ST2-->MsiExec.exe /X{CC185D10-5C0E-40C3-91F2-63314BB365AF}
Sony Ericsson PC Companion 2.01.148-->"D:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
TIA Portal Single SetupPackage - HW Module Base Package V10.5 + HF1-->MsiExec.exe /X{F1D4FDEE-BB94-4C17-8BB0-AC06DAF854BD}
TIA Portal Single SetupPackage - HWConfig Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{047BC977-015A-4339-B571-44CA33901F63}
TIA Portal Single SetupPackage - S7BASUCL V10.5 + SP12-->MsiExec.exe /X{37F822E3-B56D-4131-8E3D-0A6753DFB8A5}
TIA Portal Single SetupPackage - STEP 7 Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{DC62C484-A0B2-421A-9A0F-1ABFE1E10D71}
TIA Portal Single SetupPackage - WinCC Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{3EB30640-F847-4F59-AF74-837D0FD02B73}
TIA Portal Single SetupPackage - WINCCBASUCL V10.5 + SP12-->MsiExec.exe /X{ABE2EE7E-11F7-4374-B86B-CB75A5F276B0}
Total Commander (Remove or Repair)-->d:\totalcmd\tcuninst.exe
Totally Integrated Automation Portal V10 - TIA Portal Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{31C1839C-7967-469C-921D-0BEB49AC0652}
TrueCrypt-->"D:\Program Files\TrueCrypt\TrueCrypt Setup.exe" /u
VC User 71 RTL X86 ----->MsiExec.exe /I{A4A4567C-5C29-4756-992D-F84D8250C435}
VirtualCloneDrive-->"D:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="D:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Essentials-->D:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{E3F328E4-EB9F-4ABF-8FF3-5AD0472743D8}
Windows Live Fotogalerie-->MsiExec.exe /X{1D097338-B4FA-4F29-9C43-8D7A970A007E}
Windows Live Mail-->MsiExec.exe /I{E5A10EF8-DBF3-4251-A9CA-423311DBBFC8}
Windows Live Sync-->MsiExec.exe /X{068B46A0-8858-4CEB-80BC-A4AE787A05FC}
Windows Live Zabezpečení rodiny-->MsiExec.exe /X{F86AD773-5BC0-499B-9F48-4E0D5FED759D}
======System event log======
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247D28-05
Event Code: 900
Message: Služba Ochrana softwaru se spouští.
Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100316192712.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192513.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192509.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100316192505.750502-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20100316192505.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.246055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.230455-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x27072
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192438.934055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.578451-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.484850-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;D:\Program Files\Nokia\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;D:\Program Files\ATI Technologies\ATI.ACE\Core-Static;D:\Program Files\Dell\Dell Wireless WLAN Card;D:\Program Files\WIDCOMM\Bluetooth Software\;d:\Program Files\Microsoft SQL Server\90\Tools\binn\;D:\Program Files\Microsoft SQL Server\80\Tools\Binn\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"AutInstLog"=D:\ProgramData\Siemens\Automation\Logfiles\Setup\
"P_SCHEMA"=D:\Program Files\Solid Edge ST2\Schema
"LM_LICENSE_FILE"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\license.dat
"MW56800ELibraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MW56800ELibraryFiles"=Runtime 56800E.Lib;MSL C 56800E.lib
"MW56800Libraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MW56800LibraryFiles"=FP56800.lib;MSL C 56800.Lib
"MWAsm56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MWAsm56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
-----------------EOF-----------------
Re: Kryptik.PHU
Dle pravidel fora (viz zde a a zde bod c.3 ) se vsak nelegalnim SW nezabyvame, jelikoz nelegalni programy jsou vetsinou zdrojem haveti. Navic tim porusujete i autorska prava
, pachate trestny cin a ten jako takovy nebude nasim forem podporovan. Uvedomte si, ze jste na bezpecnostnim foru - podpora warezu (zvlaste bezpecnostnich programu) by byla zcela proti logice fora
Obstarejte si proto legalni ochranu Vaseho PC (antivir), pote sem vlozte novy log z RSITu a CKScanneru - viz nize.
Osobne Vam doporucuji Avast, Aviru nebo MSE. Prehled antiviru mate ZDE.
Log z RSITu - viz muj podpis
Stahnete na plochu CKScanner


Obstarejte si proto legalni ochranu Vaseho PC (antivir), pote sem vlozte novy log z RSITu a CKScanneru - viz nize.
Osobne Vam doporucuji Avast, Aviru nebo MSE. Prehled antiviru mate ZDE.


- Spustte a kliknete na Search for files
- Po dokonceni skenu kliknete na Save List to File a nasledne OK
- Na plose se Vam vytvori log s nazvem ckfiles.txt, jeho obsah mi sem vlozte
Re: Kryptik.PHU
Omlouvam se za ne zcela legalni Eset. Uz jsem se to snazil napravit. Prikladam nove logy podle vasich instrukci. Jeste uvadim, ze po nekolika skenech Esetem jeste nez jsem ho odinstaloval a vymenil za Aviru, tak uz nenasel zadny Kryptik ani pocitac neblbne tak jak pri nakazeni. Ale byl bych moc rad za overeni, zda tomu tak opravdu je. Budu pripraven na pripadne dalsi instrukce. Dekuji.
----------------------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Petra at 2011-06-22 22:20:36
Microsoft Windows 7 Ultimate Service Pack 1
System drive D: has 254 GB (85%) free of 300 GB
Total RAM: 3580 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:20:44, on 22.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
D:\Windows\system32\taskhost.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
D:\Program Files\IDT\WDM\sttray.exe
D:\Program Files\DellTPad\Apoint.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\DellTPad\ApMsgFwd.exe
D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
D:\Program Files\DellTPad\Apntex.exe
D:\Windows\system32\conhost.exe
D:\Program Files\DellTPad\HidFind.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Windows\system32\taskhost.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
D:\Program Files\IDT\WDM\sttray.exe
D:\Program Files\DellTPad\Apoint.exe
D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\ICQ7.5\ICQ.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Program Files\DellTPad\ApMsgFwd.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\DellTPad\HidFind.exe
D:\Program Files\DellTPad\Apntex.exe
D:\Windows\system32\conhost.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Users\Petra\Desktop\Kryptik\RSIT.exe
D:\Program Files\trend micro\Petra.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [SysTrayApp] D:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NokiaMServer] D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SiemensAutomationFileStorage] D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe preload
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-257607640-3239265805-1610675059-1001\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'alvr')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @D:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @D:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: d:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: d:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\aestsrv.exe
O23 - Service: Automation License Manager Service (almservice) - SIEMENS AG - D:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe
O23 - Service: AMD External Events Utility - AMD - D:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: FLEXlm License Manager - Acresso Software Inc. - D:\SEFlex\Program\lmgrd.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - D:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: OpcEnum - OPC Foundation - D:\Windows\system32\OpcEnum.exe
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx) - SIEMENS AG - D:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: S7TraceServiceX - SIEMENS AG - D:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - D:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
--
End of file - 10712 bytes
======Scheduled tasks folder======
D:\Windows\tasks\GoogleUpdateTaskMachineCore.job
D:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-02 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickSet"=C:\Program Files\Dell\QuickSet\QuickSet.exe [2008-11-14 1708032]
"IAAnotif"=D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-04 186904]
"StartCCC"=D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-06-25 98304]
"Broadcom Wireless Manager UI"=D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [2009-07-17 4562944]
