problem s cervom
Napsal: 15 zář 2011 15:43
Dobry den,
omylom som stiahol a otvoril infikovany exe subor, ktory mi do PC pravdepodobne vniesol cerva. Postupne mi prestavaju pracovat stale viacere programy, napriklad Skype IM, ICQ IM, Firewall Zone Alarm, VoIP program TeamSpeak 3 a mnoho dalsich. Stalo sa to pred 3 dnami a hned po tom, ako som si vsimol prve naznaky, som pustil kompletnu WMAV kontrolu a vsetko co naslo som zmazal. Zabudol som, kam to uklada logy, takze ak ho spolocne najdeme, kludne ho sem dodam. "Cervave" aplikacie nefunguju takym sposobom, ze pri otvoreni bud hodia klasicky dr watson error alebo nejaky Microsoft Visual C++ Runtime Library error R6002 - floating point support not loaded.
Momentalne som teda bez antiviru a firewallu, lebo mi nejdu spustit.
Predom dakujem.
Prikladam log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by heRoo at 2011-09-15 16:42:46
Microsoft Windows XP Professional Service Pack 3
System drive C: has 146 MB (1%) free of 13 GB
Total RAM: 2047 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:42:51, on 15.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tunngle\TnglCtrl.exe
C:\Program Files\Common Files\WireHelpSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\EslWire\dbus-daemon.exe
D:\Hry\cs\Steam.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Hry\cs\steamapps\heroo16\counter-strike\cstrike\RSIT.exe
C:\Program Files\trend micro\heRoo.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 173.212.255.178 embedded.garena.com
O1 - Hosts: 173.212.255.178 embedded.garenanow.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ESL Wire] "C:\Program Files\EslWire\wire.exe" --tray
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WireHelpSvc - Unknown owner - C:\Program Files\Common Files\WireHelpSvc.exe
--
End of file - 6055 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\cron.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\videopadDowngrade.job
C:\WINDOWS\tasks\videopadShakeIcon.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default
prefs.js - "browser.startup.homepage" - "google.sk"
prefs.js - "extensions.enabledItems" - "{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, jqs@sun.com:1.0, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:2.5.6.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1, {ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}:0.3.8.1, personas@christopher.beard:1.6.1, {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9, firebug@software.joehewitt.com:1.6.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=G:\Programy\Media go\npmediago.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default\extensions\
engine@conduit.com
{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
{c45c406e-ab73-11d8-be73-000a95be3b12}
{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC7E636D-39AA-49b6-B511-65413DA137A1}]
IE Developer Toolbar BHO - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2007-03-01 623992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-16 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-05-16 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"=D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2011-09-12 1221596]
"P17Helper"=Rundll32 P17.dll,P17Helper []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ESL Wire"=C:\Program Files\EslWire\wire.exe [2011-09-12 2121686]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-08-04 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=475
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"G:\Programy\xampp\xampp\apache\bin\httpd.exe"="G:\Programy\xampp\xampp\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"G:\Programy\xampp\xampp\mysql\bin\mysqld.exe"="G:\Programy\xampp\xampp\mysql\bin\mysqld.exe:*:Enabled:The MySQL Server"
"D:\Program Files\HLSW\hlsw.exe"="D:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"E:\Warcraft III\Warcraft III\war3.exe"="E:\Warcraft III\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"G:\QUarantine\CSdef\hl.exe"="G:\QUarantine\CSdef\hl.exe:*:Enabled:Half-Life Launcher"
"C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary"
"G:\Games\dsadas\hltv.exe"="G:\Games\dsadas\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"D:\Program Files\Java\jre6\bin\javaw.exe"="D:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"G:\Programy\bitlord\BitLord.exe"="G:\Programy\bitlord\BitLord.exe:*:Enabled:BitLord"
"G:\Programy\Update Service\Update Service.exe"="G:\Programy\Update Service\Update Service.exe:*:Enabled:Update Service"
"D:\Hry\cs\Steam.exe"="D:\Hry\cs\Steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"G:\Games\dsadas\hl.exe"="G:\Games\dsadas\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Documents and Settings\heRoo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe"="C:\Documents and Settings\heRoo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player"
"C:\Program Files\Mineserver Project\Mineserver\mineserver.exe"="C:\Program Files\Mineserver Project\Mineserver\mineserver.exe:*:Enabled:mineserver"
"G:\Games\AoE2\age2_x1\age2_x1.exe"="G:\Games\AoE2\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"G:\Games\Age Of Empires II Conquerors\age2_x1\age2_x1.exe"="G:\Games\Age Of Empires II Conquerors\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"G:\Games\StarCraft II\StarCraft II.exe"="G:\Games\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"G:\Games\StarCraft II\Versions\Base15405\SC2.exe"="G:\Games\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"G:\Games\LoL\air\LolClient.exe"="G:\Games\LoL\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"G:\Games\LoL\game\League of Legends.exe"="G:\Games\LoL\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"D:\Program Files\Garena\Garena.exe"="D:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\cs\steamapps\heroo16\source sdk base 2007\hl2.exe"="D:\Hry\cs\steamapps\heroo16\source sdk base 2007\hl2.exe:*:Enabled:hl2"
"C:\Program Files\NetMeeting\conf.exe"="C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®"
"C:\Program Files\Webteh\BSplayer\bsplayer.exe"="C:\Program Files\Webteh\BSplayer\bsplayer.exe:*:Enabled:BS.Player"
"C:\Program Files\gta2gh\gta2gh.exe"="C:\Program Files\gta2gh\gta2gh.exe:*:Enabled:gta2gh"
"G:\Programy\Media go\MediaGo.exe"="G:\Programy\Media go\MediaGo.exe:*:Enabled:Media Go"
"G:\Programy\xampp\xampp\FileZillaFTP\FileZilla Server.exe"="G:\Programy\xampp\xampp\FileZillaFTP\FileZilla Server.exe:*:Enabled:FileZilla Server"
"G:\Games\dsadas\hlds.exe"="G:\Games\dsadas\hlds.exe:*:Enabled:HLDS Launcher"
"G:\Games\CaC\Hra\ZH\game.dat"="G:\Games\CaC\Hra\ZH\game.dat:*:Enabled:game"
"C:\Program Files\Tunngle\TnglCtrl.exe"="C:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service"
"C:\Program Files\Tunngle\Tunngle.exe"="C:\Program Files\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"G:\Games\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe"="G:\Games\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"G:\Games\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe"="G:\Games\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"E:\Warcraft III\Warcraft III\gproxy.exe"="E:\Warcraft III\Warcraft III\gproxy.exe:*:Enabled:gproxy"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\cs\steamapps\heroo16\dedicated server\hltv.exe"="D:\Hry\cs\steamapps\heroo16\dedicated server\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Hry\cs\steamapps\heroo16\half-life\hl.exe"="D:\Hry\cs\steamapps\heroo16\half-life\hl.exe:*:Enabled:Half-Life"
"C:\Program Files\EslWire\wire.exe"="C:\Program Files\EslWire\wire.exe:*:Enabled:ESL Wire Client"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer"
"D:\Hry\cs\steamapps\heroo16\dedicated server\hlds.exe"="D:\Hry\cs\steamapps\heroo16\dedicated server\hlds.exe:*:Enabled:Dedicated Server"
