avg chce něco přesunovat do antivirového trezoru
Napsal: 20 lis 2011 07:56
avg chce přesunout cosi do antiviroveho trezoru. Je to ale zamčené v program files. nejde to smáznout. vůbec nevím kde se to vzalo vkládám obsah logu:
Logfile of random's system information tool 1.09 (written by random/random)
Run by vydla at 2011-11-20 07:48:00
Microsoft Windows 7 Ultimate
System drive C: has 61 GB (61%) free of 100 GB
Total RAM: 4094 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:49:04, on 20.11.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lightscreen\lightscreen.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\vydla.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKCU\..\Run: [Lightscreen] C:\Program Files (x86)\Lightscreen\lightscreen.exe -h
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = ?
O4 - Startup: OpenOffice.org 3.3.lnk = ?
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - D:\xampp\filezillaftp\filezillaserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RelevantKnowledge - TMRG, Inc. - C:\Program Files (x86)\RelevantKnowledge\rlservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 7615 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe /pipeName=82d2e570-8efd-4112-828a-971a43928246 /coreSdkOptions=286 /logConfFile="C:\ProgramData\AVG2012\temp\1b17c370-7d86-4b6a-b544-9143f9f1f713-16c-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2012\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2012" /tempPath="C:\ProgramData\AVG2012\temp\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe"
"C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE"
"D:\xampp\filezillaftp\filezillaserver.exe"
"C:\Program Files (x86)\RelevantKnowledge\rlservice.exe" /service
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe"
"C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgemca.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Lightscreen\lightscreen.exe" -h
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
"C:\Program Files (x86)\MagicDisc\MagicDisc.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
C:\Windows\system32\SearchIndexer.exe /Embedding
"D:\Jagged Alliance 2 Gold\INI Editor.exe"
taskmgr.exe /3
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "E:\torrenty_hotovo\Best of Chillout 6CD+ Covers\Best of Chillout (cd1).mixed by The Jockster\The Jockster - Best Chillout - 13 - mother hetra.mp3"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1788.6bf95d0.355317596 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.8.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 1788 "\\.\pipe\gecko-crash-server-pipe.1788" plugin
"F:\mozilla\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\vydla\AppData\Roaming\Mozilla\Firefox\Profiles\9kmixbxx.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"
prefs.js - "keyword.URL" - "http://isearch.avg.com/search?cid=%7B8e ... &sap=ku&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69]
"Description"=6.0.12.69
"Path"=C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsJSRealPlayerPlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
npdeployJava1.dll
npdjvu.dll
nppl3260.dll
nprpjplug.dll
npwachk.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
esnips.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\vydla\AppData\Roaming\Mozilla\Firefox\Profiles\9kmixbxx.default\extensions\
avg@toolbar
C:\Users\vydla\AppData\Roaming\Mozilla\Firefox\Profiles\9kmixbxx.default\searchplugins\
avg-secure-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll [2011-11-11 1942368]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll [2011-11-11 1378144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll [2011-11-10 1451336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll [2011-11-10 1451336]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-11-02 11545192]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Lightscreen"=C:\Program Files (x86)\Lightscreen\lightscreen.exe [2010-03-17 563200]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-07-06 98304]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-07-11 74752]
"AVG_TRAY"=C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2011-10-24 2415456]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2011-11-02 218440]
C:\Users\vydla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MagicDisc.lnk - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
OpenOffice.org 3.3.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-11-20 07:48:00 ----D---- C:\rsit
2011-11-20 07:48:00 ----D---- C:\Program Files\trend micro
2011-11-19 19:36:52 ----HD---- C:\$AVG
2011-11-18 07:57:56 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-11-18 07:57:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-11-18 07:57:56 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-11-18 07:57:56 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-11-18 07:57:55 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-11-18 07:57:55 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-11-18 07:57:55 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-11-18 07:57:55 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-11-18 07:57:53 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-11-18 07:57:53 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-11-18 07:57:52 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-11-18 07:57:52 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-11-18 07:57:52 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-11-18 07:57:52 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-11-18 07:57:52 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-11-18 07:57:52 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-11-18 07:57:49 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-11-18 07:57:49 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-11-18 07:57:47 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-11-18 07:57:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-11-18 07:57:47 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-11-18 07:57:47 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-11-18 07:57:45 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-11-18 07:57:45 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-11-18 07:57:43 