"SysTrayApp"=D:\Program Files\IDT\WDM\sttray.exe [2009-11-07 495708]
"Apoint"=D:\Program Files\DellTPad\Apoint.exe [2010-01-18 274432]
"NokiaMServer"=D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles []
"VirtualCloneDrive"=D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-05-27 85160]
"SiemensAutomationFileStorage"=D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe [2009-11-17 364544]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2008-11-14 1708032]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2011-03-02 149280]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-04-21 281768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ICQ"=D:\Program Files\ICQ7.5\ICQ.exe [2011-06-16 124216]
D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - D:\Windows\System32\Notepad.exe %1
.js - open - D:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-22 22:07:23 ----A---- D:\Windows\system32\drivers\ssmdrv.sys
2011-06-22 22:07:21 ----A---- D:\Windows\system32\drivers\avipbb.sys
2011-06-22 22:07:21 ----A---- D:\Windows\system32\drivers\avgntflt.sys
2011-06-22 22:07:20 ----D---- D:\ProgramData\Avira
2011-06-22 22:07:20 ----D---- D:\Program Files\Avira
2011-06-21 21:43:12 ----D---- D:\Program Files\trend micro
2011-06-21 21:43:11 ----D---- D:\rsit
2011-06-21 19:56:34 ----A---- D:\Windows\system32\wininet.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\wextract.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\webcheck.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\vbscript.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\urlmon.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\url.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\SetIEInstalledDate.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\RegisterIEPKEYs.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\pngfilt.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\occache.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msrating.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msls31.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtmler.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtmled.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtml.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshta.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeedssync.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeedsbs.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeeds.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\licmgr10.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jsproxy.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jscript9.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jscript.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\inseng.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\imgutil.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iexpress.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieUnatt.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieui.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iesysprep.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iesetup.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iertutil.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iernonce.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iepeers.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieframe.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iedkcs32.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieapfltr.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieakui.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieaksie.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieakeng.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\IEAdvpack.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ie4uinit.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\icardie.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\dxtrans.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\dxtmsft.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\admparse.dll
2011-06-21 19:24:37 ----A---- D:\Windows\system32\poqexec.exe
2011-06-21 19:24:32 ----A---- D:\Windows\system32\prevhost.exe
2011-06-20 20:52:13 ----SHD---- D:\Config.Msi
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb20.sys
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb10.sys
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb.sys
2011-06-20 20:45:26 ----A---- D:\Windows\system32\XpsGdiConverter.dll
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srvnet.sys
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srv2.sys
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srv.sys
2011-06-20 20:44:51 ----A---- D:\Windows\system32\dnsrslvr.dll
2011-06-20 20:44:51 ----A---- D:\Windows\system32\dnsapi.dll
2011-06-20 20:44:50 ----A---- D:\Windows\system32\dnscacheugc.exe
2011-06-20 20:44:46 ----A---- D:\Windows\system32\drivers\tcpip.sys
2011-06-20 20:44:45 ----A---- D:\Windows\system32\drivers\afd.sys
2011-06-20 20:44:44 ----A---- D:\Windows\system32\inetcomm.dll
2011-06-20 20:44:42 ----A---- D:\Windows\system32\oleaut32.dll
2011-06-20 20:44:40 ----A---- D:\Windows\system32\atmlib.dll
2011-06-20 20:44:40 ----A---- D:\Windows\system32\atmfd.dll
2011-06-20 20:44:39 ----A---- D:\Windows\system32\win32k.sys
2011-06-20 20:44:35 ----A---- D:\Windows\explorer.exe
2011-06-20 20:44:34 ----A---- D:\Windows\system32\FXSCOVER.exe
2011-06-20 20:44:32 ----A---- D:\Windows\system32\XpsPrint.dll
2011-06-20 20:44:31 ----A---- D:\Windows\system32\mfc42.dll
2011-06-20 20:44:30 ----A---- D:\Windows\system32\mfc42u.dll
2011-06-20 20:44:23 ----A---- D:\Windows\system32\ntkrnlpa.exe
2011-06-20 20:44:22 ----A---- D:\Windows\system32\ntoskrnl.exe
2011-06-20 20:44:10 ----A---- D:\Windows\system32\drivers\bowser.sys
2011-06-20 20:43:57 ----A---- D:\Windows\system32\d3d10_1.dll
2011-06-20 20:42:25 ----A---- D:\Windows\system32\drivers\Diskdump.sys
2011-06-20 19:10:09 ----D---- D:\ProgramData\bD42900LoEhE42900
2011-06-20 19:09:07 ----D---- D:\Windows\Sun
2011-06-19 19:35:39 ----D---- D:\ProgramData\tmp
2011-06-19 19:35:38 ----D---- D:\ProgramData\hps
2011-06-19 15:25:50 ----D---- D:\Program Files\Schlecker
2011-06-16 20:22:15 ----D---- D:\Users\Petra\AppData\Roaming\Mozilla
2011-06-16 20:22:04 ----D---- D:\Users\Petra\AppData\Roaming\ICQ
2011-06-16 20:21:56 ----D---- D:\Program Files\ICQ7.5
2011-06-07 21:25:56 ----D---- D:\Program Files\Pokluda
2011-05-25 20:47:51 ----A---- D:\Windows\NeroDigital.ini
2011-05-25 20:47:36 ----D---- D:\Users\Petra\AppData\Roaming\Nero
2011-05-25 20:05:34 ----D---- D:\Users\Petra\AppData\Roaming\Macromedia
2011-05-25 20:04:44 ----D---- D:\Users\Petra\AppData\Roaming\Adobe
2011-05-25 19:59:31 ----D---- D:\Program Files\SMART Technologies Inc
2011-05-25 19:59:23 ----D---- D:\Program Files\Slovíčka 2.0
2011-05-25 19:58:29 ----D---- D:\Program Files\LINGUA
2011-05-25 19:58:21 ----D---- D:\Program Files\Fraus
2011-05-25 19:46:59 ----D---- D:\Users\Petra\AppData\Roaming\ESET
2011-05-25 19:46:54 ----D---- D:\Users\Petra\AppData\Roaming\ATI
2011-05-25 19:45:42 ----D---- D:\Users\Petra\AppData\Roaming\Identities
2011-05-25 19:45:23 ----SD---- D:\Users\Petra\AppData\Roaming\Microsoft
2011-05-25 19:45:23 ----D---- D:\Users\Petra\AppData\Roaming\Media Center Programs
======List of files/folders modified in the last 1 months======
2011-06-22 22:20:38 ----D---- D:\Windows\Temp
2011-06-22 22:19:32 ----D---- D:\Windows\System32
2011-06-22 22:19:32 ----D---- D:\Windows\inf
2011-06-22 22:19:32 ----A---- D:\Windows\system32\PerfStringBackup.INI
2011-06-22 22:17:28 ----D---- D:\Windows\system32\config
2011-06-22 22:15:04 ----D---- D:\Windows\Prefetch
2011-06-22 22:07:23 ----D---- D:\Windows\system32\drivers
2011-06-22 22:07:20 ----RD---- D:\Program Files
2011-06-22 22:07:20 ----HD---- D:\ProgramData
2011-06-22 21:59:30 ----SHD---- D:\Windows\Installer
2011-06-22 21:58:48 ----D---- D:\Windows\system32\DriverStore
2011-06-22 21:58:48 ----D---- D:\Windows\system32\catroot
2011-06-21 21:01:01 ----D---- D:\Windows\Microsoft.NET
2011-06-21 21:01:00 ----RSD---- D:\Windows\assembly
2011-06-21 20:13:39 ----D---- D:\Windows\winsxs
2011-06-21 20:11:46 ----D---- D:\Windows\system32\sk-SK
2011-06-21 20:11:46 ----D---- D:\Program Files\Internet Explorer
2011-06-21 20:11:45 ----D---- D:\Windows\system32\migration
2011-06-21 20:11:45 ----D---- D:\Windows\system32\cs-CZ