"G:\Games\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="G:\Games\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Hry\cs\steamapps\heroo16\counter-strike\hl.exe"="D:\Hry\cs\steamapps\heroo16\counter-strike\hl.exe:*:Enabled:Counter-Strike"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.WMV3"=wmv9vcm.dll
"vidc.VP60"=C:\WINDOWS\System32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\System32\vp6vfw.dll
"vidc.iv50"=ir50_32.dll
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"VIDC.IV41"=IR41_32.AX
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-09-15 13:28:56 ----A---- C:\WINDOWS\system32\OLD17A.tmp
2011-09-15 13:28:56 ----A---- C:\WINDOWS\system32\OLD177.tmp
2011-09-15 13:28:56 ----A---- C:\WINDOWS\system32\OLD174.tmp
2011-09-15 11:28:29 ----A---- C:\WINDOWS\OLD6E.tmp
2011-09-15 11:26:21 ----D---- C:\WINDOWS\LastGood
2011-09-12 21:26:53 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2011-09-12 21:26:38 ----D---- C:\WINDOWS\system32\Data
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\VDLL.DLL
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\system32\runouce.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\rundll16.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\RUNDL132.EXE
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\logo1_.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\logo_1.exe
2011-09-12 15:10:02 ----A---- C:\WINDOWS\system32\msvcr80.dll
2011-09-12 15:10:01 ----A---- C:\WINDOWS\system32\msvcp80.dll
2011-09-12 15:10:00 ----A---- C:\WINDOWS\system32\eEmpty.exe
2011-09-12 15:09:57 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\system32\T.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\REGEDIT.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\R.COM
2011-09-12 15:09:55 ----D---- C:\Program Files\Common Files\MicroWorld
2011-09-12 15:09:48 ----D---- C:\Documents and Settings\All Users\Application Data\MicroWorld
2011-09-11 13:44:11 ----D---- C:\Documents and Settings\heRoo\Application Data\Download Manager
2011-09-04 01:07:59 ----A---- C:\Program Files\Common Files\WireHelpSvc.exe
2011-09-04 01:07:55 ----A---- C:\WINDOWS\system32\drivers\ESLWireACD.sys
2011-09-04 01:07:48 ----A---- C:\WINDOWS\system32\drivers\ESLvnic.sys
2011-09-04 01:07:47 ----D---- C:\Program Files\EslWire
2011-09-04 01:07:47 ----D---- C:\Documents and Settings\All Users\Application Data\ESL Wire
2011-08-28 23:31:55 ----D---- C:\Program Files\PHLTV
2011-08-22 02:46:16 ----D---- C:\Program Files\Windows MultiPoint Mouse SDK
2011-08-22 02:24:09 ----A---- C:\WINDOWS\system32\cpnmouse.sys
2011-08-22 02:21:41 ----A---- C:\WINDOWS\system32\drivers\cpnmouse.sys
2011-08-21 16:01:23 ----D---- C:\Program Files\MeeSoft
2011-08-20 11:26:04 ----D---- C:\Program Files\Presentation Assistant
2011-08-20 11:26:04 ----D---- C:\Documents and Settings\heRoo\Application Data\Presentation Assistant
2011-08-19 19:19:54 ----D---- C:\Documents and Settings\heRoo\Application Data\Grasssoft
2011-08-19 19:19:48 ----D---- C:\Documents and Settings\All Users\Application Data\Grasssoft
2011-08-19 19:19:40 ----D---- C:\Program Files\GrassSoft
2011-08-19 13:40:52 ----D---- C:\.jagex_cache_32
======List of files/folders modified in the last 1 month======
2011-09-15 16:42:48 ----D---- C:\Program Files\trend micro
2011-09-15 16:25:07 ----D---- C:\Documents and Settings\heRoo\Application Data\HLSW
2011-09-15 16:01:00 ----D---- C:\WINDOWS\Temp
2011-09-15 13:39:03 ----D---- C:\WINDOWS\system32\wbem
2011-09-15 13:38:03 ----D---- C:\WINDOWS\system32\usmt
2011-09-15 13:37:01 ----D---- C:\WINDOWS\system32\Restore
2011-09-15 13:36:00 ----D---- C:\WINDOWS\system32\npp
2011-09-15 13:33:57 ----D---- C:\WINDOWS\system32\Com
2011-09-15 13:32:56 ----D---- C:\WINDOWS\system32
2011-09-15 13:29:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-15 12:20:30 ----D---- C:\WINDOWS\msagent
2011-09-15 11:28:29 ----D---- C:\WINDOWS
2011-09-15 11:25:20 ----D---- C:\Program Files\Windows NT
2011-09-15 11:18:10 ----D---- C:\Program Files\Outlook Express
2011-09-15 11:17:08 ----D---- C:\Program Files\NetMeeting
2011-09-15 11:14:06 ----D---- C:\Program Files\Movie Maker
2011-09-15 10:59:16 ----D---- C:\Program Files\Internet Explorer
2011-09-15 10:41:00 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-15 10:34:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-15 10:30:20 ----D---- C:\WINDOWS\Internet Logs
2011-09-15 01:43:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-12 21:27:45 ----D---- C:\Program Files\Creative
2011-09-12 21:26:53 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2011-09-12 21:26:49 ----D---- C:\WINDOWS\system32\drivers
2011-09-12 21:26:44 ----HD---- C:\WINDOWS\inf
2011-09-12 21:26:43 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-09-12 21:26:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-12 21:26:10 ----D---- C:\Documents and Settings\heRoo\Application Data\Skype
2011-09-12 20:57:47 ----D---- C:\WINDOWS\Prefetch
2011-09-12 15:21:11 ----A---- C:\WINDOWS\system32\xpsp1hfm.exe
2011-09-12 15:21:04 ----A---- C:\WINDOWS\system32\xcopy.exe
2011-09-12 15:21:03 ----A---- C:\WINDOWS\system32\WudfHost.exe
2011-09-12 15:21:02 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2011-09-12 15:21:02 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-09-12 15:21:01 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2011-09-12 15:21:00 ----A---- C:\WINDOWS\system32\wpdshextautoplay.exe
2011-09-12 15:21:00 ----A---- C:\WINDOWS\system32\wpabaln.exe
2011-09-12 15:20:56 ----A---- C:\WINDOWS\system32\winver.exe
2011-09-12 15:20:55 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2011-09-12 15:20:54 ----A---- C:\WINDOWS\system32\wextract.exe
2011-09-12 15:20:54 ----A---- C:\WINDOWS\system32\wdfmgr.exe
2011-09-12 15:20:53 ----A---- C:\WINDOWS\system32\verclsid.exe
2011-09-12 15:20:52 ----A---- C:\WINDOWS\system32\uwdf.exe
2011-09-12 15:20:52 ----A---- C:\WINDOWS\system32\utilman.exe
2011-09-12 15:20:49 ----A---- C:\WINDOWS\system32\upnpcont.exe
2011-09-12 15:20:49 ----A---- C:\WINDOWS\system32\tzchange.exe
2011-09-12 15:20:48 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2011-09-12 15:20:48 ----A---- C:\WINDOWS\system32\tracert.exe
2011-09-12 15:20:48 ----A---- C:\WINDOWS\system32\tracerpt.exe
2011-09-12 15:20:47 ----A---- C:\WINDOWS\system32\tourstart.exe
2011-09-12 15:20:46 ----A---- C:\WINDOWS\system32\tlntsess.exe
2011-09-12 15:20:46 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2011-09-12 15:20:46 ----A---- C:\WINDOWS\system32\telnet.exe
2011-09-12 15:20:45 ----A---- C:\WINDOWS\system32\taskmgr.exe
2011-09-12 15:20:44 ----A---- C:\WINDOWS\system32\tasklist.exe
2011-09-12 15:20:44 ----A---- C:\WINDOWS\system32\taskkill.exe
2011-09-12 15:20:43 ----A---- C:\WINDOWS\system32\systeminfo.exe
2011-09-12 15:20:42 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2011-09-12 15:20:41 ----A---- C:\WINDOWS\system32\stimon.exe
2011-09-12 15:20:34 ----A---- C:\WINDOWS\system32\spupdwxp.exe
2011-09-12 15:20:34 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2011-09-12 15:20:33 ----A---- C:\WINDOWS\system32\spnpinst.exe
2011-09-12 15:20:33 ----A---- C:\WINDOWS\system32\spiisupd.exe
2011-09-12 15:20:33 ----A---- C:\WINDOWS\system32\spider.exe
2011-09-12 15:20:32 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2011-09-12 15:20:32 ----A---- C:\WINDOWS\system32\sort.exe
2011-09-12 15:20:31 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-09-12 15:20:30 ----A---- C:\WINDOWS\system32\smbinst.exe
2011-09-12 15:20:30 ----A---- C:\WINDOWS\system32\slserv.exe
2011-09-12 15:20:30 ----A---- C:\WINDOWS\system32\slrundll.exe
2011-09-12 15:20:29 ----A---- C:\WINDOWS\system32\skeys.exe
2011-09-12 15:20:29 ----A---- C:\WINDOWS\system32\sigverif.exe
