Spomaleny pc na kratku dobu
Napsal: 13 srp 2011 01:00
Dobry den potreboval by som pomoct trosku precistit pc ono asi cca kazdu hodinu mi z nicoho nic zacne pracovat HDD aj ked nic nerobim a ked napr hram hru tak vsetko zacne sekat a po 5-10 min je to ok ... pripisujem to najskor asi nejakej tejto havedi
Prikladam log z RSIT
Logfile of random's system information tool 1.09 (written by random/random)
Run by kolik at 2011-08-13 01:51:06
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (42%) free of 89 GB
Total RAM: 2047 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:52:03, on 13.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\kolik\Start Menu\Programs\Startup\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\opera.exe
C:\DOCUME~1\kolik\LOCALS~1\Temp\wcyhbk.exe
C:\Program Files\BitTorrent\BitTorrent.exe
D:\antivir\RSIT.exe
C:\Program Files\trend micro\kolik.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ctfmon.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 3309 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\kolik\Application Data\Mozilla\Firefox\Profiles\pr5444hy.default
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, toolbar@ask.com:3.12.2.100006, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat
C:\Program Files\Mozilla Firefox\plugins\
nplv90win32.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\kolik\Application Data\Mozilla\Firefox\Profiles\pr5444hy.default\extensions\
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
C:\Documents and Settings\kolik\Application Data\Mozilla\Firefox\Profiles\pr5444hy.default\searchplugins\
icqplugin.xml
qip-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-03 172032]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-12-14 651264]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2010-11-03 2815592]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\kolik\Start Menu\Programs\Startup
ctfmon.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-03-03 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:ipsec"
"C:\Documents and Settings\kolik\Desktop\warcraft-panfazole\Warcraft III + FT + eurobattle.net + dota ( 4.2.2010 )\Warcraft III.exe"="C:\Documents and Settings\kolik\Desktop\warcraft-panfazole\Warcraft III + FT + eurobattle.net + dota ( 4.2.2010 )\Warcraft III.exe:*:Enabled:Warcraft III"
"D:\stary disk\WARCRAFT 33333\w33\ warcraft\Warcraft III.exe"="D:\stary disk\WARCRAFT 33333\w33\ warcraft\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Documents and Settings\kolik\Desktop\nub slozka\Ranked Gaming Client\rgc.exe"="C:\Documents and Settings\kolik\Desktop\nub slozka\Ranked Gaming Client\rgc.exe:*:Enabled:rgc"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"C:\Program Files\BitTorrent\BitTorrent.exe"="C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\National Instruments\DIAdem 2010\DIAdem.exe"="C:\Program Files\National Instruments\DIAdem 2010\DIAdem.exe:*:Enabled:DIAdem 2010"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\National Instruments\Shared\DataFinderDesktop\bin\DataFinder.exe"="C:\Program Files\National Instruments\Shared\DataFinderDesktop\bin\DataFinder.exe:*:Disabled:DataFinder"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe"="C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh"
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe"="C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"F:\bfybt.exe"="F:\bfybt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winfqfy.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winfqfy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\dtsk.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\dtsk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ldje.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ldje.exe:*:Enabled:ipsec"
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\svchost.exe"="C:\WINDOWS\system32\svchost.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winocjis.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winocjis.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\xllt.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\xllt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winkkgux.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winkkgux.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\nltv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\nltv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\mbqp.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\mbqp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingptt.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingptt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wincocv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wincocv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\pqnd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\pqnd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winerfqug.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winerfqug.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winubmfg.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winubmfg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\vttlx.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\vttlx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhvwd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhvwd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqtfe.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqtfe.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ymkha.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ymkha.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqnst.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqnst.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\jmepoo.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\jmepoo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\xqkfd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\xqkfd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\sqsmdh.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\sqsmdh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\mjtn.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\mjtn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\scwnqb.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\scwnqb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winokno.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winokno.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\plgp.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\plgp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winbmrie.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winbmrie.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\jqtqm.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\jqtqm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winpfpw.