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-11-18 07:57:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-11-18 07:57:43 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-11-18 07:57:43 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-11-18 07:57:42 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-11-18 07:57:42 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-11-18 07:57:37 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-11-18 07:57:37 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-11-18 07:57:36 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-11-18 07:57:36 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-11-18 07:57:36 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-11-18 07:57:36 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-11-18 07:57:36 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-11-18 07:57:36 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-11-18 07:57:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-11-18 07:57:35 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-11-18 07:57:34 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-11-18 07:57:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-11-18 07:57:34 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-11-18 07:57:34 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-11-18 07:57:33 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-11-18 07:57:33 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-11-18 07:57:32 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-11-18 07:57:32 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-11-18 07:57:31 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-11-18 07:57:31 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-11-18 07:57:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-11-18 07:57:29 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-11-18 07:57:28 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-11-18 07:57:27 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-11-18 07:57:27 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-11-18 07:57:26 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-11-18 07:57:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-11-18 07:57:26 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-11-18 07:57:26 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-11-18 07:57:25 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-11-18 07:57:25 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-11-18 07:57:24 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-11-18 07:57:24 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-11-18 07:57:23 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-11-18 07:57:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-11-18 07:57:23 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-11-18 07:57:23 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-11-18 07:57:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-11-18 07:57:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-11-18 07:57:19 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-11-18 07:57:19 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-11-18 07:57:18 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-11-18 07:57:18 ----A---- C:\Windows\system32\xinput1_3.dll
2011-11-18 07:57:17 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-11-18 07:57:17 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-11-18 07:57:16 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-11-18 07:57:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-11-18 07:57:16 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-11-18 07:57:16 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-11-18 07:57:15 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-11-18 07:57:15 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-11-18 07:57:14 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-11-18 07:57:14 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-11-18 07:57:13 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-11-18 07:57:13 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-11-18 07:57:13 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-11-18 07:57:13 ----A---- C:\Windows\system32\d3dx10.dll
2011-11-18 07:57:12 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-11-18 07:57:12 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-11-18 07:57:11 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-11-18 07:57:11 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-11-18 07:57:11 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-11-18 07:57:11 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-11-18 07:57:10 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-11-18 07:57:10 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-11-18 07:57:09 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-11-18 07:57:09 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-11-18 07:57:09 ----A---- C:\Windows\system32\xinput1_2.dll
2011-11-18 07:57:09 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-11-18 07:57:08 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-11-18 07:57:08 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-11-18 07:57:06 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-11-18 07:57:06 ----A---- C:\Windows\system32\xinput1_1.dll
2011-11-18 07:57:05 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-11-18 07:57:05 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-11-18 07:56:53 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-11-18 07:56:53 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-11-18 07:56:51 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-11-18 07:56:51 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-11-18 07:56:51 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-11-18 07:56:51 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-11-18 07:56:50 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-11-18 07:56:50 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-11-18 07:56:44 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-11-18 07:56:44 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-11-18 07:56:42 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-11-18 07:56:42 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-11-18 07:56:41 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-11-18 07:56:41 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-11-18 07:56:40 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-11-18 07:56:40 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-11-18 07:56:39 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-11-18 07:56:39 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-11-17 08:31:54 ----D---- C:\Windows\system32\Macromed