2011-09-12 15:20:29 ----A---- C:\WINDOWS\system32\shutdown.exe
2011-09-12 15:20:28 ----A---- C:\WINDOWS\system32\shrpubw.exe
2011-09-12 15:20:27 ----A---- C:\WINDOWS\system32\setupn.exe
2011-09-12 15:20:27 ----A---- C:\WINDOWS\system32\setup.exe
2011-09-12 15:20:26 ----A---- C:\WINDOWS\system32\sethc.exe
2011-09-12 15:20:26 ----A---- C:\WINDOWS\system32\secedit.exe
2011-09-12 15:20:25 ----A---- C:\WINDOWS\system32\sdbinst.exe
2011-09-12 15:20:24 ----A---- C:\WINDOWS\system32\schtasks.exe
2011-09-12 15:20:23 ----A---- C:\WINDOWS\system32\savedump.exe
2011-09-12 15:20:22 ----A---- C:\WINDOWS\system32\runonce.exe
2011-09-12 15:20:22 ----A---- C:\WINDOWS\system32\rtcshare.exe
2011-09-12 15:20:21 ----A---- C:\WINDOWS\system32\rsnotify.exe
2011-09-12 15:20:20 ----A---- C:\WINDOWS\system32\rsh.exe
2011-09-12 15:20:20 ----A---- C:\WINDOWS\system32\rexec.exe
2011-09-12 15:20:20 ----A---- C:\WINDOWS\system32\reg.exe
2011-09-12 15:20:19 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-09-12 15:20:19 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-09-12 15:20:19 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-09-12 15:20:18 ----A---- C:\WINDOWS\system32\rcp.exe
2011-09-12 15:20:18 ----A---- C:\WINDOWS\system32\rcimlby.exe
2011-09-12 15:20:17 ----A---- C:\WINDOWS\system32\rasphone.exe
2011-09-12 15:20:16 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-09-12 15:20:16 ----A---- C:\WINDOWS\system32\proxycfg.exe
2011-09-12 15:20:15 ----A---- C:\WINDOWS\system32\proquota.exe
2011-09-12 15:20:15 ----A---- C:\WINDOWS\system32\PresentationHost.exe
2011-09-12 15:20:14 ----A---- C:\WINDOWS\system32\powercfg.exe
2011-09-12 15:20:13 ----A---- C:\WINDOWS\system32\perfmon.exe
2011-09-12 15:20:12 ----A---- C:\WINDOWS\system32\packager.exe
2011-09-12 15:20:12 ----A---- C:\WINDOWS\system32\osk.exe
2011-09-12 15:20:11 ----A---- C:\WINDOWS\system32\openfiles.exe
2011-09-12 15:20:09 ----A---- C:\WINDOWS\system32\odbcconf.exe
2011-09-12 15:20:08 ----RA---- C:\WINDOWS\system32\nvusmu.exe
2011-09-12 15:20:08 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2011-09-12 15:20:08 ----A---- C:\WINDOWS\system32\odbcad32.exe
2011-09-12 15:20:08 ----A---- C:\WINDOWS\system32\nvunrm.exe
2011-09-12 15:20:07 ----RA---- C:\WINDOWS\system32\NVUNINST.EXE
2011-09-12 15:20:06 ----A---- C:\WINDOWS\system32\ntbackup.exe
2011-09-12 15:20:06 ----A---- C:\WINDOWS\system32\nslookup.exe
2011-09-12 15:20:05 ----A---- C:\WINDOWS\system32\notepad.exe
2011-09-12 15:20:05 ----A---- C:\WINDOWS\system32\netstat.exe
2011-09-12 15:20:05 ----A---- C:\WINDOWS\system32\netsh.exe
2011-09-12 15:20:04 ----A---- C:\WINDOWS\system32\netsetup.exe
2011-09-12 15:20:04 ----A---- C:\WINDOWS\system32\net1.exe
2011-09-12 15:20:03 ----A---- C:\WINDOWS\system32\net.exe
2011-09-12 15:20:03 ----A---- C:\WINDOWS\system32\nddeapir.exe
2011-09-12 15:20:03 ----A---- C:\WINDOWS\system32\narrator.exe
2011-09-12 15:20:02 ----A---- C:\WINDOWS\system32\napstat.exe
2011-09-12 15:20:00 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-09-12 15:19:59 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-09-12 15:19:56 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2011-09-12 15:19:54 ----A---- C:\WINDOWS\system32\mqbkup.exe
2011-09-12 15:19:54 ----A---- C:\WINDOWS\system32\mobsync.exe
2011-09-12 15:19:53 ----A---- C:\WINDOWS\system32\mmcperf.exe
2011-09-12 15:19:53 ----A---- C:\WINDOWS\system32\mmc.exe
2011-09-12 15:19:52 ----A---- C:\WINDOWS\system32\migpwd.exe
2011-09-12 15:19:50 ----A---- C:\WINDOWS\system32\makecab.exe
2011-09-12 15:19:50 ----A---- C:\WINDOWS\system32\magnify.exe
2011-09-12 15:19:50 ----A---- C:\WINDOWS\system32\logonui.exe
2011-09-12 15:19:49 ----A---- C:\WINDOWS\system32\logman.exe
2011-09-12 15:19:47 ----A---- C:\WINDOWS\system32\javaws.exe
2011-09-12 15:19:46 ----A---- C:\WINDOWS\system32\javaw.exe
2011-09-12 15:19:46 ----A---- C:\WINDOWS\system32\java.exe
2011-09-12 15:19:44 ----A---- C:\WINDOWS\system32\ipxroute.exe
2011-09-12 15:19:44 ----A---- C:\WINDOWS\system32\ipv6.exe
2011-09-12 15:19:43 ----A---- C:\WINDOWS\system32\ipconfig.exe
2011-09-12 15:19:41 ----A---- C:\WINDOWS\system32\iexpress.exe
2011-09-12 15:19:41 ----A---- C:\WINDOWS\system32\icardagt.exe
2011-09-12 15:19:39 ----A---- C:\WINDOWS\system32\help.exe
2011-09-12 15:19:39 ----A---- C:\WINDOWS\system32\grpconv.exe
2011-09-12 15:19:39 ----A---- C:\WINDOWS\system32\gpresult.exe
2011-09-12 15:19:38 ----A---- C:\WINDOWS\system32\getmac.exe
2011-09-12 15:19:38 ----A---- C:\WINDOWS\system32\ftp.exe
2011-09-12 15:19:37 ----A---- C:\WINDOWS\system32\fsquirt.exe
2011-09-12 15:19:37 ----A---- C:\WINDOWS\system32\forcedos.exe
2011-09-12 15:19:37 ----A---- C:\WINDOWS\system32\fontview.exe
2011-09-12 15:19:36 ----A---- C:\WINDOWS\system32\fltmc.exe
2011-09-12 15:19:36 ----A---- C:\WINDOWS\system32\findstr.exe
2011-09-12 15:19:35 ----A---- C:\WINDOWS\system32\faxpatch.exe
2011-09-12 15:19:35 ----A---- C:\WINDOWS\system32\extrac32.exe
2011-09-12 15:19:35 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2011-09-12 15:19:34 ----A---- C:\WINDOWS\system32\eventcreate.exe
2011-09-12 15:19:34 ----A---- C:\WINDOWS\system32\eudcedit.exe
2011-09-12 15:19:33 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2011-09-12 15:19:32 ----A---- C:\WINDOWS\system32\dxdiag.exe
2011-09-12 15:19:31 ----A---- C:\WINDOWS\system32\dwwin.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\dvdplay.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\dumprep.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\drmupgds.exe
2011-09-12 15:19:29 ----A---- C:\WINDOWS\system32\driverquery.exe
2011-09-12 15:19:29 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2011-09-12 15:19:29 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2011-09-12 15:19:28 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2011-09-12 15:19:28 ----A---- C:\WINDOWS\system32\dns-sd.exe
2011-09-12 15:19:28 ----A---- C:\WINDOWS\system32\dmremote.exe
2011-09-12 15:19:27 ----A---- C:\WINDOWS\system32\diskpart.exe
2011-09-12 15:19:27 ----A---- C:\WINDOWS\system32\diantz.exe
2011-09-12 15:19:27 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\defrag.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\ddeshare.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-09-12 15:19:16 ----A---- C:\WINDOWS\system32\ctfmon.exe
2011-09-12 15:19:15 ----A---- C:\WINDOWS\system32\cscript.exe
2011-09-12 15:19:14 ----A---- C:\WINDOWS\system32\conime.exe
2011-09-12 15:19:14 ----A---- C:\WINDOWS\system32\comsdupd.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\cmstp.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\cmmon32.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\cmdl32.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-09-12 15:19:12 ----A---- C:\WINDOWS\system32\cliconfg.exe
2011-09-12 15:19:12 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2011-09-12 15:19:12 ----A---- C:\WINDOWS\system32\cipher.exe
2011-09-12 15:19:11 ----A---- C:\WINDOWS\system32\cacls.exe
2011-09-12 15:19:11 ----A---- C:\WINDOWS\system32\bootcfg.exe
2011-09-12 15:19:10 ----A---- C:\WINDOWS\system32\blastcln.exe
2011-09-12 15:19:09 ----A---- C:\WINDOWS\system32\auditusr.exe
2011-09-12 15:19:09 ----A---- C:\WINDOWS\system32\attrib.exe
2011-09-12 15:19:09 ----A---- C:\WINDOWS\system32\atmadm.exe
2011-09-12 15:19:04 ----A---- C:\WINDOWS\system32\ATIODE.exe
2011-09-12 15:19:03 ----A---- C:\WINDOWS\system32\ATIODCLI.exe
2011-09-12 15:19:03 ----A---- C:\WINDOWS\system32\atibtmon.exe
2011-09-12 15:19:03 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2011-09-12 15:19:02 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2011-09-12 15:19:02 ----A---- C:\WINDOWS\system32\at.exe
2011-09-12 15:19:01 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2011-09-12 15:19:01 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2011-09-12 15:19:00 ----A---- C:\WINDOWS\system32\ahui.exe