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winpfpw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winmrwdf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winmrwdf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winxnclvj.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winxnclvj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winttqgxu.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winttqgxu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winbpss.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winbpss.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingnjvf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingnjvf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\kopor.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\kopor.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winyobm.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winyobm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\emwlcm.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\emwlcm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrmwtf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrmwtf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ksvrxg.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ksvrxg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\hmuoh.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\hmuoh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqkonof.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqkonof.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingmhiby.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingmhiby.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winrnsskv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winrnsskv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhxja.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhxja.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\yinxo.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\yinxo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqcvoa.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqcvoa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\bngl.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\bngl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrguur.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrguur.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winixstky.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winixstky.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\nkvhci.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\nkvhci.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winkqlqr.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winkqlqr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\vvpve.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\vvpve.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\pltw.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\pltw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\tycv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\tycv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ngvjo.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ngvjo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\xdvhsk.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\xdvhsk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winuixxu.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winuixxu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\euxb.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\euxb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winkpoi.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winkpoi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\csli.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\csli.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winmxxoty.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winmxxoty.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhcrckh.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhcrckh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winehru.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winehru.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winvefl.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winvefl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ndpcbf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ndpcbf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winivyyi.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winivyyi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\rkyye.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\rkyye.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ltate.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ltate.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winxota.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winxota.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winxhrd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winxhrd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\asuu.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\asuu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhaigq.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhaigq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\fndsk.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\fndsk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winatmox.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winatmox.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winbcjij.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winbcjij.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\windaidp.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\windaidp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingwxqb.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingwxqb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ogosg.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ogosg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winjndkc.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winjndkc.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe"="C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh"
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe"="C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"vidc.XVID"=xvidvfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-08-13 01:51:06 ----D---- C:\rsit
2011-08-13 01:51:06 ----D---- C:\Program Files\trend micro
2011-08-13 01:15:27 ----D---- C:\WINDOWS\system32\NtmsData
2011-08-13 00:36:00 ----D---- C:\WINDOWS\SxsCaPendDel
2011-08-13 00:29:36 ----SHD---- C:\Config.Msi
2011-08-13 00:23:22 ----D---- C:\WINDOWS\system32\appmgmt
2011-08-13 00:22:04 ----A---- C:\WINDOWS\Eurobattle.net Uninstall Log.txt
======List of files/folders modified in the last 1 month======