2011-11-15 18:33:16 ----D---- C:\Program Files\Recuva
2011-11-15 18:32:20 ----D---- C:\Program Files (x86)\Google
2011-11-15 18:25:33 ----D---- C:\Program Files (x86)\Convar
2011-11-15 18:19:16 ----D---- C:\Program Files (x86)\File Scavenger 3.2
2011-11-04 09:51:47 ----D---- C:\Windows\SYSWOW64\drivers\AVG
2011-11-02 14:37:49 ----D---- C:\Program Files (x86)\AVG Secure Search
2011-11-02 14:37:18 ----D---- C:\Users\vydla\AppData\Roaming\AVG2012
2011-11-02 14:37:02 ----D---- C:\ProgramData\AVG2012
2011-10-29 22:52:06 ----D---- C:\Program Files (x86)\Jagged Alliance 2 Gold
2011-10-29 21:46:26 ----D---- C:\Users\vydla\AppData\Roaming\Logia
2011-10-29 21:46:26 ----D---- C:\Program Files (x86)\Logia
2011-10-29 18:46:48 ----N---- C:\Windows\Setup1.exe
2011-10-29 18:46:47 ----A---- C:\Windows\ST6UNST.EXE
2011-10-29 17:21:40 ----D---- C:\Program Files (x86)\jag_zaloh
2011-10-25 18:55:49 ----D---- C:\Program Files (x86)\Plus500
2011-10-22 19:40:56 ----D---- C:\Users\vydla\AppData\Roaming\GHISLER
2011-10-22 19:40:56 ----D---- C:\totalcmd
2011-10-22 19:40:56 ----A---- C:\Windows\UC.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\RAR.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\PKZIP.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\PKUNZIP.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\NOCLOSE.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\LHA.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\ARJ.PIF
======List of files/folders modified in the last 1 month======
2011-11-20 07:48:12 ----D---- C:\Windows\Prefetch
2011-11-20 07:48:00 ----RD---- C:\Program Files
2011-11-20 07:44:49 ----D---- C:\Windows\System32
2011-11-20 07:44:49 ----D---- C:\Windows\inf
2011-11-20 07:44:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-20 07:43:25 ----D---- C:\Program Files (x86)\RelevantKnowledge
2011-11-20 07:42:09 ----D---- C:\Windows\Temp
2011-11-20 07:40:26 ----RD---- C:\Program Files (x86)
2011-11-19 22:00:14 ----D---- C:\Users\vydla\AppData\Roaming\.purple
2011-11-19 17:29:43 ----D---- C:\ProgramData\MFAData
2011-11-19 17:29:39 ----D---- C:\Windows\system32\drivers\AVG
2011-11-18 22:49:41 ----D---- C:\Users\vydla\AppData\Roaming\uTorrent
2011-11-18 07:58:32 ----D---- C:\Windows\SysWOW64
2011-11-18 07:58:16 ----SHD---- C:\Windows\Installer
2011-11-18 07:57:05 ----RSD---- C:\Windows\assembly
2011-11-15 18:32:29 ----D---- C:\Windows\Tasks
2011-11-15 18:32:29 ----D---- C:\Windows\system32\Tasks
2011-11-14 17:31:46 ----SD---- C:\Users\vydla\AppData\Roaming\Microsoft
2011-11-14 00:55:05 ----D---- C:\Users\vydla\AppData\Roaming\dvdcss
2011-11-12 21:07:00 ----D---- C:\Users\vydla\AppData\Roaming\gtk-2.0
2011-11-12 14:06:34 ----D---- C:\Windows\system32\catroot2
2011-11-10 15:34:00 ----D---- C:\Program Files (x86)\Common Files
2011-11-09 15:54:21 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-11-04 18:46:56 ----D---- C:\Windows\system32\NDF
2011-11-04 09:52:32 ----D---- C:\Windows\system32\drivers
2011-11-04 09:51:47 ----D---- C:\Windows\SYSWOW64\drivers
2011-11-02 14:38:19 ----HD---- C:\ProgramData
2011-11-02 14:38:19 ----D---- C:\Program Files (x86)\AVG
2011-10-30 17:41:40 ----D---- C:\DOSBox-0.74
2011-10-29 18:48:08 ----D---- C:\Windows
2011-10-28 13:43:37 ----D---- C:\Windows\system32\drivers\UMDF
2011-10-23 17:16:58 ----D---- C:\Program Files (x86)\uTorrent
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2011-09-13 37456]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2011-10-07 283728]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2011-08-08 46672]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2011-07-11 375376]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-07-07 7195648]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-07-07 265728]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 120400]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 29776]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-01-26 39808]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-01-26 64256]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-11-20 25640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-11-02 2536040]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2009-02-24 255552]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-05-25 253728]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2011-07-15 30528]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-07-07 203264]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 FileZilla Server;FileZilla Server FTP server; D:\xampp\filezillaftp\filezillaserver.exe [2011-06-07 630272]
R2 RelevantKnowledge;RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe [2011-08-16 107136]
R2 vToolbarUpdater;vToolbarUpdater; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-11-02 246600]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-15 136176]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-15 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
jo a ještě jeden log tu je:
info.txt logfile of random's system information tool 1.09 2011-11-20 07:49:05
======Uninstall list======
@BIOS-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}\Setup.exe" -l0x9 -removeonly
µTorrent-->"C:\Program Files (x86)\uTorrent\uTorrent.exe" /UNINSTALL
7-Zip 9.20 (x64 edition)-->MsiExec.exe /I{23170F69-40C1-2702-0920-000001000000}
Adobe Flash Player 11 Plugin 64-bit-->C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_Plugin.exe -maintain plugin
ALO RM to MP3 Converter 7.0-->"C:\Program Files (x86)\Alo RM Converter\unins000.exe"
AMD Drag and Drop Transcoding-->MsiExec.exe /X{203DE003-C392-FF19-BCA2-3F775477BC94}
ATI AVIVO64 Codecs-->MsiExec.exe /X{33A49BF2-CB4F-5E54-D7F5-25502CAB6B70}