2011-09-12 15:18:58 ----A---- C:\WINDOWS\system32\actmovie.exe
2011-09-12 15:18:58 ----A---- C:\WINDOWS\system32\AcSignOpt.exe
2011-09-12 15:18:57 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-09-12 15:18:55 ----A---- C:\WINDOWS\winhlp32.exe
2011-09-12 15:18:54 ----A---- C:\WINDOWS\Updreg.EXE
2011-09-12 15:18:53 ----A---- C:\WINDOWS\ST5UNST.EXE
2011-09-12 15:18:53 ----A---- C:\WINDOWS\regedit.exe
2011-09-12 15:18:52 ----A---- C:\WINDOWS\P17DEF.EXE
2011-09-12 15:18:52 ----A---- C:\WINDOWS\notepad.exe
2011-09-12 15:18:51 ----A---- C:\WINDOWS\MIDIDEF.EXE
2011-09-12 15:18:51 ----A---- C:\WINDOWS\lsb_un20.exe
2011-09-12 15:18:50 ----A---- C:\WINDOWS\IsUninst.exe
2011-09-12 15:18:50 ----A---- C:\WINDOWS\hh.exe
2011-09-12 15:18:49 ----A---- C:\WINDOWS\Ctregrun.exe
2011-09-12 15:18:49 ----A---- C:\WINDOWS\ColorPic Uninstaller.exe
2011-09-12 15:18:46 ----D---- C:\Program Files\Cheat Engine
2011-09-12 15:17:18 ----A---- C:\WINDOWS\system32\vssvc.exe
2011-09-12 15:17:16 ----A---- C:\WINDOWS\system32\ups.exe
2011-09-12 15:17:16 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2011-09-12 15:17:16 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2011-09-12 15:17:15 ----A---- C:\WINDOWS\system32\scardsvr.exe
2011-09-12 15:17:14 ----A---- C:\WINDOWS\system32\locator.exe
2011-09-12 15:17:13 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-09-12 15:17:12 ----A---- C:\WINDOWS\system32\netdde.exe
2011-09-12 15:17:12 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-09-12 15:17:12 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-09-12 15:17:11 ----A---- C:\WINDOWS\system32\imapi.exe
2011-09-12 15:17:09 ----A---- C:\WINDOWS\system32\dmadmin.exe
2011-09-12 15:17:08 ----A---- C:\WINDOWS\system32\dllhost.exe
2011-09-12 15:17:08 ----A---- C:\WINDOWS\system32\clipsrv.exe
2011-09-12 15:17:08 ----A---- C:\WINDOWS\system32\cisvc.exe
2011-09-12 15:16:53 ----A---- C:\WINDOWS\system32\wscript.exe
2011-09-12 15:16:52 ----A---- C:\WINDOWS\system32\mshta.exe
2011-09-12 15:16:49 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2011-09-12 15:16:48 ----A---- C:\WINDOWS\system32\shmgrate.exe
2011-09-12 15:16:48 ----A---- C:\WINDOWS\system32\regsvr32.exe
2011-09-12 15:16:47 ----A---- C:\WINDOWS\system32\ntvdm.exe
2011-09-12 15:16:45 ----A---- C:\WINDOWS\system32\userinit.exe
2011-09-12 15:16:40 ----A---- C:\WINDOWS\system32\mspaint.exe
2011-09-12 15:09:55 ----D---- C:\Program Files\Common Files
2011-09-11 14:10:16 ----ASH---- C:\boot.ini
2011-09-11 11:46:02 ----D---- C:\WINDOWS\mui
2011-09-09 17:56:33 ----SHD---- C:\WINDOWS\Installer
2011-09-08 23:18:05 ----SD---- C:\WINDOWS\Tasks
2011-09-07 18:29:15 ----D---- C:\Program Files\Mozilla Firefox
2011-09-04 01:07:47 ----RD---- C:\Program Files
2011-08-26 22:49:50 ----A---- C:\Documents and Settings\heRoo\Application Data\myMPQ.ini
2011-08-22 02:46:27 ----RSD---- C:\WINDOWS\assembly
2011-08-22 02:43:55 ----D---- C:\WINDOWS\SoftwareDistribution
2011-08-22 00:50:57 ----D---- C:\WINDOWS\.jagex_cache_32
2011-08-19 19:19:55 ----RSD---- C:\WINDOWS\Fonts
2011-08-19 19:19:42 ----D---- C:\Documents and Settings\heRoo\Application Data\GetRightToGo
2011-08-18 03:21:53 ----D---- C:\Program Files\AMX Mod X
2011-08-16 02:55:28 ----D---- C:\Documents and Settings\heRoo\Application Data\mIRC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-06-17 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2010-05-13 532224]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 ESLWireAC;ESLWireAC; \??\C:\WINDOWS\system32\drivers\ESLWireACD.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2010-08-04 5243392]
R3 BTCAMDRV;Mobiola Web Camera driver; C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 219264]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 DCamUSBSQTECH;Dual-Mode DSC(2770); C:\WINDOWS\System32\Drivers\SQcaptur.sys [2003-01-10 30921]
R3 ESLvnic1;ESLvnic Virtual Network 32 Bit; C:\WINDOWS\system32\DRIVERS\ESLvnic.sys [2011-08-03 24504]
R3 gbridge;Gbridge Virtual Miniport; C:\WINDOWS\system32\DRIVERS\gbridge.sys [2009-05-10 41216]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2007-11-17 54016]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2007-11-17 22016]
R3 nvsmu;nvsmu; C:\WINDOWS\System32\DRIVERS\nvsmu.sys [2007-10-12 13312]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\System32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2007-06-15 1127936]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\System32\DRIVERS\point32.sys [2007-08-21 21760]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-08-22 27632]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\WINDOWS\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 au08znq6;au08znq6; C:\WINDOWS\system32\drivers\au08znq6.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpnmouse;cpnmouse; C:\WINDOWS\system32\DRIVERS\cpnmouse.sys [2003-11-28 5162]
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2010-08-22 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2010-08-22 25512]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\WINDOWS\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\WINDOWS\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\WINDOWS\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\WINDOWS\system32\DRIVERS\s1039bus.sys [2009-11-19 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s1039mdfl.sys [2009-11-19 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s1039mdm.sys [2009-11-19 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s1039mgmt.sys [2009-11-19 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\s1039nd5.sys [2009-11-19 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s1039obex.sys [2009-11-19 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\s1039unic.sys [2009-11-19 123504]
S3 se32;EnTech softEngine; C:\WINDOWS\system32\drivers\se32.sys [2007-05-03 12112]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\System32\DRIVERS\VBoxNetAdp.sys [2010-02-12 99152]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-08-04 606208]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-16 153376]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2010-11-22 718072]
R2 WireHelpSvc;WireHelpSvc; C:\Program Files\Common Files\WireHelpSvc.exe [2011-08-03 265120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2011-09-12 308186]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-12 313818]
S2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2011-09-12 2613722]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2011-09-12 212950]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2011-09-12 255958]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-09-12 832474]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-12 313818]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2011-09-12 1062368]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2011-09-12 931296]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2011-09-12 247252]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
omylom som stiahol a otvoril infikovany exe subor, ktory mi do PC pravdepodobne vniesol cerva. Postupne mi prestavaju pracovat stale viacere programy, napriklad Skype IM, ICQ IM, Firewall Zone Alarm, VoIP program TeamSpeak 3 a mnoho dalsich. Stalo sa to pred 3 dnami a hned po tom, ako som si vsimol prve naznaky, som pustil kompletnu WMAV kontrolu a vsetko co naslo som zmazal. Zabudol som, kam to uklada logy, takze ak ho spolocne najdeme, kludne ho sem dodam. "Cervave" aplikacie nefunguju takym sposobom, ze pri otvoreni bud hodia klasicky dr watson error alebo nejaky Microsoft Visual C++ Runtime Library error R6002 - floating point support not loaded.
Momentalne som teda bez antiviru a firewallu, lebo mi nejdu spustit.
Predom dakujem.