2011-08-13 01:51:58 ----D---- C:\Documents and Settings\kolik\Application Data\BitTorrent
2011-08-13 01:51:13 ----D---- C:\WINDOWS\Prefetch
2011-08-13 01:51:06 ----RD---- C:\Program Files
2011-08-13 01:15:27 ----D---- C:\WINDOWS\system32
2011-08-13 00:45:46 ----D---- C:\WINDOWS\system32\drivers
2011-08-13 00:44:31 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-13 00:43:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-13 00:37:02 ----SHD---- C:\WINDOWS\Installer
2011-08-13 00:37:02 ----D---- C:\Program Files\Common Files
2011-08-13 00:36:46 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-13 00:36:18 ----RSD---- C:\WINDOWS\assembly
2011-08-13 00:36:16 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2011-08-13 00:36:01 ----D---- C:\WINDOWS\WinSxS
2011-08-13 00:36:00 ----D---- C:\WINDOWS
2011-08-13 00:35:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-08-13 00:25:11 ----SD---- C:\WINDOWS\Tasks
2011-08-13 00:24:24 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-13 00:24:24 ----D---- C:\Program Files\Ubi Soft
2011-08-13 00:23:51 ----D---- C:\Program Files\Mozilla Firefox
2011-08-13 00:23:35 ----D---- C:\Documents and Settings\kolik\Application Data\Skype
2011-08-13 00:22:08 ----D---- C:\Program Files\Warcraft III
2011-08-12 22:28:14 ----D---- C:\Program Files\Opera
2011-08-12 13:52:05 ----D---- C:\Program Files\Heroes of Newerth
2011-08-06 09:11:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2003-10-28 20016]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2002-03-11 436792]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 cvintdrv;cvintdrv; C:\WINDOWS\system32\drivers\cvintdrv.sys [2008-04-07 4096]
R3 amsint32;amsint32; \??\C:\WINDOWS\system32\drivers\pkhqn.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-03-03 4630016]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-11-30 6261352]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-04-14 94592]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 at6saa36;at6saa36; C:\WINDOWS\system32\drivers\at6saa36.sys []
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\kolik\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-14 20992]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-03-03 602112]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 LkCitadelServer;Lookout Citadel Server; C:\WINDOWS\system32\lkcitdl.exe [2009-09-29 695136]
R2 lkClassAds;National Instruments PSP Server Locator; C:\WINDOWS\system32\lkads.exe [2010-03-10 43056]
R2 lkTimeSync;National Instruments Time Synchronization; C:\WINDOWS\system32\lktsrv.exe [2010-03-10 53808]
R2 NIDomainService;National Instruments Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2010-03-10 358448]
R2 niSvcLoc;NI Service Locator; C:\WINDOWS\system32\nisvcloc.exe [2009-10-20 13896]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 135456]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NILM License Manager;NILM License Manager; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2009-09-18 1077248]
-----------------EOF-----------------
Prikladam log z RSIT
Logfile of random's system information tool 1.09 (written by random/random)
Run by kolik at 2011-08-13 01:51:06
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 37 GB (42%) free of 89 GB
Total RAM: 2047 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:52:03, on 13.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\kolik\Start Menu\Programs\Startup\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\opera.exe
C:\DOCUME~1\kolik\LOCALS~1\Temp\wcyhbk.exe
C:\Program Files\BitTorrent\BitTorrent.exe
D:\antivir\RSIT.exe
C:\Program Files\trend micro\kolik.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ctfmon.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 3309 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\kolik\Application Data\Mozilla\Firefox\Profiles\pr5444hy.default
prefs.js - "browser.startup.homepage" - "http://start.icq.com/"
prefs.js - "extensions.enabledItems" - "{32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.9, toolbar@ask.com:3.12.2.100006, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.12"
prefs.js - "keyword.URL" - "http://search.icq.com/search/afe_result ... r=1.1.9&q="
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat
C:\Program Files\Mozilla Firefox\plugins\
nplv90win32.dll
npnul32.dll
NPOFF12.DLL
nppdf32.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\kolik\Application Data\Mozilla\Firefox\Profiles\pr5444hy.default\extensions\
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
C:\Documents and Settings\kolik\Application Data\Mozilla\Firefox\Profiles\pr5444hy.default\searchplugins\
icqplugin.xml
qip-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-03 172032]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-12-14 651264]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2010-11-03 2815592]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\kolik\Start Menu\Programs\Startup
ctfmon.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-03-03 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:ipsec"
"C:\Documents and Settings\kolik\Desktop\warcraft-panfazole\Warcraft III + FT + eurobattle.net + dota ( 4.2.2010 )\Warcraft III.exe"="C:\Documents and Settings\kolik\Desktop\warcraft-panfazole\Warcraft III + FT + eurobattle.net + dota ( 4.2.2010 )\Warcraft III.exe:*:Enabled:Warcraft III"
"D:\stary disk\WARCRAFT 33333\w33\ warcraft\Warcraft III.exe"="D:\stary disk\WARCRAFT 33333\w33\ warcraft\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Documents and Settings\kolik\Desktop\nub slozka\Ranked Gaming Client\rgc.exe"="C:\Documents and Settings\kolik\Desktop\nub slozka\Ranked Gaming Client\rgc.exe:*:Enabled:rgc"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"C:\Program Files\BitTorrent\BitTorrent.exe"="C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\National Instruments\DIAdem 2010\DIAdem.exe"="C:\Program Files\National Instruments\DIAdem 2010\DIAdem.exe:*:Enabled:DIAdem 2010"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\National Instruments\Shared\DataFinderDesktop\bin\DataFinder.exe"="C:\Program Files\National Instruments\Shared\DataFinderDesktop\bin\DataFinder.exe:*:Disabled:DataFinder"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe"="C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh"
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe"="C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"F:\bfybt.exe"="F:\bfybt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winfqfy.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winfqfy.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\dtsk.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\dtsk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ldje.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ldje.exe:*:Enabled:ipsec"