2011-06-21 20:11:45 ----D---- D:\Windows\PolicyDefinitions
2011-06-21 20:11:44 ----D---- D:\Windows\system32\en-US
2011-06-21 20:11:44 ----D---- D:\Windows\AppPatch
2011-06-21 19:57:37 ----D---- D:\Windows\Logs
2011-06-21 19:57:23 ----D---- D:\Windows\system32\catroot2
2011-06-21 19:35:40 ----D---- D:\Windows
2011-06-21 19:25:59 ----SHD---- D:\System Volume Information
2011-06-21 07:23:20 ----D---- D:\Program Files\Microsoft Silverlight
2011-06-20 20:24:36 ----D---- D:\Program Files\ICQ6Toolbar
2011-06-16 20:22:15 ----HD---- D:\Program Files\InstallShield Installation Information
2011-06-16 20:22:14 ----D---- D:\ProgramData\ICQ
2011-06-13 20:31:42 ----A---- D:\Windows\ODBC.INI
2011-06-12 14:59:01 ----D---- D:\Windows\system32\NDF
2011-06-07 21:16:21 ----D---- D:\Program Files\Moje slovíčka
2011-06-03 17:56:44 ----A---- D:\Windows\system32\MRT.exe
2011-05-25 19:45:39 ----SHD---- D:\$Recycle.Bin
2011-05-25 19:45:21 ----RD---- D:\Users
2011-05-24 19:14:10 ----N---- D:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; D:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 330264]
R0 rdyboost;ReadyBoost; D:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; D:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 avipbb;avipbb; D:\Windows\system32\DRIVERS\avipbb.sys [2011-06-17 137656]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; D:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ElbyCDIO;ElbyCDIO Driver; D:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 ssmdrv;ssmdrv; D:\Windows\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R1 truecrypt;truecrypt; D:\Windows\System32\drivers\truecrypt.sys [2010-03-17 223440]
R1 vwififlt;Virtual WiFi Filter Driver; D:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 avgntflt;avgntflt; D:\Windows\system32\DRIVERS\avgntflt.sys [2011-06-17 61960]
R2 S7opcsrtx;PROFINET IO RT-Protocol (LLDP); D:\Windows\system32\DRIVERS\s7opcsrtx.sys [2009-06-30 31232]
R2 s7snsrtx;PROFINET IO RT-Protocol V1.0; D:\Windows\system32\DRIVERS\s7snsrtx.sys [2009-02-24 73088]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); D:\Windows\system32\DRIVERS\sntie.sys [2009-06-05 311424]
R2 WinDriver;WinDriver; D:\Windows\System32\drivers\WINDRVR.SYS [2007-10-04 205220]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x86; D:\Windows\system32\DRIVERS\Apfiltr.sys [2009-12-26 237104]
R3 atikmdag;atikmdag; D:\Windows\system32\DRIVERS\atikmdag.sys [2009-06-25 4993536]
R3 BCM42RLY;BCM42RLY; D:\Windows\system32\drivers\BCM42RLY.sys [2009-07-17 18424]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; D:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-17 2506232]
R3 BthEnum;Ovladač pro Bluetooth Request Block; D:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); D:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; D:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 btwaudio;Bluetooth Audio Device Service; D:\Windows\system32\drivers\btwaudio.sys [2009-07-21 86056]
R3 btwavdt;Bluetooth AVDT Service; D:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-21 108072]
R3 btwl2cap;Bluetooth L2CAP Service; D:\Windows\system32\DRIVERS\btwl2cap.sys [2009-07-21 29472]
R3 btwrchid;btwrchid; D:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-21 18344]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); D:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; D:\Windows\System32\Drivers\RtsUStor.sys [2009-05-08 165888]
R3 STHDA;IDT High Definition Audio CODEC; D:\Windows\system32\DRIVERS\stwrt.sys [2009-11-07 420864]
R3 VClone;VClone; D:\Windows\system32\DRIVERS\VClone.sys [2009-05-23 29696]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; D:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 WinDriver6;WinDriver6; D:\Windows\system32\drivers\windrvr6.sys [2007-10-04 166912]
S2 eamonm;eamonm; D:\Windows\system32\DRIVERS\eamonm.sys []
S2 MLPTDR_N;MLPTDR_N; \??\D:\Windows\system32\MLPTDR_N.sys [2003-07-19 18848]
S2 Parvdm;Parvdm; D:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; D:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; D:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; D:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; D:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 fssfltr;FssFltr; D:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 FTDIBUS;USB Serial Converter Driver; D:\Windows\system32\drivers\ftdibus.sys [2010-07-12 60104]
S3 FTSER2K;USB Serial Port Driver; D:\Windows\system32\drivers\ftser2k.sys [2010-07-12 73032]
S3 jusb;jusb; D:\Windows\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 nmwcd;Nokia USB Phone Parent; D:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; D:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; D:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; D:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; D:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; D:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 RtsUIR;Realtek IR Driver; D:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 s3cap;s3cap; D:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; D:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 StarOpen;StarOpen; D:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; D:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; D:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; D:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; D:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; D:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 USBCCID;Realtek Smartcard Reader Driver; D:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbser;Sony Ericsson USB Serial Port; D:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; D:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 VGPU;VGPU; D:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; D:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; D:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; D:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; D:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\aestsrv.exe [2009-03-03 81920]
R2 almservice;Automation License Manager Service; D:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe [2009-04-23 1200128]
R2 AMD External Events Utility;AMD External Events Utility; D:\Windows\system32\atiesrxx.exe [2009-06-25 176128]
R2 AntiVirService;Avira AntiVir Guard; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-04-21 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
R2 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 582944]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; D:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-04 354840]
R2 ICQ Service;ICQ Service; D:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MSSQL$WINCCPLUS;SQL Server (WINCCPLUS); d:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 s7oiehsx;SIMATIC IEPG Help Service; D:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe [2009-06-30 1576072]
R2 S7TraceServiceX;S7TraceServiceX; D:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe [2009-06-30 240776]
R2 SQLBrowser;SQL Server Browser; d:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; d:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 STacSV;Audio Service; D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\STacSV.exe [2009-11-07 229458]
R2 wlidsvc;Windows Live ID Sign-in Assistant; D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 wltrysvc;Dell Wireless WLAN Tray Service; D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [2009-07-17 26112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 FLEXlm License Manager;FLEXlm License Manager; D:\SEFlex\Program\lmgrd.exe [2009-08-01 1431440]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 AppMgmt;@appmgmts.dll,-3250; D:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; D:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 OpcEnum;OpcEnum; D:\Windows\system32\OpcEnum.exe [2007-04-17 135168]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; D:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; d:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2011-06-22 22:22:07
======Uninstall list======
7-Zip 4.65-->"D:\Program Files\7-Zip\Uninstall.exe"
Activation (Nero 9 HD)-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="5EA0-EM11-98K2-380M-MX8X-AXC9-20AA"
Adobe Flash Player 10 ActiveX-->D:\Windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe -maintain activex