Prikladam log:
Logfile of random's system information tool 1.09 (written by random/random)
Run by heRoo at 2011-09-15 16:42:46
Microsoft Windows XP Professional Service Pack 3
System drive C: has 146 MB (1%) free of 13 GB
Total RAM: 2047 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:42:51, on 15.9.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tunngle\TnglCtrl.exe
C:\Program Files\Common Files\WireHelpSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\EslWire\dbus-daemon.exe
D:\Hry\cs\Steam.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Hry\cs\steamapps\heroo16\counter-strike\cstrike\RSIT.exe
C:\Program Files\trend micro\heRoo.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 173.212.255.178 embedded.garena.com
O1 - Hosts: 173.212.255.178 embedded.garenanow.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ESL Wire] "C:\Program Files\EslWire\wire.exe" --tray
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WireHelpSvc - Unknown owner - C:\Program Files\Common Files\WireHelpSvc.exe
--
End of file - 6055 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\cron.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\videopadDowngrade.job
C:\WINDOWS\tasks\videopadShakeIcon.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default
prefs.js - "browser.startup.homepage" - "google.sk"
prefs.js - "extensions.enabledItems" - "{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, jqs@sun.com:1.0, {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}:2.5.6.0, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1, {ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}:0.3.8.1, personas@christopher.beard:1.6.1, {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9, firebug@software.joehewitt.com:1.6.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=G:\Programy\Media go\npmediago.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default\extensions\
engine@conduit.com
{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
{c45c406e-ab73-11d8-be73-000a95be3b12}
{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
C:\Documents and Settings\heRoo\Application Data\Mozilla\Firefox\Profiles\n01jo72q.default\searchplugins\
conduit.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC7E636D-39AA-49b6-B511-65413DA137A1}]
IE Developer Toolbar BHO - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2007-03-01 623992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-16 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-05-16 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"=D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2011-09-12 1221596]
"P17Helper"=Rundll32 P17.dll,P17Helper []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"ESL Wire"=C:\Program Files\EslWire\wire.exe [2011-09-12 2121686]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-08-04 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=475
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=475
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"G:\Programy\xampp\xampp\apache\bin\httpd.exe"="G:\Programy\xampp\xampp\apache\bin\httpd.exe:*:Enabled:Apache HTTP Server"
"G:\Programy\xampp\xampp\mysql\bin\mysqld.exe"="G:\Programy\xampp\xampp\mysql\bin\mysqld.exe:*:Enabled:The MySQL Server"
"D:\Program Files\HLSW\hlsw.exe"="D:\Program Files\HLSW\hlsw.exe:*:Enabled:HLSW Application"
"E:\Warcraft III\Warcraft III\war3.exe"="E:\Warcraft III\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"G:\QUarantine\CSdef\hl.exe"="G:\QUarantine\CSdef\hl.exe:*:Enabled:Half-Life Launcher"
"C:\WINDOWS\system32\java.exe"="C:\WINDOWS\system32\java.exe:*:Enabled:Java(TM) Platform SE binary"
"G:\Games\dsadas\hltv.exe"="G:\Games\dsadas\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"D:\Program Files\Java\jre6\bin\javaw.exe"="D:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"G:\Programy\bitlord\BitLord.exe"="G:\Programy\bitlord\BitLord.exe:*:Enabled:BitLord"
"G:\Programy\Update Service\Update Service.exe"="G:\Programy\Update Service\Update Service.exe:*:Enabled:Update Service"
"D:\Hry\cs\Steam.exe"="D:\Hry\cs\Steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe"="C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"G:\Games\dsadas\hl.exe"="G:\Games\dsadas\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Documents and Settings\heRoo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe"="C:\Documents and Settings\heRoo\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player"
"C:\Program Files\Mineserver Project\Mineserver\mineserver.exe"="C:\Program Files\Mineserver Project\Mineserver\mineserver.exe:*:Enabled:mineserver"
"G:\Games\AoE2\age2_x1\age2_x1.exe"="G:\Games\AoE2\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"G:\Games\Age Of Empires II Conquerors\age2_x1\age2_x1.exe"="G:\Games\Age Of Empires II Conquerors\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"G:\Games\StarCraft II\StarCraft II.exe"="G:\Games\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"G:\Games\StarCraft II\Versions\Base15405\SC2.exe"="G:\Games\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"G:\Games\LoL\air\LolClient.exe"="G:\Games\LoL\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"G:\Games\LoL\game\League of Legends.exe"="G:\Games\LoL\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"D:\Program Files\Garena\Garena.exe"="D:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\cs\steamapps\heroo16\source sdk base 2007\hl2.exe"="D:\Hry\cs\steamapps\heroo16\source sdk base 2007\hl2.exe:*:Enabled:hl2"
"C:\Program Files\NetMeeting\conf.exe"="C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®"
"C:\Program Files\Webteh\BSplayer\bsplayer.exe"="C:\Program Files\Webteh\BSplayer\bsplayer.exe:*:Enabled:BS.Player"
"C:\Program Files\gta2gh\gta2gh.exe"="C:\Program Files\gta2gh\gta2gh.exe:*:Enabled:gta2gh"
"G:\Programy\Media go\MediaGo.exe"="G:\Programy\Media go\MediaGo.exe:*:Enabled:Media Go"
"G:\Programy\xampp\xampp\FileZillaFTP\FileZilla Server.exe"="G:\Programy\xampp\xampp\FileZillaFTP\FileZilla Server.exe:*:Enabled:FileZilla Server"
"G:\Games\dsadas\hlds.exe"="G:\Games\dsadas\hlds.exe:*:Enabled:HLDS Launcher"
"G:\Games\CaC\Hra\ZH\game.dat"="G:\Games\CaC\Hra\ZH\game.dat:*:Enabled:game"
"C:\Program Files\Tunngle\TnglCtrl.exe"="C:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service"
"C:\Program Files\Tunngle\Tunngle.exe"="C:\Program Files\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"G:\Games\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe"="G:\Games\GTA IV\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club"
"G:\Games\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe"="G:\Games\GTA IV\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"E:\Warcraft III\Warcraft III\gproxy.exe"="E:\Warcraft III\Warcraft III\gproxy.exe:*:Enabled:gproxy"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Enabled:Garena"
"D:\Hry\cs\steamapps\heroo16\dedicated server\hltv.exe"="D:\Hry\cs\steamapps\heroo16\dedicated server\hltv.exe:*:Enabled:HLTV Launcher"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"D:\Hry\cs\steamapps\heroo16\half-life\hl.exe"="D:\Hry\cs\steamapps\heroo16\half-life\hl.exe:*:Enabled:Half-Life"
"C:\Program Files\EslWire\wire.exe"="C:\Program Files\EslWire\wire.exe:*:Enabled:ESL Wire Client"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer"
"D:\Hry\cs\steamapps\heroo16\dedicated server\hlds.exe"="D:\Hry\cs\steamapps\heroo16\dedicated server\hlds.exe:*:Enabled:Dedicated Server"
"G:\Games\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"="G:\Games\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader"