ATI Catalyst Install Manager-->msiexec /q/x{397878FC-1B1B-EED7-04A8-3184CE494A3B} REBOOT=ReallySuppress
Audio Recorder for Free v12.8.2-->"C:\Program Files (x86)\Audio Recorder for Free\unins000.exe"
AutoGreen B10.1021.1-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C75FAD21-EC08-42F3-92D6-C9C0AB355345}
AVG 2012-->"C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe" /AppMode=SETUP /Uninstall
AVG 2012-->MsiExec.exe /I{0B7465E2-1A7E-4D21-8670-94D9C11449B8}
AVG 2012-->MsiExec.exe /I{B639AFD8-48E9-49BC-88DF-C5C55A471D94}
AVG Security Toolbar-->C:\Program Files (x86)\AVG Secure Search\UNINSTALL.exe /UNINSTALL
Catalyst Control Center - Branding-->MsiExec.exe /I{87323561-58BA-4D5B-BADA-A791B69D1705}
Click to Call with Skype-->MsiExec.exe /I{B6CF2967-C81E-40C0-9815-C05774FEF120}
Document Express DjVu Plug-in-->MsiExec.exe /I{4B59576E-E748-415A-BAD4-7B5E2CFDE2D1}
Easy Tune 6 B11.0120.1-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{457D7505-D665-4F95-91C3-ECB8C56E9ACA}
EasySaver B9.1214.1 -->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{07300F01-89CA-4CF8-92BD-2A605EB83C95}\setup.exe" -l0x9 -removeonly
Etron USB3.0 Host Controller-->"C:\Program Files (x86)\InstallShield Installation Information\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}\SETUP.EXE" -runfromtemp -l0x0409 -removeonly
Etron USB3.0 Host Controller-->MsiExec.exe /I{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}
File Scavenger 3.2 (en)-->C:\Program Files (x86)\File Scavenger 3.2\FileScav.exe /uninstall
FLAC To MP3 V4.0.4-->"c:\FLAC To MP3\unins000.exe"
Foxit Reader-->C:\Program Files (x86)\Foxit Software\Foxit Reader\Uninstall.exe
Francesco's leveled creatures-items mod 4.5b-->"F:\fcom\data\Francesco's mod\Unistall data\Main files\unins000.exe"
Francesco's optional new items/creatures 4.5-->"F:\fcom\data\Francesco's mod\Unistall data\AddOns\unins000.exe"
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\Installer\setup.exe" --uninstall --multi-install --chrome --system-level --verbose-logging
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
GTA San Andreas-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
HydraVision-->MsiExec.exe /X{D5134D14-A38D-A217-4310-5C8B6DFA08D0}
Jagged Alliance 2 Gold-->D:\JAGGED~1\UNWISE.EXE D:\JAGGED~1\INSTALL.LOG
Lightscreen-->"C:\Program Files (x86)\Lightscreen\uninstall.exe"
Magic RM RAM to MP3 Converter 3.72-->"C:\Program Files (x86)\Magic RM to MP3 Converter\unins000.exe"
MagicDisc 2.7.106-->C:\PROGRA~2\MAGICD~1\UNWISE.EXE C:\PROGRA~2\MAGICD~1\INSTALL.LOG
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Mozilla Firefox 8.0 (x86 cs)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
Oblivion - Knights of the Nine-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{14C87AA7-08E6-419F-A165-998EBE5023D7}\setup.exe" -l0x9 -removeonly
Oblivion - Mehrunes Razor-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{EF295F5C-7B57-47AA-8889-6B3E8E214E89}\setup.exe" -l0x9 -removeonly
Oblivion - Spell Tomes-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{16D919E6-F019-4E15-BFBE-4A85EF19DA57}\setup.exe" -l0x9 -removeonly
Oblivion - Thieves Den-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{FFFFFD17-B460-41EB-93F1-C48ABAD63828}\setup.exe" -l0x9 -removeonly
Oblivion Face Exchange Lite-->MsiExec.exe /I{0DBEC4D5-2CCA-45CB-A529-75CD83E698AB}
Oblivion-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
ON_OFF Charge B11.0110.1-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{3DECD372-76A1-4483-BF10-B547790A3261}\setup.exe" -l0x9 -removeonly
OpenOffice.org 3.3-->MsiExec.exe /I{10B43A43-FF73-47FD-83E8-A503E84F9ED6}
PC Translator-->C:\Users\vydla\AppData\Local\Temp\UN32.EXE -UP
Pidgin-->C:\Program Files (x86)\Pidgin\pidgin-uninst.exe
Plus500-->C:\Program Files (x86)\Plus500\Plus500.exe /uninstall
Python 2.7 comtypes-0.6.2-->"C:\Python27\Removecomtypes.exe" -u "C:\Python27\comtypes-wininst.log"
Python 2.7 pywin32-216-->"C:\Python27\Removepywin32.exe" -u "C:\Python27\pywin32-wininst.log"
Python 2.7.2-->MsiExec.exe /I{2E295B5B-1AD4-4D36-97C2-A316084722CF}
Real Alternative 1.9.0 Lite-->"C:\Program Files (x86)\Real Alternative\unins000.exe"
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.Exe -runfromtemp -removeonly
Realtek HDMI Audio Driver for ATI-->C:\Program Files\Realtek\Audio\HDA\RtkUpd64.exe -k -m -nrg2709
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -removeonly
Recuva-->"C:\Program Files\Recuva\uninst.exe"
RelevantKnowledge-->C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe -bootremove -uninst:RelevantKnowledge
Skype™ 5.5-->MsiExec.exe /X{AA59DDE4-B672-4621-A016-4C248204957A}
TextMaker Viewer-->C:\Windows\unTMV.exe
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Visual Studio 2008 x64 Redistributables-->MsiExec.exe /I{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}
VLC media player 1.1.11-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Wrye Bash-->"C:\Program Files (x86)\Common Files\Wrye Bash\uninstall.exe"
wxPython 2.8.12.1 (ansi) for Python 2.6-->"C:\Python27\site-packages\wx-2.8-msw-ansi\unins000.exe"
wxPython 2.8.12.1 (ansi) for Python 2.7-->"C:\Python27\Lib\site-packages\wx-2.8-msw-ansi\unins000.exe"
XAMPP 1.7.7-->"D:\xampp\uninstall.exe"
======System event log======
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name inferno.demonoid.com timed out after none of the configured DNS servers responded.
Record Number: 32404
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111016071645.636003-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: vydla-PC
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom3.
Record Number: 32397
Source Name: cdrom
Time Written: 20111016051436.346197-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name www.seznamobchodu.cz timed out after none of the configured DNS servers responded.
Record Number: 32370
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111015113509.011348-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name www.h33t.com timed out after none of the configured DNS servers responded.
Record Number: 32187
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111014132119.620863-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name tracker.openbittorrent.com timed out after none of the configured DNS servers responded.