Adobe Photoshop 7.0 CE-->D:\WINDOWS\ISUN0405.EXE -f"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.dll"
Avanquest update-->"D:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
Avira AntiVir Personal - Free Antivirus-->D:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->D:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u D:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
Blu-ray Disc Authoring Plug-in-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M13-0083-2710-5622-98W3-TL0A-THW4-9A0T"
Catalyst Control Center - Branding-->MsiExec.exe /I{69533745-1E2D-4C98-8B4A-B7643EF9E1A2}
CDA to MP3 Converter v2.8 build 839-->"D:\Program Files\HooTech CDA to MP3 Converter\unins000.exe"
CDBurnerXP-->MsiExec.exe /X{5932A5C4-BB44-4CFB-AD66-1B826F4D788B}
Cisco EAP-FAST Module-->MsiExec.exe /I{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
Cisco LEAP Module-->MsiExec.exe /I{51C7AD07-C3F6-4635-8E8A-231306D810FE}
Cisco PEAP Module-->MsiExec.exe /I{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
CodeWarrior Development Studio for Freescale Digital Signal Controllers, Version 8.2.3-->MsiExec.exe /I{7C816C26-FDB7-4AE5-9816-47E55CBBB564}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell Touchpad-->D:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
Dell Wireless WLAN Card Utility-->"D:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Dell\Dell Wireless WLAN Card"
EAGLE 5.11.0-->cmd.exe /c start "EAGLE Uninstaller" /min "D:\Program Files\EAGLE-5.11.0\bin\uninstall.bat" D:\Program Files\EAGLE-5.11.0\bin
FLIP 2.4.6-->D:\Windows\IsUninst.exe -f"D:\Program Files\ATMEL\FLIP 2.4.6\Uninst.isu"
Flip 3.3.4-->D:\Program Files\Atmel\Flip 3.3.4\uninstall.exe
FOTOSVET Schlecker 3-->"D:\Program Files\Schlecker\FOTOSVET Schlecker 3\uninstall.exe"
Foxit Reader-->D:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
Google Earth-->MsiExec.exe /X{4286E640-B5FB-11DF-AC4B-005056C00008}
Google Chrome-->"D:\Program Files\Google\Chrome\Application\12.0.742.100\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
ICQ Toolbar-->D:\Program Files\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.5-->"D:\Program Files\InstallShield Installation Information\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
IDT Audio-->"D:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -remove -removeonly
Intel® Matrix Storage Manager-->D:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
JabloTool-->"D:\Windows\JabloTool Uninstaller.exe"
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Keil µVision3-->D:\Keil\Uninstall.exe
KONICA MINOLTA PagePro 1300W-->MUINST_N.EXE /PRN:"KONICA MINOLTA PagePro 1300W"
Marvell Miniport Driver-->D:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office Live Add-in 1.5-->MsiExec.exe /I{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}
Microsoft Office XP Professional s aplikací FrontPage-->MsiExec.exe /I{90280405-6000-11D3-8CFE-0050048383C9}
Microsoft Primary Interoperability Assemblies 2005-->MsiExec.exe /X{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SOAP Toolkit 3.0-->MsiExec.exe /I{BCB4C18A-ACA6-4383-8688-E19933A705DD}
Microsoft SQL Server 2005 Backward compatibility-->MsiExec.exe /I{0D61D68B-DF5E-4635-82C7-B0C53F0A581B}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server 2005 Express Edition (WINCCPLUS)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005-->"d:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Native Client-->MsiExec.exe /I{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}
Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{E7084B89-69E0-46B3-A118-8F99D06988CD}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{6AFCA4E1-9B78-3640-8F72-A7BF33448200}
Moje slovíčka 1.3-->"D:\Program Files\Moje slovíčka\unins000.exe"
Mozilla Thunderbird (3.1.7)-->D:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nástroj pro odesílání služby Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Nero 9-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
nLite 1.4.9.1-->"D:\Program Files\nLite\unins000.exe"
Nokia Connectivity Cable Driver-->MsiExec.exe /I{82427977-8776-4087-90CA-9F65174D3C4D}
Nokia Flashing Cable Driver-->MsiExec.exe /X{A4E0CA0F-1903-440A-9B98-FEA6CB049999}
Nokia Ovi Application Installer 6.85.3011-->msiexec /qn /x {42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Application Installer-->MsiExec.exe /I{42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Content Copier 6.85.3011-->msiexec /qn /x {6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi Content Copier-->MsiExec.exe /X{6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi One Touch Access 6.85.3011-->msiexec /qn /x {4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi One Touch Access-->MsiExec.exe /I{4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi Suite-->MsiExec.exe /I{B5264B25-8908-49BB-A708-5A70DFBF8094}
Nokia Ovi System Utilities 6.85.3016-->msiexec /qn /x {FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Ovi System Utilities-->MsiExec.exe /X{FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Software Updater-->MsiExec.exe /X{2FA28330-2028-4033-BD10-425C87EB4D54}
Nvu 1.0-->D:\Program Files\Nvu\uninst.exe
OPC Core Components Redistributable-->MsiExec.exe /I{75F9DAD1-792C-44E9-B48B-2E22C76E0CBF}
PC Connectivity Solution-->MsiExec.exe /I{B7CB0BF3-791E-44D3-9F04-786E36D51C9D}
PDFCreator-->D:\Program Files\PDFCreator\unins000.exe
Pomocník pro přihlášení ke službě Windows Live ID-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
Prosave V7.4 incl. SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
Prosave V7.4 SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
QuickSet32-->MsiExec.exe /I{C4972073-2BFE-475D-8441-564EA97DA161}
Realtek USB 2.0 Card Reader-->"D:\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe" -runfromtemp -l0x0005 -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Siemens Totally Integrated Automation Portal V10-->D:\Program Files\Common Files\Siemens\Automation\Siemens Totally Integrated Automation Portal V10\SIA.exe /arpmode
Siemens Automation License Manager V4.0 + SP3 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Siemens Automation License Manager-->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Slovnik verze 3.5-->"D:\Program Files\Pokluda\Slovnik\unins000.exe"
Software Bluetooth WIDCOMM-->MsiExec.exe /X{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
Solid Edge License Manager-->MsiExec.exe /X{531C1B44-611D-4909-B35E-34A11C40163E}
Solid Edge ST2-->MsiExec.exe /X{CC185D10-5C0E-40C3-91F2-63314BB365AF}
Sony Ericsson PC Companion 2.01.148-->"D:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
TIA Portal Single SetupPackage - HW Module Base Package V10.5 + HF1-->MsiExec.exe /X{F1D4FDEE-BB94-4C17-8BB0-AC06DAF854BD}
TIA Portal Single SetupPackage - HWConfig Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{047BC977-015A-4339-B571-44CA33901F63}
TIA Portal Single SetupPackage - S7BASUCL V10.5 + SP12-->MsiExec.exe /X{37F822E3-B56D-4131-8E3D-0A6753DFB8A5}
TIA Portal Single SetupPackage - STEP 7 Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{DC62C484-A0B2-421A-9A0F-1ABFE1E10D71}
TIA Portal Single SetupPackage - WinCC Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{3EB30640-F847-4F59-AF74-837D0FD02B73}
TIA Portal Single SetupPackage - WINCCBASUCL V10.5 + SP12-->MsiExec.exe /X{ABE2EE7E-11F7-4374-B86B-CB75A5F276B0}
Total Commander (Remove or Repair)-->d:\totalcmd\tcuninst.exe
Totally Integrated Automation Portal V10 - TIA Portal Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{31C1839C-7967-469C-921D-0BEB49AC0652}
TrueCrypt-->"D:\Program Files\TrueCrypt\TrueCrypt Setup.exe" /u
VC User 71 RTL X86 ----->MsiExec.exe /I{A4A4567C-5C29-4756-992D-F84D8250C435}
VirtualCloneDrive-->"D:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="D:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Essentials-->D:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{E3F328E4-EB9F-4ABF-8FF3-5AD0472743D8}
Windows Live Fotogalerie-->MsiExec.exe /X{1D097338-B4FA-4F29-9C43-8D7A970A007E}
Windows Live Mail-->MsiExec.exe /I{E5A10EF8-DBF3-4251-A9CA-423311DBBFC8}
Windows Live Sync-->MsiExec.exe /X{068B46A0-8858-4CEB-80BC-A4AE787A05FC}
Windows Live Zabezpečení rodiny-->MsiExec.exe /X{F86AD773-5BC0-499B-9F48-4E0D5FED759D}
======System event log======
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247D28-05
Event Code: 900
Message: Služba Ochrana softwaru se spouští.
Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100316192712.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192513.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192509.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100316192505.750502-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20100316192505.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.246055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.230455-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x27072
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192438.934055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.578451-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.484850-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;D:\Program Files\Nokia\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;D:\Program Files\ATI Technologies\ATI.ACE\Core-Static;D:\Program Files\Dell\Dell Wireless WLAN Card;D:\Program Files\WIDCOMM\Bluetooth Software\;d:\Program Files\Microsoft SQL Server\90\Tools\binn\;D:\Program Files\Microsoft SQL Server\80\Tools\Binn\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"AutInstLog"=D:\ProgramData\Siemens\Automation\Logfiles\Setup\
"P_SCHEMA"=D:\Program Files\Solid Edge ST2\Schema
"LM_LICENSE_FILE"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\license.dat
"MW56800ELibraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MW56800ELibraryFiles"=Runtime 56800E.Lib;MSL C 56800E.lib
"MW56800Libraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MW56800LibraryFiles"=FP56800.lib;MSL C 56800.Lib
"MWAsm56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MWAsm56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
-----------------EOF-----------------
CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----
----------------------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Petra at 2011-06-22 22:20:36
Microsoft Windows 7 Ultimate Service Pack 1
System drive D: has 254 GB (85%) free of 300 GB
Total RAM: 3580 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:20:44, on 22.6.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
D:\Windows\system32\taskhost.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
D:\Program Files\IDT\WDM\sttray.exe
D:\Program Files\DellTPad\Apoint.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\DellTPad\ApMsgFwd.exe
D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
D:\Program Files\DellTPad\Apntex.exe
D:\Windows\system32\conhost.exe
D:\Program Files\DellTPad\HidFind.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Windows\system32\taskhost.exe
D:\Windows\system32\Dwm.exe
D:\Windows\Explorer.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
D:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
D:\Program Files\IDT\WDM\sttray.exe
D:\Program Files\DellTPad\Apoint.exe
D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\Program Files\ICQ7.5\ICQ.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
D:\Program Files\DellTPad\ApMsgFwd.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\DellTPad\HidFind.exe
D:\Program Files\DellTPad\Apntex.exe
D:\Windows\system32\conhost.exe
D:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Users\Petra\Desktop\Kryptik\RSIT.exe
D:\Program Files\trend micro\Petra.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [SysTrayApp] D:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NokiaMServer] D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [SiemensAutomationFileStorage] D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe preload
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ICQ] "D:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] D:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-257607640-3239265805-1610675059-1001\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'alvr')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - D:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @D:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @D:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: d:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: d:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\aestsrv.exe
O23 - Service: Automation License Manager Service (almservice) - SIEMENS AG - D:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe
O23 - Service: AMD External Events Utility - AMD - D:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: FLEXlm License Manager - Acresso Software Inc. - D:\SEFlex\Program\lmgrd.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICQ Service - Unknown owner - D:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: OpcEnum - OPC Foundation - D:\Windows\system32\OpcEnum.exe
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx) - SIEMENS AG - D:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: S7TraceServiceX - SIEMENS AG - D:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - D:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
--
End of file - 10712 bytes
======Scheduled tasks folder======
D:\Windows\tasks\GoogleUpdateTaskMachineCore.job
D:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-03-02 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - D:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-11-21 1054520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickSet"=C:\Program Files\Dell\QuickSet\QuickSet.exe [2008-11-14 1708032]
"IAAnotif"=D:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-04 186904]
"StartCCC"=D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-06-25 98304]
"Broadcom Wireless Manager UI"=D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [2009-07-17 4562944]
"SysTrayApp"=D:\Program Files\IDT\WDM\sttray.exe [2009-11-07 495708]
"Apoint"=D:\Program Files\DellTPad\Apoint.exe [2010-01-18 274432]
"NokiaMServer"=D:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles []
"VirtualCloneDrive"=D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-05-27 85160]
"SiemensAutomationFileStorage"=D:\Program Files\Siemens\Automation\Portal V10\Bin\Siemens.Automation.ObjectFrame.FileStorage.Server.exe [2009-11-17 364544]
"Dell QuickSet"=C:\Program Files\Dell\QuickSet\quickset.exe [2008-11-14 1708032]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2011-03-02 149280]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-04-21 281768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ICQ"=D:\Program Files\ICQ7.5\ICQ.exe [2011-06-16 124216]
D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Bluetooth.lnk - D:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - D:\Windows\System32\Notepad.exe %1
.js - open - D:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2011-06-22 22:07:23 ----A---- D:\Windows\system32\drivers\ssmdrv.sys
2011-06-22 22:07:21 ----A---- D:\Windows\system32\drivers\avipbb.sys
2011-06-22 22:07:21 ----A---- D:\Windows\system32\drivers\avgntflt.sys
2011-06-22 22:07:20 ----D---- D:\ProgramData\Avira
2011-06-22 22:07:20 ----D---- D:\Program Files\Avira
2011-06-21 21:43:12 ----D---- D:\Program Files\trend micro
2011-06-21 21:43:11 ----D---- D:\rsit
2011-06-21 19:56:34 ----A---- D:\Windows\system32\wininet.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\wextract.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\webcheck.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\vbscript.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\urlmon.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\url.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\SetIEInstalledDate.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\RegisterIEPKEYs.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\pngfilt.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\occache.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msrating.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msls31.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtmler.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtmled.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshtml.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\mshta.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeedssync.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeedsbs.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\msfeeds.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\licmgr10.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jsproxy.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jscript9.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\jscript.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\inseng.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\imgutil.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iexpress.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieUnatt.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieui.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iesysprep.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iesetup.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iertutil.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iernonce.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iepeers.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieframe.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\iedkcs32.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieapfltr.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieakui.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieaksie.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ieakeng.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\IEAdvpack.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\ie4uinit.exe