"D:\Hry\cs\steamapps\heroo16\counter-strike\hl.exe"="D:\Hry\cs\steamapps\heroo16\counter-strike\hl.exe:*:Enabled:Counter-Strike"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"VIDC.WMV3"=wmv9vcm.dll
"vidc.VP60"=C:\WINDOWS\System32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\System32\vp6vfw.dll
"vidc.iv50"=ir50_32.dll
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"VIDC.IV41"=IR41_32.AX
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======List of files/folders created in the last 1 month======
2011-09-15 13:28:56 ----A---- C:\WINDOWS\system32\OLD17A.tmp
2011-09-15 13:28:56 ----A---- C:\WINDOWS\system32\OLD177.tmp
2011-09-15 13:28:56 ----A---- C:\WINDOWS\system32\OLD174.tmp
2011-09-15 11:28:29 ----A---- C:\WINDOWS\OLD6E.tmp
2011-09-15 11:26:21 ----D---- C:\WINDOWS\LastGood
2011-09-12 21:26:53 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2011-09-12 21:26:38 ----D---- C:\WINDOWS\system32\Data
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\VDLL.DLL
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\system32\runouce.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\rundll16.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\RUNDL132.EXE
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\logo1_.exe
2011-09-12 15:17:20 ----AD---- C:\WINDOWS\logo_1.exe
2011-09-12 15:10:02 ----A---- C:\WINDOWS\system32\msvcr80.dll
2011-09-12 15:10:01 ----A---- C:\WINDOWS\system32\msvcp80.dll
2011-09-12 15:10:00 ----A---- C:\WINDOWS\system32\eEmpty.exe
2011-09-12 15:09:57 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\system32\T.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\REGEDIT.COM
2011-09-12 15:09:57 ----A---- C:\WINDOWS\R.COM
2011-09-12 15:09:55 ----D---- C:\Program Files\Common Files\MicroWorld
2011-09-12 15:09:48 ----D---- C:\Documents and Settings\All Users\Application Data\MicroWorld
2011-09-11 13:44:11 ----D---- C:\Documents and Settings\heRoo\Application Data\Download Manager
2011-09-04 01:07:59 ----A---- C:\Program Files\Common Files\WireHelpSvc.exe
2011-09-04 01:07:55 ----A---- C:\WINDOWS\system32\drivers\ESLWireACD.sys
2011-09-04 01:07:48 ----A---- C:\WINDOWS\system32\drivers\ESLvnic.sys
2011-09-04 01:07:47 ----D---- C:\Program Files\EslWire
2011-09-04 01:07:47 ----D---- C:\Documents and Settings\All Users\Application Data\ESL Wire
2011-08-28 23:31:55 ----D---- C:\Program Files\PHLTV
2011-08-22 02:46:16 ----D---- C:\Program Files\Windows MultiPoint Mouse SDK
2011-08-22 02:24:09 ----A---- C:\WINDOWS\system32\cpnmouse.sys
2011-08-22 02:21:41 ----A---- C:\WINDOWS\system32\drivers\cpnmouse.sys
2011-08-21 16:01:23 ----D---- C:\Program Files\MeeSoft
2011-08-20 11:26:04 ----D---- C:\Program Files\Presentation Assistant
2011-08-20 11:26:04 ----D---- C:\Documents and Settings\heRoo\Application Data\Presentation Assistant
2011-08-19 19:19:54 ----D---- C:\Documents and Settings\heRoo\Application Data\Grasssoft
2011-08-19 19:19:48 ----D---- C:\Documents and Settings\All Users\Application Data\Grasssoft
2011-08-19 19:19:40 ----D---- C:\Program Files\GrassSoft
2011-08-19 13:40:52 ----D---- C:\.jagex_cache_32
======List of files/folders modified in the last 1 month======
2011-09-15 16:42:48 ----D---- C:\Program Files\trend micro
2011-09-15 16:25:07 ----D---- C:\Documents and Settings\heRoo\Application Data\HLSW
2011-09-15 16:01:00 ----D---- C:\WINDOWS\Temp
2011-09-15 13:39:03 ----D---- C:\WINDOWS\system32\wbem
2011-09-15 13:38:03 ----D---- C:\WINDOWS\system32\usmt
2011-09-15 13:37:01 ----D---- C:\WINDOWS\system32\Restore
2011-09-15 13:36:00 ----D---- C:\WINDOWS\system32\npp
2011-09-15 13:33:57 ----D---- C:\WINDOWS\system32\Com
2011-09-15 13:32:56 ----D---- C:\WINDOWS\system32
2011-09-15 13:29:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-09-15 12:20:30 ----D---- C:\WINDOWS\msagent
2011-09-15 11:28:29 ----D---- C:\WINDOWS
2011-09-15 11:25:20 ----D---- C:\Program Files\Windows NT
2011-09-15 11:18:10 ----D---- C:\Program Files\Outlook Express
2011-09-15 11:17:08 ----D---- C:\Program Files\NetMeeting
2011-09-15 11:14:06 ----D---- C:\Program Files\Movie Maker
2011-09-15 10:59:16 ----D---- C:\Program Files\Internet Explorer
2011-09-15 10:41:00 ----D---- C:\WINDOWS\system32\CatRoot2
2011-09-15 10:34:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-09-15 10:30:20 ----D---- C:\WINDOWS\Internet Logs
2011-09-15 01:43:22 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-09-12 21:27:45 ----D---- C:\Program Files\Creative
2011-09-12 21:26:53 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2011-09-12 21:26:49 ----D---- C:\WINDOWS\system32\drivers
2011-09-12 21:26:44 ----HD---- C:\WINDOWS\inf
2011-09-12 21:26:43 ----D---- C:\WINDOWS\system32\ReinstallBackups
2011-09-12 21:26:19 ----HD---- C:\Program Files\InstallShield Installation Information
2011-09-12 21:26:10 ----D---- C:\Documents and Settings\heRoo\Application Data\Skype
2011-09-12 20:57:47 ----D---- C:\WINDOWS\Prefetch
2011-09-12 15:21:11 ----A---- C:\WINDOWS\system32\xpsp1hfm.exe
2011-09-12 15:21:04 ----A---- C:\WINDOWS\system32\xcopy.exe
2011-09-12 15:21:03 ----A---- C:\WINDOWS\system32\WudfHost.exe
2011-09-12 15:21:02 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2011-09-12 15:21:02 ----A---- C:\WINDOWS\system32\wuauclt.exe
2011-09-12 15:21:01 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2011-09-12 15:21:00 ----A---- C:\WINDOWS\system32\wpdshextautoplay.exe
2011-09-12 15:21:00 ----A---- C:\WINDOWS\system32\wpabaln.exe
2011-09-12 15:20:56 ----A---- C:\WINDOWS\system32\winver.exe
2011-09-12 15:20:55 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2011-09-12 15:20:54 ----A---- C:\WINDOWS\system32\wextract.exe
2011-09-12 15:20:54 ----A---- C:\WINDOWS\system32\wdfmgr.exe
2011-09-12 15:20:53 ----A---- C:\WINDOWS\system32\verclsid.exe
2011-09-12 15:20:52 ----A---- C:\WINDOWS\system32\uwdf.exe
2011-09-12 15:20:52 ----A---- C:\WINDOWS\system32\utilman.exe
2011-09-12 15:20:49 ----A---- C:\WINDOWS\system32\upnpcont.exe
2011-09-12 15:20:49 ----A---- C:\WINDOWS\system32\tzchange.exe
2011-09-12 15:20:48 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2011-09-12 15:20:48 ----A---- C:\WINDOWS\system32\tracert.exe
2011-09-12 15:20:48 ----A---- C:\WINDOWS\system32\tracerpt.exe
2011-09-12 15:20:47 ----A---- C:\WINDOWS\system32\tourstart.exe
2011-09-12 15:20:46 ----A---- C:\WINDOWS\system32\tlntsess.exe
2011-09-12 15:20:46 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2011-09-12 15:20:46 ----A---- C:\WINDOWS\system32\telnet.exe
2011-09-12 15:20:45 ----A---- C:\WINDOWS\system32\taskmgr.exe
2011-09-12 15:20:44 ----A---- C:\WINDOWS\system32\tasklist.exe
2011-09-12 15:20:44 ----A---- C:\WINDOWS\system32\taskkill.exe
2011-09-12 15:20:43 ----A---- C:\WINDOWS\system32\systeminfo.exe
2011-09-12 15:20:42 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2011-09-12 15:20:41 ----A---- C:\WINDOWS\system32\stimon.exe
2011-09-12 15:20:34 ----A---- C:\WINDOWS\system32\spupdwxp.exe
2011-09-12 15:20:34 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2011-09-12 15:20:33 ----A---- C:\WINDOWS\system32\spnpinst.exe
2011-09-12 15:20:33 ----A---- C:\WINDOWS\system32\spiisupd.exe
2011-09-12 15:20:33 ----A---- C:\WINDOWS\system32\spider.exe
2011-09-12 15:20:32 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
2011-09-12 15:20:32 ----A---- C:\WINDOWS\system32\sort.exe
2011-09-12 15:20:31 ----A---- C:\WINDOWS\system32\sndrec32.exe
2011-09-12 15:20:30 ----A---- C:\WINDOWS\system32\smbinst.exe
2011-09-12 15:20:30 ----A---- C:\WINDOWS\system32\slserv.exe
2011-09-12 15:20:30 ----A---- C:\WINDOWS\system32\slrundll.exe
2011-09-12 15:20:29 ----A---- C:\WINDOWS\system32\skeys.exe
2011-09-12 15:20:29 ----A---- C:\WINDOWS\system32\sigverif.exe
2011-09-12 15:20:29 ----A---- C:\WINDOWS\system32\shutdown.exe