Record Number: 32123
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111013144726.791662-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
=====Application event log=====
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil . Error code = 0x80070002
Record Number: 104
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil . Error code = 0x80070002
Record Number: 103
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil . Error code = 0x80070002
Record Number: 102
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64 . Error code = 0x80070002
Record Number: 101
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1008
Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
Record Number: 92
Source Name: Microsoft-Windows-Search
Time Written: 20110713175038.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: 37L4247E29-32
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174019.554859-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174019.554859-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x2bd0b
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174019.336459-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174017.901256-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174017.870056-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=0503
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by vydla at 2011-11-20 07:48:00
Microsoft Windows 7 Ultimate
System drive C: has 61 GB (61%) free of 100 GB
Total RAM: 4094 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:49:04, on 20.11.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lightscreen\lightscreen.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\vydla.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKCU\..\Run: [Lightscreen] C:\Program Files (x86)\Lightscreen\lightscreen.exe -h
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = ?
O4 - Startup: OpenOffice.org 3.3.lnk = ?
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - D:\xampp\filezillaftp\filezillaserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RelevantKnowledge - TMRG, Inc. - C:\Program Files (x86)\RelevantKnowledge\rlservice.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 7615 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe /pipeName=82d2e570-8efd-4112-828a-971a43928246 /coreSdkOptions=286 /logConfFile="C:\ProgramData\AVG2012\temp\1b17c370-7d86-4b6a-b544-9143f9f1f713-16c-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2012\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2012" /tempPath="C:\ProgramData\AVG2012\temp\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
atieclxx
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe"
"C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE"
"D:\xampp\filezillaftp\filezillaserver.exe"
"C:\Program Files (x86)\RelevantKnowledge\rlservice.exe" /service
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe"
"C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2012\avgemca.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Lightscreen\lightscreen.exe" -h
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
"C:\Program Files (x86)\MagicDisc\MagicDisc.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
C:\Windows\system32\SearchIndexer.exe /Embedding
"D:\Jagged Alliance 2 Gold\INI Editor.exe"
taskmgr.exe /3
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "E:\torrenty_hotovo\Best of Chillout 6CD+ Covers\Best of Chillout (cd1).mixed by The Jockster\The Jockster - Best Chillout - 13 - mother hetra.mp3"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1788.6bf95d0.355317596 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.8.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 1788 "\\.\pipe\gecko-crash-server-pipe.1788" plugin
"F:\mozilla\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\vydla\AppData\Roaming\Mozilla\Firefox\Profiles\9kmixbxx.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "chrome://speeddial/content/speeddial.xul"
prefs.js - "keyword.URL" - "http://isearch.avg.com/search?cid=%7B8e ... &sap=ku&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69]
"Description"=6.0.12.69
"Path"=C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsJSRealPlayerPlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
npdeployJava1.dll
npdjvu.dll
nppl3260.dll
nprpjplug.dll
npwachk.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
esnips.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\vydla\AppData\Roaming\Mozilla\Firefox\Profiles\9kmixbxx.default\extensions\
avg@toolbar
C:\Users\vydla\AppData\Roaming\Mozilla\Firefox\Profiles\9kmixbxx.default\searchplugins\
avg-secure-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll [2011-11-11 1942368]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll [2011-11-11 1378144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll [2011-11-10 1451336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll [2011-11-10 1451336]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-11-02 11545192]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Lightscreen"=C:\Program Files (x86)\Lightscreen\lightscreen.exe [2010-03-17 563200]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-07-06 98304]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-07-11 74752]
"AVG_TRAY"=C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2011-10-24 2415456]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2011-11-02 218440]
C:\Users\vydla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MagicDisc.lnk - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
OpenOffice.org 3.3.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-11-20 07:48:00 ----D---- C:\rsit
2011-11-20 07:48:00 ----D---- C:\Program Files\trend micro
2011-11-19 19:36:52 ----HD---- C:\$AVG
2011-11-18 07:57:56 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2011-11-18 07:57:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2011-11-18 07:57:56 ----A---- C:\Windows\system32\XAudio2_6.dll