2011-06-21 19:56:34 ----A---- D:\Windows\system32\icardie.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\dxtrans.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\dxtmsft.dll
2011-06-21 19:56:34 ----A---- D:\Windows\system32\admparse.dll
2011-06-21 19:24:37 ----A---- D:\Windows\system32\poqexec.exe
2011-06-21 19:24:32 ----A---- D:\Windows\system32\prevhost.exe
2011-06-20 20:52:13 ----SHD---- D:\Config.Msi
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb20.sys
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb10.sys
2011-06-20 20:45:28 ----A---- D:\Windows\system32\drivers\mrxsmb.sys
2011-06-20 20:45:26 ----A---- D:\Windows\system32\XpsGdiConverter.dll
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srvnet.sys
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srv2.sys
2011-06-20 20:45:02 ----A---- D:\Windows\system32\drivers\srv.sys
2011-06-20 20:44:51 ----A---- D:\Windows\system32\dnsrslvr.dll
2011-06-20 20:44:51 ----A---- D:\Windows\system32\dnsapi.dll
2011-06-20 20:44:50 ----A---- D:\Windows\system32\dnscacheugc.exe
2011-06-20 20:44:46 ----A---- D:\Windows\system32\drivers\tcpip.sys
2011-06-20 20:44:45 ----A---- D:\Windows\system32\drivers\afd.sys
2011-06-20 20:44:44 ----A---- D:\Windows\system32\inetcomm.dll
2011-06-20 20:44:42 ----A---- D:\Windows\system32\oleaut32.dll
2011-06-20 20:44:40 ----A---- D:\Windows\system32\atmlib.dll
2011-06-20 20:44:40 ----A---- D:\Windows\system32\atmfd.dll
2011-06-20 20:44:39 ----A---- D:\Windows\system32\win32k.sys
2011-06-20 20:44:35 ----A---- D:\Windows\explorer.exe
2011-06-20 20:44:34 ----A---- D:\Windows\system32\FXSCOVER.exe
2011-06-20 20:44:32 ----A---- D:\Windows\system32\XpsPrint.dll
2011-06-20 20:44:31 ----A---- D:\Windows\system32\mfc42.dll
2011-06-20 20:44:30 ----A---- D:\Windows\system32\mfc42u.dll
2011-06-20 20:44:23 ----A---- D:\Windows\system32\ntkrnlpa.exe
2011-06-20 20:44:22 ----A---- D:\Windows\system32\ntoskrnl.exe
2011-06-20 20:44:10 ----A---- D:\Windows\system32\drivers\bowser.sys
2011-06-20 20:43:57 ----A---- D:\Windows\system32\d3d10_1.dll
2011-06-20 20:42:25 ----A---- D:\Windows\system32\drivers\Diskdump.sys
2011-06-20 19:10:09 ----D---- D:\ProgramData\bD42900LoEhE42900
2011-06-20 19:09:07 ----D---- D:\Windows\Sun
2011-06-19 19:35:39 ----D---- D:\ProgramData\tmp
2011-06-19 19:35:38 ----D---- D:\ProgramData\hps
2011-06-19 15:25:50 ----D---- D:\Program Files\Schlecker
2011-06-16 20:22:15 ----D---- D:\Users\Petra\AppData\Roaming\Mozilla
2011-06-16 20:22:04 ----D---- D:\Users\Petra\AppData\Roaming\ICQ
2011-06-16 20:21:56 ----D---- D:\Program Files\ICQ7.5
2011-06-07 21:25:56 ----D---- D:\Program Files\Pokluda
2011-05-25 20:47:51 ----A---- D:\Windows\NeroDigital.ini
2011-05-25 20:47:36 ----D---- D:\Users\Petra\AppData\Roaming\Nero
2011-05-25 20:05:34 ----D---- D:\Users\Petra\AppData\Roaming\Macromedia
2011-05-25 20:04:44 ----D---- D:\Users\Petra\AppData\Roaming\Adobe
2011-05-25 19:59:31 ----D---- D:\Program Files\SMART Technologies Inc
2011-05-25 19:59:23 ----D---- D:\Program Files\Slovíčka 2.0
2011-05-25 19:58:29 ----D---- D:\Program Files\LINGUA
2011-05-25 19:58:21 ----D---- D:\Program Files\Fraus
2011-05-25 19:46:59 ----D---- D:\Users\Petra\AppData\Roaming\ESET
2011-05-25 19:46:54 ----D---- D:\Users\Petra\AppData\Roaming\ATI
2011-05-25 19:45:42 ----D---- D:\Users\Petra\AppData\Roaming\Identities
2011-05-25 19:45:23 ----SD---- D:\Users\Petra\AppData\Roaming\Microsoft
2011-05-25 19:45:23 ----D---- D:\Users\Petra\AppData\Roaming\Media Center Programs
======List of files/folders modified in the last 1 months======
2011-06-22 22:20:38 ----D---- D:\Windows\Temp
2011-06-22 22:19:32 ----D---- D:\Windows\System32
2011-06-22 22:19:32 ----D---- D:\Windows\inf
2011-06-22 22:19:32 ----A---- D:\Windows\system32\PerfStringBackup.INI
2011-06-22 22:17:28 ----D---- D:\Windows\system32\config
2011-06-22 22:15:04 ----D---- D:\Windows\Prefetch
2011-06-22 22:07:23 ----D---- D:\Windows\system32\drivers
2011-06-22 22:07:20 ----RD---- D:\Program Files
2011-06-22 22:07:20 ----HD---- D:\ProgramData
2011-06-22 21:59:30 ----SHD---- D:\Windows\Installer
2011-06-22 21:58:48 ----D---- D:\Windows\system32\DriverStore
2011-06-22 21:58:48 ----D---- D:\Windows\system32\catroot
2011-06-21 21:01:01 ----D---- D:\Windows\Microsoft.NET
2011-06-21 21:01:00 ----RSD---- D:\Windows\assembly
2011-06-21 20:13:39 ----D---- D:\Windows\winsxs
2011-06-21 20:11:46 ----D---- D:\Windows\system32\sk-SK
2011-06-21 20:11:46 ----D---- D:\Program Files\Internet Explorer
2011-06-21 20:11:45 ----D---- D:\Windows\system32\migration
2011-06-21 20:11:45 ----D---- D:\Windows\system32\cs-CZ
2011-06-21 20:11:45 ----D---- D:\Windows\PolicyDefinitions
2011-06-21 20:11:44 ----D---- D:\Windows\system32\en-US
2011-06-21 20:11:44 ----D---- D:\Windows\AppPatch
2011-06-21 19:57:37 ----D---- D:\Windows\Logs
2011-06-21 19:57:23 ----D---- D:\Windows\system32\catroot2
2011-06-21 19:35:40 ----D---- D:\Windows
2011-06-21 19:25:59 ----SHD---- D:\System Volume Information
2011-06-21 07:23:20 ----D---- D:\Program Files\Microsoft Silverlight
2011-06-20 20:24:36 ----D---- D:\Program Files\ICQ6Toolbar
2011-06-16 20:22:15 ----HD---- D:\Program Files\InstallShield Installation Information
2011-06-16 20:22:14 ----D---- D:\ProgramData\ICQ
2011-06-13 20:31:42 ----A---- D:\Windows\ODBC.INI
2011-06-12 14:59:01 ----D---- D:\Windows\system32\NDF
2011-06-07 21:16:21 ----D---- D:\Program Files\Moje slovíčka
2011-06-03 17:56:44 ----A---- D:\Windows\system32\MRT.exe
2011-05-25 19:45:39 ----SHD---- D:\$Recycle.Bin
2011-05-25 19:45:21 ----RD---- D:\Users
2011-05-24 19:14:10 ----N---- D:\Windows\system32\MpSigStub.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; D:\Windows\system32\DRIVERS\iaStor.sys [2009-06-04 330264]
R0 rdyboost;ReadyBoost; D:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; D:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 avipbb;avipbb; D:\Windows\system32\DRIVERS\avipbb.sys [2011-06-17 137656]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; D:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ElbyCDIO;ElbyCDIO Driver; D:\Windows\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 ssmdrv;ssmdrv; D:\Windows\system32\DRIVERS\ssmdrv.sys [2010-06-17 28520]
R1 truecrypt;truecrypt; D:\Windows\System32\drivers\truecrypt.sys [2010-03-17 223440]
R1 vwififlt;Virtual WiFi Filter Driver; D:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 avgntflt;avgntflt; D:\Windows\system32\DRIVERS\avgntflt.sys [2011-06-17 61960]
R2 S7opcsrtx;PROFINET IO RT-Protocol (LLDP); D:\Windows\system32\DRIVERS\s7opcsrtx.sys [2009-06-30 31232]
R2 s7snsrtx;PROFINET IO RT-Protocol V1.0; D:\Windows\system32\DRIVERS\s7snsrtx.sys [2009-02-24 73088]
R2 SNTIE;SIMATIC Industrial Ethernet (ISO); D:\Windows\system32\DRIVERS\sntie.sys [2009-06-05 311424]
R2 WinDriver;WinDriver; D:\Windows\System32\drivers\WINDRVR.SYS [2007-10-04 205220]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows x86; D:\Windows\system32\DRIVERS\Apfiltr.sys [2009-12-26 237104]
R3 atikmdag;atikmdag; D:\Windows\system32\DRIVERS\atikmdag.sys [2009-06-25 4993536]
R3 BCM42RLY;BCM42RLY; D:\Windows\system32\drivers\BCM42RLY.sys [2009-07-17 18424]
R3 BCM43XX;Ovladač bezdrátové karty Dell WLAN; D:\Windows\system32\DRIVERS\bcmwl6.sys [2009-07-17 2506232]
R3 BthEnum;Ovladač pro Bluetooth Request Block; D:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); D:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; D:\Windows\System32\Drivers\BTHUSB.sys [2010-11-20 60416]
R3 btwaudio;Bluetooth Audio Device Service; D:\Windows\system32\drivers\btwaudio.sys [2009-07-21 86056]
R3 btwavdt;Bluetooth AVDT Service; D:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-21 108072]
R3 btwl2cap;Bluetooth L2CAP Service; D:\Windows\system32\DRIVERS\btwl2cap.sys [2009-07-21 29472]
R3 btwrchid;btwrchid; D:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-21 18344]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); D:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; D:\Windows\System32\Drivers\RtsUStor.sys [2009-05-08 165888]
R3 STHDA;IDT High Definition Audio CODEC; D:\Windows\system32\DRIVERS\stwrt.sys [2009-11-07 420864]
R3 VClone;VClone; D:\Windows\system32\DRIVERS\VClone.sys [2009-05-23 29696]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; D:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336]
R3 WinDriver6;WinDriver6; D:\Windows\system32\drivers\windrvr6.sys [2007-10-04 166912]
S2 eamonm;eamonm; D:\Windows\system32\DRIVERS\eamonm.sys []
S2 MLPTDR_N;MLPTDR_N; \??\D:\Windows\system32\MLPTDR_N.sys [2003-07-19 18848]
S2 Parvdm;Parvdm; D:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; D:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; D:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; D:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; D:\Windows\System32\Drivers\BTHport.sys [2010-11-20 393216]
S3 fssfltr;FssFltr; D:\Windows\system32\DRIVERS\fssfltr.sys [2009-08-05 54632]
S3 FTDIBUS;USB Serial Converter Driver; D:\Windows\system32\drivers\ftdibus.sys [2010-07-12 60104]
S3 FTSER2K;USB Serial Port Driver; D:\Windows\system32\drivers\ftser2k.sys [2010-07-12 73032]
S3 jusb;jusb; D:\Windows\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 nmwcd;Nokia USB Phone Parent; D:\Windows\system32\drivers\ccdcmb.sys [2009-02-09 17664]