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\userinit.exe"="C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec"
"C:\WINDOWS\system32\svchost.exe"="C:\WINDOWS\system32\svchost.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winocjis.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winocjis.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\xllt.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\xllt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winkkgux.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winkkgux.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\nltv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\nltv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\mbqp.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\mbqp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingptt.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingptt.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wincocv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wincocv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\pqnd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\pqnd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winerfqug.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winerfqug.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winubmfg.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winubmfg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\vttlx.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\vttlx.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhvwd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhvwd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqtfe.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqtfe.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ymkha.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ymkha.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqnst.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqnst.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\jmepoo.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\jmepoo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\xqkfd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\xqkfd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\sqsmdh.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\sqsmdh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\mjtn.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\mjtn.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\scwnqb.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\scwnqb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winokno.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winokno.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\plgp.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\plgp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winbmrie.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winbmrie.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\jqtqm.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\jqtqm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winpfpw.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winpfpw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winmrwdf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winmrwdf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winxnclvj.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winxnclvj.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winttqgxu.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winttqgxu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winbpss.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winbpss.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingnjvf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingnjvf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\kopor.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\kopor.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winyobm.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winyobm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\emwlcm.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\emwlcm.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrmwtf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrmwtf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ksvrxg.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ksvrxg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\hmuoh.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\hmuoh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqkonof.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqkonof.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingmhiby.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingmhiby.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winrnsskv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winrnsskv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhxja.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhxja.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\yinxo.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\yinxo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winqcvoa.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winqcvoa.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\bngl.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\bngl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrguur.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingrguur.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winixstky.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winixstky.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\nkvhci.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\nkvhci.exe:*:Enabled:ipsec"
"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winkqlqr.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winkqlqr.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\vvpve.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\vvpve.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\pltw.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\pltw.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\tycv.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\tycv.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ngvjo.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ngvjo.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\xdvhsk.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\xdvhsk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winuixxu.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winuixxu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\euxb.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\euxb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winkpoi.