2011-11-18 07:57:56 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2011-11-18 07:57:55 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2011-11-18 07:57:55 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2011-11-18 07:57:55 ----A---- C:\Windows\system32\xactengine3_6.dll
2011-11-18 07:57:55 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2011-11-18 07:57:53 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-11-18 07:57:53 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-11-18 07:57:52 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2011-11-18 07:57:52 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2011-11-18 07:57:52 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2011-11-18 07:57:52 ----A---- C:\Windows\system32\xactengine3_5.dll
2011-11-18 07:57:52 ----A---- C:\Windows\system32\d3dcsx_42.dll
2011-11-18 07:57:52 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\system32\d3dx11_42.dll
2011-11-18 07:57:51 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-11-18 07:57:49 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2011-11-18 07:57:49 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-11-18 07:57:47 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2011-11-18 07:57:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2011-11-18 07:57:47 ----A---- C:\Windows\system32\d3dx10_41.dll
2011-11-18 07:57:47 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2011-11-18 07:57:45 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2011-11-18 07:57:45 ----A---- C:\Windows\system32\D3DX9_41.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\XAudio2_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\xactengine3_4.dll
2011-11-18 07:57:44 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2011-11-18 07:57:43 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2011-11-18 07:57:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2011-11-18 07:57:43 ----A---- C:\Windows\system32\d3dx10_40.dll
2011-11-18 07:57:43 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2011-11-18 07:57:42 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2011-11-18 07:57:42 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\XAudio2_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\xactengine3_3.dll
2011-11-18 07:57:40 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2011-11-18 07:57:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\XAudio2_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\xactengine3_2.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\d3dx10_39.dll
2011-11-18 07:57:38 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2011-11-18 07:57:37 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2011-11-18 07:57:37 ----A---- C:\Windows\system32\D3DX9_39.dll
2011-11-18 07:57:36 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2011-11-18 07:57:36 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2011-11-18 07:57:36 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2011-11-18 07:57:36 ----A---- C:\Windows\system32\XAudio2_1.dll
2011-11-18 07:57:36 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2011-11-18 07:57:36 ----A---- C:\Windows\system32\xactengine3_1.dll
2011-11-18 07:57:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2011-11-18 07:57:35 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2011-11-18 07:57:34 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2011-11-18 07:57:34 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2011-11-18 07:57:34 ----A---- C:\Windows\system32\d3dx10_38.dll
2011-11-18 07:57:34 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2011-11-18 07:57:33 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2011-11-18 07:57:33 ----A---- C:\Windows\system32\D3DX9_38.dll
2011-11-18 07:57:32 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2011-11-18 07:57:32 ----A---- C:\Windows\system32\XAudio2_0.dll
2011-11-18 07:57:31 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2011-11-18 07:57:31 ----A---- C:\Windows\system32\xactengine3_0.dll
2011-11-18 07:57:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2011-11-18 07:57:29 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2011-11-18 07:57:28 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\system32\D3DX9_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\system32\d3dx10_37.dll
2011-11-18 07:57:28 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2011-11-18 07:57:27 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2011-11-18 07:57:27 ----A---- C:\Windows\system32\xactengine2_10.dll
2011-11-18 07:57:26 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2011-11-18 07:57:26 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2011-11-18 07:57:26 ----A---- C:\Windows\system32\d3dx10_36.dll
2011-11-18 07:57:26 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2011-11-18 07:57:25 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2011-11-18 07:57:25 ----A---- C:\Windows\system32\d3dx9_36.dll
2011-11-18 07:57:24 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2011-11-18 07:57:24 ----A---- C:\Windows\system32\xactengine2_9.dll
2011-11-18 07:57:23 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2011-11-18 07:57:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2011-11-18 07:57:23 ----A---- C:\Windows\system32\d3dx10_35.dll
2011-11-18 07:57:23 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2011-11-18 07:57:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2011-11-18 07:57:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2011-11-18 07:57:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\xactengine2_8.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\d3dx10_34.dll
2011-11-18 07:57:20 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2011-11-18 07:57:19 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2011-11-18 07:57:19 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-11-18 07:57:18 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2011-11-18 07:57:18 ----A---- C:\Windows\system32\xinput1_3.dll
2011-11-18 07:57:17 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2011-11-18 07:57:17 ----A---- C:\Windows\system32\xactengine2_7.dll