S3 nmwcdc;Nokia USB Generic; D:\Windows\system32\drivers\ccdcmbo.sys [2009-02-09 22016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; D:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; D:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; D:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; D:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 RtsUIR;Realtek IR Driver; D:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 s3cap;s3cap; D:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; D:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 StarOpen;StarOpen; D:\Windows\system32\drivers\StarOpen.sys []
S3 storvsc;storvsc; D:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 Synth3dVsc;Synth3dVsc; D:\Windows\System32\drivers\synth3dvsc.sys []
S3 TsUsbFlt;TsUsbFlt; D:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; D:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; D:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2009-02-09 7808]
S3 USBCCID;Realtek Smartcard Reader Driver; D:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbser;Sony Ericsson USB Serial Port; D:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; D:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-02-09 7808]
S3 VGPU;VGPU; D:\Windows\System32\drivers\rdvgkmd.sys []
S3 viaagp;Filtr VIA sběrnice AGP; D:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; D:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; D:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]
S3 WinUsb;WinUsb; D:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\aestsrv.exe [2009-03-03 81920]
R2 almservice;Automation License Manager Service; D:\Program Files\Common Files\Siemens\sws\almsrv\almsrvx.exe [2009-04-23 1200128]
R2 AMD External Events Utility;AMD External Events Utility; D:\Windows\system32\atiesrxx.exe [2009-06-25 176128]
R2 AntiVirService;Avira AntiVir Guard; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-04-21 269480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-21 136360]
R2 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 582944]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; D:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; D:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-04 354840]
R2 ICQ Service;ICQ Service; D:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-11-21 247608]
R2 MSSQL$WINCCPLUS;SQL Server (WINCCPLUS); d:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; D:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
R2 s7oiehsx;SIMATIC IEPG Help Service; D:\Program Files\Common Files\Siemens\S7IEPG\s7oiehsx.exe [2009-06-30 1576072]
R2 S7TraceServiceX;S7TraceServiceX; D:\Program Files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe [2009-06-30 240776]
R2 SQLBrowser;SQL Server Browser; d:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-12-10 238944]
R2 SQLWriter;SQL Server VSS Writer; d:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-12-10 86880]
R2 STacSV;Audio Service; D:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_c1f21f27f4c2b301\STacSV.exe [2009-11-07 229458]
R2 wlidsvc;Windows Live ID Sign-in Assistant; D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 wltrysvc;Dell Wireless WLAN Tray Service; D:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE [2009-07-17 26112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; D:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 FLEXlm License Manager;FLEXlm License Manager; D:\SEFlex\Program\lmgrd.exe [2009-08-01 1431440]
S2 gupdate;Služba Google Update (gupdate); D:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
S3 AppMgmt;@appmgmts.dll,-3250; D:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 fsssvc;Služba Windows Live Zabezpečení rodiny; D:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 OpcEnum;OpcEnum; D:\Windows\system32\OpcEnum.exe [2007-04-17 135168]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 ServiceLayer;ServiceLayer; D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; D:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-02-10 150528]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; D:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; d:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2010-12-10 44384]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.08 2011-06-22 22:22:07
======Uninstall list======
7-Zip 4.65-->"D:\Program Files\7-Zip\Uninstall.exe"
Activation (Nero 9 HD)-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="5EA0-EM11-98K2-380M-MX8X-AXC9-20AA"
Adobe Flash Player 10 ActiveX-->D:\Windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe -maintain activex
Adobe Photoshop 7.0 CE-->D:\WINDOWS\ISUN0405.EXE -f"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.isu" -c"D:\Program Files\Adobe\Photoshop 7.0 CE\Uninst.dll"
Avanquest update-->"D:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
Avira AntiVir Personal - Free Antivirus-->D:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->D:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u D:\Windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.inf
Blu-ray Disc Authoring Plug-in-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M13-0083-2710-5622-98W3-TL0A-THW4-9A0T"
Catalyst Control Center - Branding-->MsiExec.exe /I{69533745-1E2D-4C98-8B4A-B7643EF9E1A2}
CDA to MP3 Converter v2.8 build 839-->"D:\Program Files\HooTech CDA to MP3 Converter\unins000.exe"
CDBurnerXP-->MsiExec.exe /X{5932A5C4-BB44-4CFB-AD66-1B826F4D788B}
Cisco EAP-FAST Module-->MsiExec.exe /I{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}
Cisco LEAP Module-->MsiExec.exe /I{51C7AD07-C3F6-4635-8E8A-231306D810FE}
Cisco PEAP Module-->MsiExec.exe /I{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}
CodeWarrior Development Studio for Freescale Digital Signal Controllers, Version 8.2.3-->MsiExec.exe /I{7C816C26-FDB7-4AE5-9816-47E55CBBB564}
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Dell Touchpad-->D:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
Dell Wireless WLAN Card Utility-->"D:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Dell\Dell Wireless WLAN Card"
EAGLE 5.11.0-->cmd.exe /c start "EAGLE Uninstaller" /min "D:\Program Files\EAGLE-5.11.0\bin\uninstall.bat" D:\Program Files\EAGLE-5.11.0\bin
FLIP 2.4.6-->D:\Windows\IsUninst.exe -f"D:\Program Files\ATMEL\FLIP 2.4.6\Uninst.isu"
Flip 3.3.4-->D:\Program Files\Atmel\Flip 3.3.4\uninstall.exe
FOTOSVET Schlecker 3-->"D:\Program Files\Schlecker\FOTOSVET Schlecker 3\uninstall.exe"
Foxit Reader-->D:\Program Files\Foxit Software\Foxit Reader\Uninstall.exe
Google Earth-->MsiExec.exe /X{4286E640-B5FB-11DF-AC4B-005056C00008}
Google Chrome-->"D:\Program Files\Google\Chrome\Application\12.0.742.100\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
ICQ Toolbar-->D:\Program Files\ICQ6Toolbar\ICQUnToolbar.exe
ICQ7.5-->"D:\Program Files\InstallShield Installation Information\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}\ICQ7.exe" -runfromtemp -l0x0009 -removeonly
IDT Audio-->"D:\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe" -remove -removeonly
Intel® Matrix Storage Manager-->D:\Program Files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe -uninstall
JabloTool-->"D:\Windows\JabloTool Uninstaller.exe"
Java(TM) 6 Update 15-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216015FF}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Keil µVision3-->D:\Keil\Uninstall.exe
KONICA MINOLTA PagePro 1300W-->MUINST_N.EXE /PRN:"KONICA MINOLTA PagePro 1300W"
Marvell Miniport Driver-->D:\Program Files\Marvell\Miniport Driver\Uninst.exe
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->D:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office Live Add-in 1.5-->MsiExec.exe /I{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}
Microsoft Office XP Professional s aplikací FrontPage-->MsiExec.exe /I{90280405-6000-11D3-8CFE-0050048383C9}
Microsoft Primary Interoperability Assemblies 2005-->MsiExec.exe /X{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SOAP Toolkit 3.0-->MsiExec.exe /I{BCB4C18A-ACA6-4383-8688-E19933A705DD}
Microsoft SQL Server 2005 Backward compatibility-->MsiExec.exe /I{0D61D68B-DF5E-4635-82C7-B0C53F0A581B}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server 2005 Express Edition (WINCCPLUS)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005-->"d:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Native Client-->MsiExec.exe /I{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}
Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{E7084B89-69E0-46B3-A118-8F99D06988CD}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{6AFCA4E1-9B78-3640-8F72-A7BF33448200}
Moje slovíčka 1.3-->"D:\Program Files\Moje slovíčka\unins000.exe"
Mozilla Thunderbird (3.1.7)-->D:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nástroj pro odesílání služby Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Nero 9-->D:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER="9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A"
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
nLite 1.4.9.1-->"D:\Program Files\nLite\unins000.exe"
Nokia Connectivity Cable Driver-->MsiExec.exe /I{82427977-8776-4087-90CA-9F65174D3C4D}
Nokia Flashing Cable Driver-->MsiExec.exe /X{A4E0CA0F-1903-440A-9B98-FEA6CB049999}
Nokia Ovi Application Installer 6.85.3011-->msiexec /qn /x {42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Application Installer-->MsiExec.exe /I{42B74521-4706-412A-9A27-AED12B83E886}