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winkpoi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\csli.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\csli.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winmxxoty.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winmxxoty.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhcrckh.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhcrckh.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winehru.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winehru.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winvefl.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winvefl.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ndpcbf.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ndpcbf.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winivyyi.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winivyyi.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\rkyye.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\rkyye.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ltate.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ltate.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winxota.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winxota.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winxhrd.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winxhrd.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\asuu.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\asuu.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winhaigq.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winhaigq.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\fndsk.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\fndsk.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winatmox.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winatmox.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winbcjij.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winbcjij.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\windaidp.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\windaidp.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\wingwxqb.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\wingwxqb.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\ogosg.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\ogosg.exe:*:Enabled:ipsec"
"C:\DOCUME~1\kolik\LOCALS~1\Temp\winjndkc.exe"="C:\DOCUME~1\kolik\LOCALS~1\Temp\winjndkc.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\iMesh Applications\iMesh\iMesh.exe"="C:\Program Files\iMesh Applications\iMesh\iMesh.exe:*:Enabled:iMesh"
"C:\Program Files\BearShare Applications\BearShare\BearShare.exe"="C:\Program Files\BearShare Applications\BearShare\BearShare.exe:*:Enabled:BearShare"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"vidc.XVID"=xvidvfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-08-13 01:51:06 ----D---- C:\rsit
2011-08-13 01:51:06 ----D---- C:\Program Files\trend micro
2011-08-13 01:15:27 ----D---- C:\WINDOWS\system32\NtmsData
2011-08-13 00:36:00 ----D---- C:\WINDOWS\SxsCaPendDel
2011-08-13 00:29:36 ----SHD---- C:\Config.Msi
2011-08-13 00:23:22 ----D---- C:\WINDOWS\system32\appmgmt
2011-08-13 00:22:04 ----A---- C:\WINDOWS\Eurobattle.net Uninstall Log.txt
======List of files/folders modified in the last 1 month======
2011-08-13 01:51:58 ----D---- C:\Documents and Settings\kolik\Application Data\BitTorrent
2011-08-13 01:51:13 ----D---- C:\WINDOWS\Prefetch
2011-08-13 01:51:06 ----RD---- C:\Program Files
2011-08-13 01:15:27 ----D---- C:\WINDOWS\system32
2011-08-13 00:45:46 ----D---- C:\WINDOWS\system32\drivers
2011-08-13 00:44:31 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-13 00:43:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-13 00:37:02 ----SHD---- C:\WINDOWS\Installer
2011-08-13 00:37:02 ----D---- C:\Program Files\Common Files
2011-08-13 00:36:46 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-13 00:36:18 ----RSD---- C:\WINDOWS\assembly
2011-08-13 00:36:16 ----D---- C:\Program Files\Microsoft Visual Studio 10.0
2011-08-13 00:36:01 ----D---- C:\WINDOWS\WinSxS
2011-08-13 00:36:00 ----D---- C:\WINDOWS
2011-08-13 00:35:23 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-08-13 00:25:11 ----SD---- C:\WINDOWS\Tasks
2011-08-13 00:24:24 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-13 00:24:24 ----D---- C:\Program Files\Ubi Soft
2011-08-13 00:23:51 ----D---- C:\Program Files\Mozilla Firefox
2011-08-13 00:23:35 ----D---- C:\Documents and Settings\kolik\Application Data\Skype
2011-08-13 00:22:08 ----D---- C:\Program Files\Warcraft III
2011-08-12 22:28:14 ----D---- C:\Program Files\Opera
2011-08-12 13:52:05 ----D---- C:\Program Files\Heroes of Newerth
2011-08-06 09:11:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 PxHelp20;PxHelp20; C:\WINDOWS\system32\DRIVERS\PxHelp20.sys [2003-10-28 20016]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2002-03-11 436792]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-02 36864]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 cvintdrv;cvintdrv; C:\WINDOWS\system32\drivers\cvintdrv.sys [2008-04-07 4096]
R3 amsint32;amsint32; \??\C:\WINDOWS\system32\drivers\pkhqn.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-03-03 4630016]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-11-30 6261352]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2007-04-14 94592]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S2 DgiVecp;DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys []
S2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 at6saa36;at6saa36; C:\WINDOWS\system32\drivers\at6saa36.sys []
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\kolik\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\safedrv.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSICPL;MSICPL; \??\E:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-14 20992]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-03-03 602112]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 LkCitadelServer;Lookout Citadel Server; C:\WINDOWS\system32\lkcitdl.exe [2009-09-29 695136]
R2 lkClassAds;National Instruments PSP Server Locator; C:\WINDOWS\system32\lkads.exe [2010-03-10 43056]
R2 lkTimeSync;National Instruments Time Synchronization; C:\WINDOWS\system32\lktsrv.exe [2010-03-10 53808]
R2 NIDomainService;National Instruments Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2010-03-10 358448]
R2 niSvcLoc;NI Service Locator; C:\WINDOWS\system32\nisvcloc.exe [2009-10-20 13896]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 135456]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NILM License Manager;NILM License Manager; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2009-09-18 1077248]
-----------------EOF-----------------