2011-11-18 07:57:16 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2011-11-18 07:57:16 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2011-11-18 07:57:16 ----A---- C:\Windows\system32\d3dx10_33.dll
2011-11-18 07:57:16 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2011-11-18 07:57:15 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2011-11-18 07:57:15 ----A---- C:\Windows\system32\d3dx9_33.dll
2011-11-18 07:57:14 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2011-11-18 07:57:14 ----A---- C:\Windows\system32\xactengine2_6.dll
2011-11-18 07:57:13 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2011-11-18 07:57:13 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2011-11-18 07:57:13 ----A---- C:\Windows\system32\xactengine2_5.dll
2011-11-18 07:57:13 ----A---- C:\Windows\system32\d3dx10.dll
2011-11-18 07:57:12 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2011-11-18 07:57:12 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-11-18 07:57:11 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2011-11-18 07:57:11 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2011-11-18 07:57:11 ----A---- C:\Windows\system32\xactengine2_4.dll
2011-11-18 07:57:11 ----A---- C:\Windows\system32\x3daudio1_1.dll
2011-11-18 07:57:10 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2011-11-18 07:57:10 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-11-18 07:57:09 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2011-11-18 07:57:09 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2011-11-18 07:57:09 ----A---- C:\Windows\system32\xinput1_2.dll
2011-11-18 07:57:09 ----A---- C:\Windows\system32\xactengine2_3.dll
2011-11-18 07:57:08 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2011-11-18 07:57:08 ----A---- C:\Windows\system32\xactengine2_2.dll
2011-11-18 07:57:06 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2011-11-18 07:57:06 ----A---- C:\Windows\system32\xinput1_1.dll
2011-11-18 07:57:05 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2011-11-18 07:57:05 ----A---- C:\Windows\system32\xactengine2_1.dll
2011-11-18 07:56:53 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2011-11-18 07:56:53 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-11-18 07:56:51 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2011-11-18 07:56:51 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2011-11-18 07:56:51 ----A---- C:\Windows\system32\xactengine2_0.dll
2011-11-18 07:56:51 ----A---- C:\Windows\system32\x3daudio1_0.dll
2011-11-18 07:56:50 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2011-11-18 07:56:50 ----A---- C:\Windows\system32\d3dx9_29.dll
2011-11-18 07:56:44 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2011-11-18 07:56:44 ----A---- C:\Windows\system32\d3dx9_28.dll
2011-11-18 07:56:42 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2011-11-18 07:56:42 ----A---- C:\Windows\system32\d3dx9_27.dll
2011-11-18 07:56:41 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2011-11-18 07:56:41 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-11-18 07:56:40 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2011-11-18 07:56:40 ----A---- C:\Windows\system32\d3dx9_25.dll
2011-11-18 07:56:39 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2011-11-18 07:56:39 ----A---- C:\Windows\system32\d3dx9_24.dll
2011-11-17 08:31:54 ----D---- C:\Windows\system32\Macromed
2011-11-15 18:33:16 ----D---- C:\Program Files\Recuva
2011-11-15 18:32:20 ----D---- C:\Program Files (x86)\Google
2011-11-15 18:25:33 ----D---- C:\Program Files (x86)\Convar
2011-11-15 18:19:16 ----D---- C:\Program Files (x86)\File Scavenger 3.2
2011-11-04 09:51:47 ----D---- C:\Windows\SYSWOW64\drivers\AVG
2011-11-02 14:37:49 ----D---- C:\Program Files (x86)\AVG Secure Search
2011-11-02 14:37:18 ----D---- C:\Users\vydla\AppData\Roaming\AVG2012
2011-11-02 14:37:02 ----D---- C:\ProgramData\AVG2012
2011-10-29 22:52:06 ----D---- C:\Program Files (x86)\Jagged Alliance 2 Gold
2011-10-29 21:46:26 ----D---- C:\Users\vydla\AppData\Roaming\Logia
2011-10-29 21:46:26 ----D---- C:\Program Files (x86)\Logia
2011-10-29 18:46:48 ----N---- C:\Windows\Setup1.exe
2011-10-29 18:46:47 ----A---- C:\Windows\ST6UNST.EXE
2011-10-29 17:21:40 ----D---- C:\Program Files (x86)\jag_zaloh
2011-10-25 18:55:49 ----D---- C:\Program Files (x86)\Plus500
2011-10-22 19:40:56 ----D---- C:\Users\vydla\AppData\Roaming\GHISLER
2011-10-22 19:40:56 ----D---- C:\totalcmd
2011-10-22 19:40:56 ----A---- C:\Windows\UC.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\RAR.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\PKZIP.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\PKUNZIP.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\NOCLOSE.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\LHA.PIF
2011-10-22 19:40:56 ----A---- C:\Windows\ARJ.PIF
======List of files/folders modified in the last 1 month======
2011-11-20 07:48:12 ----D---- C:\Windows\Prefetch
2011-11-20 07:48:00 ----RD---- C:\Program Files
2011-11-20 07:44:49 ----D---- C:\Windows\System32
2011-11-20 07:44:49 ----D---- C:\Windows\inf
2011-11-20 07:44:49 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-20 07:43:25 ----D---- C:\Program Files (x86)\RelevantKnowledge
2011-11-20 07:42:09 ----D---- C:\Windows\Temp
2011-11-20 07:40:26 ----RD---- C:\Program Files (x86)
2011-11-19 22:00:14 ----D---- C:\Users\vydla\AppData\Roaming\.purple
2011-11-19 17:29:43 ----D---- C:\ProgramData\MFAData
2011-11-19 17:29:39 ----D---- C:\Windows\system32\drivers\AVG
2011-11-18 22:49:41 ----D---- C:\Users\vydla\AppData\Roaming\uTorrent
2011-11-18 07:58:32 ----D---- C:\Windows\SysWOW64
2011-11-18 07:58:16 ----SHD---- C:\Windows\Installer
2011-11-18 07:57:05 ----RSD---- C:\Windows\assembly
2011-11-15 18:32:29 ----D---- C:\Windows\Tasks
2011-11-15 18:32:29 ----D---- C:\Windows\system32\Tasks
2011-11-14 17:31:46 ----SD---- C:\Users\vydla\AppData\Roaming\Microsoft
2011-11-14 00:55:05 ----D---- C:\Users\vydla\AppData\Roaming\dvdcss
2011-11-12 21:07:00 ----D---- C:\Users\vydla\AppData\Roaming\gtk-2.0
2011-11-12 14:06:34 ----D---- C:\Windows\system32\catroot2
2011-11-10 15:34:00 ----D---- C:\Program Files (x86)\Common Files