2011-09-12 15:20:28 ----A---- C:\WINDOWS\system32\shrpubw.exe
2011-09-12 15:20:27 ----A---- C:\WINDOWS\system32\setupn.exe
2011-09-12 15:20:27 ----A---- C:\WINDOWS\system32\setup.exe
2011-09-12 15:20:26 ----A---- C:\WINDOWS\system32\sethc.exe
2011-09-12 15:20:26 ----A---- C:\WINDOWS\system32\secedit.exe
2011-09-12 15:20:25 ----A---- C:\WINDOWS\system32\sdbinst.exe
2011-09-12 15:20:24 ----A---- C:\WINDOWS\system32\schtasks.exe
2011-09-12 15:20:23 ----A---- C:\WINDOWS\system32\savedump.exe
2011-09-12 15:20:22 ----A---- C:\WINDOWS\system32\runonce.exe
2011-09-12 15:20:22 ----A---- C:\WINDOWS\system32\rtcshare.exe
2011-09-12 15:20:21 ----A---- C:\WINDOWS\system32\rsnotify.exe
2011-09-12 15:20:20 ----A---- C:\WINDOWS\system32\rsh.exe
2011-09-12 15:20:20 ----A---- C:\WINDOWS\system32\rexec.exe
2011-09-12 15:20:20 ----A---- C:\WINDOWS\system32\reg.exe
2011-09-12 15:20:19 ----A---- C:\WINDOWS\system32\rdshost.exe
2011-09-12 15:20:19 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2011-09-12 15:20:19 ----A---- C:\WINDOWS\system32\rdpclip.exe
2011-09-12 15:20:18 ----A---- C:\WINDOWS\system32\rcp.exe
2011-09-12 15:20:18 ----A---- C:\WINDOWS\system32\rcimlby.exe
2011-09-12 15:20:17 ----A---- C:\WINDOWS\system32\rasphone.exe
2011-09-12 15:20:16 ----A---- C:\WINDOWS\system32\qprocess.exe
2011-09-12 15:20:16 ----A---- C:\WINDOWS\system32\proxycfg.exe
2011-09-12 15:20:15 ----A---- C:\WINDOWS\system32\proquota.exe
2011-09-12 15:20:15 ----A---- C:\WINDOWS\system32\PresentationHost.exe
2011-09-12 15:20:14 ----A---- C:\WINDOWS\system32\powercfg.exe
2011-09-12 15:20:13 ----A---- C:\WINDOWS\system32\perfmon.exe
2011-09-12 15:20:12 ----A---- C:\WINDOWS\system32\packager.exe
2011-09-12 15:20:12 ----A---- C:\WINDOWS\system32\osk.exe
2011-09-12 15:20:11 ----A---- C:\WINDOWS\system32\openfiles.exe
2011-09-12 15:20:09 ----A---- C:\WINDOWS\system32\odbcconf.exe
2011-09-12 15:20:08 ----RA---- C:\WINDOWS\system32\nvusmu.exe
2011-09-12 15:20:08 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2011-09-12 15:20:08 ----A---- C:\WINDOWS\system32\odbcad32.exe
2011-09-12 15:20:08 ----A---- C:\WINDOWS\system32\nvunrm.exe
2011-09-12 15:20:07 ----RA---- C:\WINDOWS\system32\NVUNINST.EXE
2011-09-12 15:20:06 ----A---- C:\WINDOWS\system32\ntbackup.exe
2011-09-12 15:20:06 ----A---- C:\WINDOWS\system32\nslookup.exe
2011-09-12 15:20:05 ----A---- C:\WINDOWS\system32\notepad.exe
2011-09-12 15:20:05 ----A---- C:\WINDOWS\system32\netstat.exe
2011-09-12 15:20:05 ----A---- C:\WINDOWS\system32\netsh.exe
2011-09-12 15:20:04 ----A---- C:\WINDOWS\system32\netsetup.exe
2011-09-12 15:20:04 ----A---- C:\WINDOWS\system32\net1.exe
2011-09-12 15:20:03 ----A---- C:\WINDOWS\system32\net.exe
2011-09-12 15:20:03 ----A---- C:\WINDOWS\system32\nddeapir.exe
2011-09-12 15:20:03 ----A---- C:\WINDOWS\system32\narrator.exe
2011-09-12 15:20:02 ----A---- C:\WINDOWS\system32\napstat.exe
2011-09-12 15:20:00 ----A---- C:\WINDOWS\system32\mstsc.exe
2011-09-12 15:19:59 ----A---- C:\WINDOWS\system32\mstinit.exe
2011-09-12 15:19:56 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2011-09-12 15:19:54 ----A---- C:\WINDOWS\system32\mqbkup.exe
2011-09-12 15:19:54 ----A---- C:\WINDOWS\system32\mobsync.exe
2011-09-12 15:19:53 ----A---- C:\WINDOWS\system32\mmcperf.exe
2011-09-12 15:19:53 ----A---- C:\WINDOWS\system32\mmc.exe
2011-09-12 15:19:52 ----A---- C:\WINDOWS\system32\migpwd.exe
2011-09-12 15:19:50 ----A---- C:\WINDOWS\system32\makecab.exe
2011-09-12 15:19:50 ----A---- C:\WINDOWS\system32\magnify.exe
2011-09-12 15:19:50 ----A---- C:\WINDOWS\system32\logonui.exe
2011-09-12 15:19:49 ----A---- C:\WINDOWS\system32\logman.exe
2011-09-12 15:19:47 ----A---- C:\WINDOWS\system32\javaws.exe
2011-09-12 15:19:46 ----A---- C:\WINDOWS\system32\javaw.exe
2011-09-12 15:19:46 ----A---- C:\WINDOWS\system32\java.exe
2011-09-12 15:19:44 ----A---- C:\WINDOWS\system32\ipxroute.exe
2011-09-12 15:19:44 ----A---- C:\WINDOWS\system32\ipv6.exe
2011-09-12 15:19:43 ----A---- C:\WINDOWS\system32\ipconfig.exe
2011-09-12 15:19:41 ----A---- C:\WINDOWS\system32\iexpress.exe
2011-09-12 15:19:41 ----A---- C:\WINDOWS\system32\icardagt.exe
2011-09-12 15:19:39 ----A---- C:\WINDOWS\system32\help.exe
2011-09-12 15:19:39 ----A---- C:\WINDOWS\system32\grpconv.exe
2011-09-12 15:19:39 ----A---- C:\WINDOWS\system32\gpresult.exe
2011-09-12 15:19:38 ----A---- C:\WINDOWS\system32\getmac.exe
2011-09-12 15:19:38 ----A---- C:\WINDOWS\system32\ftp.exe
2011-09-12 15:19:37 ----A---- C:\WINDOWS\system32\fsquirt.exe
2011-09-12 15:19:37 ----A---- C:\WINDOWS\system32\forcedos.exe
2011-09-12 15:19:37 ----A---- C:\WINDOWS\system32\fontview.exe
2011-09-12 15:19:36 ----A---- C:\WINDOWS\system32\fltmc.exe
2011-09-12 15:19:36 ----A---- C:\WINDOWS\system32\findstr.exe
2011-09-12 15:19:35 ----A---- C:\WINDOWS\system32\faxpatch.exe
2011-09-12 15:19:35 ----A---- C:\WINDOWS\system32\extrac32.exe
2011-09-12 15:19:35 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2011-09-12 15:19:34 ----A---- C:\WINDOWS\system32\eventcreate.exe
2011-09-12 15:19:34 ----A---- C:\WINDOWS\system32\eudcedit.exe
2011-09-12 15:19:33 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2011-09-12 15:19:32 ----A---- C:\WINDOWS\system32\dxdiag.exe
2011-09-12 15:19:31 ----A---- C:\WINDOWS\system32\dwwin.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\dvdplay.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\dumprep.exe
2011-09-12 15:19:30 ----A---- C:\WINDOWS\system32\drmupgds.exe
2011-09-12 15:19:29 ----A---- C:\WINDOWS\system32\driverquery.exe
2011-09-12 15:19:29 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2011-09-12 15:19:29 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2011-09-12 15:19:28 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2011-09-12 15:19:28 ----A---- C:\WINDOWS\system32\dns-sd.exe
2011-09-12 15:19:28 ----A---- C:\WINDOWS\system32\dmremote.exe
2011-09-12 15:19:27 ----A---- C:\WINDOWS\system32\diskpart.exe
2011-09-12 15:19:27 ----A---- C:\WINDOWS\system32\diantz.exe
2011-09-12 15:19:27 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\defrag.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\ddeshare.exe
2011-09-12 15:19:26 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2011-09-12 15:19:16 ----A---- C:\WINDOWS\system32\ctfmon.exe
2011-09-12 15:19:15 ----A---- C:\WINDOWS\system32\cscript.exe
2011-09-12 15:19:14 ----A---- C:\WINDOWS\system32\conime.exe
2011-09-12 15:19:14 ----A---- C:\WINDOWS\system32\comsdupd.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\cmstp.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\cmmon32.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\cmdl32.exe
2011-09-12 15:19:13 ----A---- C:\WINDOWS\system32\clipbrd.exe
2011-09-12 15:19:12 ----A---- C:\WINDOWS\system32\cliconfg.exe
2011-09-12 15:19:12 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2011-09-12 15:19:12 ----A---- C:\WINDOWS\system32\cipher.exe
2011-09-12 15:19:11 ----A---- C:\WINDOWS\system32\cacls.exe
2011-09-12 15:19:11 ----A---- C:\WINDOWS\system32\bootcfg.exe
2011-09-12 15:19:10 ----A---- C:\WINDOWS\system32\blastcln.exe
2011-09-12 15:19:09 ----A---- C:\WINDOWS\system32\auditusr.exe
2011-09-12 15:19:09 ----A---- C:\WINDOWS\system32\attrib.exe
2011-09-12 15:19:09 ----A---- C:\WINDOWS\system32\atmadm.exe
2011-09-12 15:19:04 ----A---- C:\WINDOWS\system32\ATIODE.exe
2011-09-12 15:19:03 ----A---- C:\WINDOWS\system32\ATIODCLI.exe
2011-09-12 15:19:03 ----A---- C:\WINDOWS\system32\atibtmon.exe
2011-09-12 15:19:03 ----A---- C:\WINDOWS\system32\atiapfxx.exe
2011-09-12 15:19:02 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2011-09-12 15:19:02 ----A---- C:\WINDOWS\system32\at.exe