Nokia Ovi Content Copier 6.85.3011-->msiexec /qn /x {6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi Content Copier-->MsiExec.exe /X{6442DEDF-AC2F-4CBA-85DE-42E459C5006C}
Nokia Ovi One Touch Access 6.85.3011-->msiexec /qn /x {4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi One Touch Access-->MsiExec.exe /I{4AE48A64-6C6A-4E5A-95FA-55F5131DECF9}
Nokia Ovi Suite-->MsiExec.exe /I{B5264B25-8908-49BB-A708-5A70DFBF8094}
Nokia Ovi System Utilities 6.85.3016-->msiexec /qn /x {FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Ovi System Utilities-->MsiExec.exe /X{FF34EA62-92C1-41E6-BA64-B2B7ECB53737}
Nokia Software Updater-->MsiExec.exe /X{2FA28330-2028-4033-BD10-425C87EB4D54}
Nvu 1.0-->D:\Program Files\Nvu\uninst.exe
OPC Core Components Redistributable-->MsiExec.exe /I{75F9DAD1-792C-44E9-B48B-2E22C76E0CBF}
PC Connectivity Solution-->MsiExec.exe /I{B7CB0BF3-791E-44D3-9F04-786E36D51C9D}
PDFCreator-->D:\Program Files\PDFCreator\unins000.exe
Pomocník pro přihlášení ke službě Windows Live ID-->MsiExec.exe /X{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}
Prosave V7.4 incl. SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
Prosave V7.4 SP4 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {9B9856F7-FB16-4EDF-81FF-6382D0733D8F}
QuickSet32-->MsiExec.exe /I{C4972073-2BFE-475D-8441-564EA97DA161}
Realtek USB 2.0 Card Reader-->"D:\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe" -runfromtemp -l0x0005 -removeonly
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {3E0806DB-3085-378A-840A-F0D3AE3609D1} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->d:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Siemens Totally Integrated Automation Portal V10-->D:\Program Files\Common Files\Siemens\Automation\Siemens Totally Integrated Automation Portal V10\SIA.exe /arpmode
Siemens Automation License Manager V4.0 + SP3 -->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Siemens Automation License Manager-->D:\Program Files\Common Files\Siemens\Bin\setupdeinstaller.exe /x {31BCC2ED-3E12-4A23-8899-6C89C208B8CE}
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
Slovnik verze 3.5-->"D:\Program Files\Pokluda\Slovnik\unins000.exe"
Software Bluetooth WIDCOMM-->MsiExec.exe /X{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}
Solid Edge License Manager-->MsiExec.exe /X{531C1B44-611D-4909-B35E-34A11C40163E}
Solid Edge ST2-->MsiExec.exe /X{CC185D10-5C0E-40C3-91F2-63314BB365AF}
Sony Ericsson PC Companion 2.01.148-->"D:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
TIA Portal Single SetupPackage - HW Module Base Package V10.5 + HF1-->MsiExec.exe /X{F1D4FDEE-BB94-4C17-8BB0-AC06DAF854BD}
TIA Portal Single SetupPackage - HWConfig Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{047BC977-015A-4339-B571-44CA33901F63}
TIA Portal Single SetupPackage - S7BASUCL V10.5 + SP12-->MsiExec.exe /X{37F822E3-B56D-4131-8E3D-0A6753DFB8A5}
TIA Portal Single SetupPackage - STEP 7 Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{DC62C484-A0B2-421A-9A0F-1ABFE1E10D71}
TIA Portal Single SetupPackage - WinCC Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{3EB30640-F847-4F59-AF74-837D0FD02B73}
TIA Portal Single SetupPackage - WINCCBASUCL V10.5 + SP12-->MsiExec.exe /X{ABE2EE7E-11F7-4374-B86B-CB75A5F276B0}
Total Commander (Remove or Repair)-->d:\totalcmd\tcuninst.exe
Totally Integrated Automation Portal V10 - TIA Portal Single SetupPackage V10.5 + SP2-->MsiExec.exe /X{31C1839C-7967-469C-921D-0BEB49AC0652}
TrueCrypt-->"D:\Program Files\TrueCrypt\TrueCrypt Setup.exe" /u
VC User 71 RTL X86 ----->MsiExec.exe /I{A4A4567C-5C29-4756-992D-F84D8250C435}
VirtualCloneDrive-->"D:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="D:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
Windows Live Essentials-->D:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{E3F328E4-EB9F-4ABF-8FF3-5AD0472743D8}
Windows Live Fotogalerie-->MsiExec.exe /X{1D097338-B4FA-4F29-9C43-8D7A970A007E}
Windows Live Mail-->MsiExec.exe /I{E5A10EF8-DBF3-4251-A9CA-423311DBBFC8}
Windows Live Sync-->MsiExec.exe /X{068B46A0-8858-4CEB-80BC-A4AE787A05FC}
Windows Live Zabezpečení rodiny-->MsiExec.exe /X{F86AD773-5BC0-499B-9F48-4E0D5FED759D}
======System event log======
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Distributed Link Tracking Client byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Security Center byl změněn na: stopped
Record Number: 4
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Desktop Window Manager Session Manager byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Diagnostic Policy Service byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 7036
Message: Stav služby Microsoft Software Shadow Copy Provider byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20090714045645.074339-000
Event Type: Informace
User:
=====Application event log=====
Computer Name: 37L4247D28-05
Event Code: 900
Message: Služba Ochrana softwaru se spouští.
Record Number: 5
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20100316192712.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192513.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20100316192509.000000-000
Event Type: Informace
User:
Computer Name: 37L4247D28-05
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100316192505.750502-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: 37L4247D28-05
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20100316192505.000000-000
Event Type: Informace
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: Byla změněna zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Změněné atributy:
Název účtu SAM: -
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.246055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: Byla vytvořena zabezpečená místní skupina.
Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247D28-05$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7
Nová skupina:
ID zabezpečení: S-1-5-32-551
Název skupiny: Backup Operators
Doména skupiny: Builtin
Atributy:
Název účtu SAM: Backup Operators
Historie identifikátoru zabezpečení: -
Další informace:
Oprávnění: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192439.230455-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.
Počet prvků: 0
ID zásady: 0x27072
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192438.934055-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: Účet byl úspěšně přihlášen.
Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0
Typ přihlášení: 0
Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}
Informace o procesu:
ID procesu: 0x4
Název procesu:
Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -
Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0
Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.
Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.
Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).
Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.
Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.
Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.578451-000
Event Type: Úspěšný audit
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Spouští se systém Windows.
Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100316192436.484850-000
Event Type: Úspěšný audit
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;D:\Program Files\Nokia\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;D:\Program Files\ATI Technologies\ATI.ACE\Core-Static;D:\Program Files\Dell\Dell Wireless WLAN Card;D:\Program Files\WIDCOMM\Bluetooth Software\;d:\Program Files\Microsoft SQL Server\90\Tools\binn\;D:\Program Files\Microsoft SQL Server\80\Tools\Binn\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
"AutInstLog"=D:\ProgramData\Siemens\Automation\Logfiles\Setup\
"P_SCHEMA"=D:\Program Files\Solid Edge ST2\Schema
"LM_LICENSE_FILE"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\license.dat
"MW56800ELibraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MW56800ELibraryFiles"=Runtime 56800E.Lib;MSL C 56800E.lib
"MW56800Libraries"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MW56800LibraryFiles"=FP56800.lib;MSL C 56800.Lib
"MWAsm56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
"MWAsm56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800Includes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800 Support
"MWC56800EIncludes"=D:\Program Files\Freescale\CodeWarrior for DSC56800E v8.2.3\M56800E Support
-----------------EOF-----------------
CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----
Re: Kryptik.PHU

- Provedte aktualizaci - treti zalozka
- Provedte uplny sken - nic nemazte
- MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
Re: Kryptik.PHU
zdravim. Prikladam pozadovany log. Vypada to dobre.
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Verze databáze: 6926
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
23.6.2011 19:45:20
mbam-log-2011-06-23 (19-45-03).txt
Typ: Úplná kontrola (C:\|D:\|E:\|)
Kontrolované objekty: 509220
Uplynulý čas: 2 hodin, 25 minut, 52 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Verze databáze: 6926
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
23.6.2011 19:45:20
mbam-log-2011-06-23 (19-45-03).txt
Typ: Úplná kontrola (C:\|D:\|E:\|)
Kontrolované objekty: 509220
Uplynulý čas: 2 hodin, 25 minut, 52 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Re: Kryptik.PHU
Odinstalujte ICQ6Toolbar a vypada to, ze mame cisto 

Re: Kryptik.PHU
Mockrat dekuji za pomoc! Jste opravdu vyborny web!
Re: Kryptik.PHU
Nemate zac, rado se stalo 