2011-09-12 15:19:01 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2011-09-12 15:19:01 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2011-09-12 15:19:00 ----A---- C:\WINDOWS\system32\ahui.exe
2011-09-12 15:18:58 ----A---- C:\WINDOWS\system32\actmovie.exe
2011-09-12 15:18:58 ----A---- C:\WINDOWS\system32\AcSignOpt.exe
2011-09-12 15:18:57 ----A---- C:\WINDOWS\system32\accwiz.exe
2011-09-12 15:18:55 ----A---- C:\WINDOWS\winhlp32.exe
2011-09-12 15:18:54 ----A---- C:\WINDOWS\Updreg.EXE
2011-09-12 15:18:53 ----A---- C:\WINDOWS\ST5UNST.EXE
2011-09-12 15:18:53 ----A---- C:\WINDOWS\regedit.exe
2011-09-12 15:18:52 ----A---- C:\WINDOWS\P17DEF.EXE
2011-09-12 15:18:52 ----A---- C:\WINDOWS\notepad.exe
2011-09-12 15:18:51 ----A---- C:\WINDOWS\MIDIDEF.EXE
2011-09-12 15:18:51 ----A---- C:\WINDOWS\lsb_un20.exe
2011-09-12 15:18:50 ----A---- C:\WINDOWS\IsUninst.exe
2011-09-12 15:18:50 ----A---- C:\WINDOWS\hh.exe
2011-09-12 15:18:49 ----A---- C:\WINDOWS\Ctregrun.exe
2011-09-12 15:18:49 ----A---- C:\WINDOWS\ColorPic Uninstaller.exe
2011-09-12 15:18:46 ----D---- C:\Program Files\Cheat Engine
2011-09-12 15:17:18 ----A---- C:\WINDOWS\system32\vssvc.exe
2011-09-12 15:17:16 ----A---- C:\WINDOWS\system32\ups.exe
2011-09-12 15:17:16 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2011-09-12 15:17:16 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2011-09-12 15:17:15 ----A---- C:\WINDOWS\system32\scardsvr.exe
2011-09-12 15:17:14 ----A---- C:\WINDOWS\system32\locator.exe
2011-09-12 15:17:13 ----A---- C:\WINDOWS\system32\sessmgr.exe
2011-09-12 15:17:12 ----A---- C:\WINDOWS\system32\netdde.exe
2011-09-12 15:17:12 ----A---- C:\WINDOWS\system32\msdtc.exe
2011-09-12 15:17:12 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2011-09-12 15:17:11 ----A---- C:\WINDOWS\system32\imapi.exe
2011-09-12 15:17:09 ----A---- C:\WINDOWS\system32\dmadmin.exe
2011-09-12 15:17:08 ----A---- C:\WINDOWS\system32\dllhost.exe
2011-09-12 15:17:08 ----A---- C:\WINDOWS\system32\clipsrv.exe
2011-09-12 15:17:08 ----A---- C:\WINDOWS\system32\cisvc.exe
2011-09-12 15:16:53 ----A---- C:\WINDOWS\system32\wscript.exe
2011-09-12 15:16:52 ----A---- C:\WINDOWS\system32\mshta.exe
2011-09-12 15:16:49 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2011-09-12 15:16:48 ----A---- C:\WINDOWS\system32\shmgrate.exe
2011-09-12 15:16:48 ----A---- C:\WINDOWS\system32\regsvr32.exe
2011-09-12 15:16:47 ----A---- C:\WINDOWS\system32\ntvdm.exe
2011-09-12 15:16:45 ----A---- C:\WINDOWS\system32\userinit.exe
2011-09-12 15:16:40 ----A---- C:\WINDOWS\system32\mspaint.exe
2011-09-12 15:09:55 ----D---- C:\Program Files\Common Files
2011-09-11 14:10:16 ----ASH---- C:\boot.ini
2011-09-11 11:46:02 ----D---- C:\WINDOWS\mui
2011-09-09 17:56:33 ----SHD---- C:\WINDOWS\Installer
2011-09-08 23:18:05 ----SD---- C:\WINDOWS\Tasks
2011-09-07 18:29:15 ----D---- C:\Program Files\Mozilla Firefox
2011-09-04 01:07:47 ----RD---- C:\Program Files
2011-08-26 22:49:50 ----A---- C:\Documents and Settings\heRoo\Application Data\myMPQ.ini
2011-08-22 02:46:27 ----RSD---- C:\WINDOWS\assembly
2011-08-22 02:43:55 ----D---- C:\WINDOWS\SoftwareDistribution
2011-08-22 00:50:57 ----D---- C:\WINDOWS\.jagex_cache_32
2011-08-19 19:19:55 ----RSD---- C:\WINDOWS\Fonts
2011-08-19 19:19:42 ----D---- C:\Documents and Settings\heRoo\Application Data\GetRightToGo
2011-08-18 03:21:53 ----D---- C:\Program Files\AMX Mod X
2011-08-16 02:55:28 ----D---- C:\Documents and Settings\heRoo\Application Data\mIRC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-06-17 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 ISODrive;ISO CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2002-09-16 4228]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2010-05-13 532224]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 ESLWireAC;ESLWireAC; \??\C:\WINDOWS\system32\drivers\ESLWireACD.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2010-08-04 5243392]
R3 BTCAMDRV;Mobiola Web Camera driver; C:\WINDOWS\system32\DRIVERS\BTCamDrv.sys [2006-11-01 219264]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\DRIVERS\ctsfm2k.sys [2005-01-10 138752]
R3 DCamUSBSQTECH;Dual-Mode DSC(2770); C:\WINDOWS\System32\Drivers\SQcaptur.sys [2003-01-10 30921]
R3 ESLvnic1;ESLvnic Virtual Network 32 Bit; C:\WINDOWS\system32\DRIVERS\ESLvnic.sys [2011-08-03 24504]
R3 gbridge;Gbridge Virtual Miniport; C:\WINDOWS\system32\DRIVERS\gbridge.sys [2009-05-10 41216]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2007-11-17 54016]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2007-11-17 22016]
R3 nvsmu;nvsmu; C:\WINDOWS\System32\DRIVERS\nvsmu.sys [2007-10-12 13312]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\System32\DRIVERS\ctoss2k.sys [2005-01-10 106496]
R3 P17;SB Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2007-06-15 1127936]
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\System32\DRIVERS\point32.sys [2007-08-21 21760]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\WINDOWS\system32\DRIVERS\seehcri.sys [2010-08-22 27632]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\WINDOWS\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 au08znq6;au08znq6; C:\WINDOWS\system32\drivers\au08znq6.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpnmouse;cpnmouse; C:\WINDOWS\system32\DRIVERS\cpnmouse.sys [2003-11-28 5162]
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2010-08-22 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2010-08-22 25512]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\WINDOWS\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\WINDOWS\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\WINDOWS\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 s1039bus;Sony Ericsson Device 1039 driver (WDM); C:\WINDOWS\system32\DRIVERS\s1039bus.sys [2009-11-19 98672]
S3 s1039mdfl;Sony Ericsson Device 1039 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s1039mdfl.sys [2009-11-19 14960]
S3 s1039mdm;Sony Ericsson Device 1039 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s1039mdm.sys [2009-11-19 124016]
S3 s1039mgmt;Sony Ericsson Device 1039 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s1039mgmt.sys [2009-11-19 117872]
S3 s1039nd5;Sony Ericsson Device 1039 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\s1039nd5.sys [2009-11-19 25456]
S3 s1039obex;Sony Ericsson Device 1039 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s1039obex.sys [2009-11-19 113904]
S3 s1039unic;Sony Ericsson Device 1039 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\s1039unic.sys [2009-11-19 123504]
S3 se32;EnTech softEngine; C:\WINDOWS\system32\drivers\se32.sys [2007-05-03 12112]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\System32\DRIVERS\VBoxNetAdp.sys [2010-02-12 99152]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-08-04 606208]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-05-16 153376]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2010-11-22 718072]
R2 WireHelpSvc;WireHelpSvc; C:\Program Files\Common Files\WireHelpSvc.exe [2011-08-03 265120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2011-09-12 308186]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-12 313818]
S2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2011-09-12 2613722]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2011-09-12 212950]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2011-09-12 255958]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-09-12 832474]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-09-12 313818]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2011-09-12 1062368]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2011-09-12 931296]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2011-09-12 247252]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------