2011-11-09 15:54:21 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-11-04 18:46:56 ----D---- C:\Windows\system32\NDF
2011-11-04 09:52:32 ----D---- C:\Windows\system32\drivers
2011-11-04 09:51:47 ----D---- C:\Windows\SYSWOW64\drivers
2011-11-02 14:38:19 ----HD---- C:\ProgramData
2011-11-02 14:38:19 ----D---- C:\Program Files (x86)\AVG
2011-10-30 17:41:40 ----D---- C:\DOSBox-0.74
2011-10-29 18:48:08 ----D---- C:\Windows
2011-10-28 13:43:37 ----D---- C:\Windows\system32\drivers\UMDF
2011-10-23 17:16:58 ----D---- C:\Program Files (x86)\uTorrent
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 26704]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2011-09-13 37456]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2011-10-07 283728]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2011-08-08 46672]
R1 Avgtdia;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdia.sys [2011-07-11 375376]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-07-07 7195648]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-07-07 265728]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 120400]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 29776]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-01-26 39808]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-01-26 64256]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-11-20 25640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-11-02 2536040]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2009-02-24 255552]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-05-25 253728]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-01-13 413800]
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2011-07-15 30528]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-07-07 203264]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 FileZilla Server;FileZilla Server FTP server; D:\xampp\filezillaftp\filezillaserver.exe [2011-06-07 630272]
R2 RelevantKnowledge;RelevantKnowledge; C:\Program Files (x86)\RelevantKnowledge\rlservice.exe [2011-08-16 107136]
R2 vToolbarUpdater;vToolbarUpdater; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [2011-11-02 246600]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-15 136176]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-15 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
-----------------EOF-----------------
jo a ještě jeden log tu je:
info.txt logfile of random's system information tool 1.09 2011-11-20 07:49:05
======Uninstall list======
@BIOS-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}\Setup.exe" -l0x9 -removeonly
µTorrent-->"C:\Program Files (x86)\uTorrent\uTorrent.exe" /UNINSTALL
7-Zip 9.20 (x64 edition)-->MsiExec.exe /I{23170F69-40C1-2702-0920-000001000000}
Adobe Flash Player 11 Plugin 64-bit-->C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_Plugin.exe -maintain plugin
ALO RM to MP3 Converter 7.0-->"C:\Program Files (x86)\Alo RM Converter\unins000.exe"
AMD Drag and Drop Transcoding-->MsiExec.exe /X{203DE003-C392-FF19-BCA2-3F775477BC94}
ATI AVIVO64 Codecs-->MsiExec.exe /X{33A49BF2-CB4F-5E54-D7F5-25502CAB6B70}
ATI Catalyst Install Manager-->msiexec /q/x{397878FC-1B1B-EED7-04A8-3184CE494A3B} REBOOT=ReallySuppress
Audio Recorder for Free v12.8.2-->"C:\Program Files (x86)\Audio Recorder for Free\unins000.exe"
AutoGreen B10.1021.1-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{C75FAD21-EC08-42F3-92D6-C9C0AB355345}
AVG 2012-->"C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe" /AppMode=SETUP /Uninstall
AVG 2012-->MsiExec.exe /I{0B7465E2-1A7E-4D21-8670-94D9C11449B8}
AVG 2012-->MsiExec.exe /I{B639AFD8-48E9-49BC-88DF-C5C55A471D94}
AVG Security Toolbar-->C:\Program Files (x86)\AVG Secure Search\UNINSTALL.exe /UNINSTALL
Catalyst Control Center - Branding-->MsiExec.exe /I{87323561-58BA-4D5B-BADA-A791B69D1705}
Click to Call with Skype-->MsiExec.exe /I{B6CF2967-C81E-40C0-9815-C05774FEF120}
Document Express DjVu Plug-in-->MsiExec.exe /I{4B59576E-E748-415A-BAD4-7B5E2CFDE2D1}
Easy Tune 6 B11.0120.1-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{457D7505-D665-4F95-91C3-ECB8C56E9ACA}
EasySaver B9.1214.1 -->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{07300F01-89CA-4CF8-92BD-2A605EB83C95}\setup.exe" -l0x9 -removeonly
Etron USB3.0 Host Controller-->"C:\Program Files (x86)\InstallShield Installation Information\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}\SETUP.EXE" -runfromtemp -l0x0409 -removeonly
Etron USB3.0 Host Controller-->MsiExec.exe /I{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}
File Scavenger 3.2 (en)-->C:\Program Files (x86)\File Scavenger 3.2\FileScav.exe /uninstall
FLAC To MP3 V4.0.4-->"c:\FLAC To MP3\unins000.exe"
Foxit Reader-->C:\Program Files (x86)\Foxit Software\Foxit Reader\Uninstall.exe
Francesco's leveled creatures-items mod 4.5b-->"F:\fcom\data\Francesco's mod\Unistall data\Main files\unins000.exe"
Francesco's optional new items/creatures 4.5-->"F:\fcom\data\Francesco's mod\Unistall data\AddOns\unins000.exe"
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\Installer\setup.exe" --uninstall --multi-install --chrome --system-level --verbose-logging
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
GTA San Andreas-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
HydraVision-->MsiExec.exe /X{D5134D14-A38D-A217-4310-5C8B6DFA08D0}
Jagged Alliance 2 Gold-->D:\JAGGED~1\UNWISE.EXE D:\JAGGED~1\INSTALL.LOG
Lightscreen-->"C:\Program Files (x86)\Lightscreen\uninstall.exe"
Magic RM RAM to MP3 Converter 3.72-->"C:\Program Files (x86)\Magic RM to MP3 Converter\unins000.exe"
MagicDisc 2.7.106-->C:\PROGRA~2\MAGICD~1\UNWISE.EXE C:\PROGRA~2\MAGICD~1\INSTALL.LOG
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Mozilla Firefox 8.0 (x86 cs)-->C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe
Oblivion - Knights of the Nine-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{14C87AA7-08E6-419F-A165-998EBE5023D7}\setup.exe" -l0x9 -removeonly
Oblivion - Mehrunes Razor-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{EF295F5C-7B57-47AA-8889-6B3E8E214E89}\setup.exe" -l0x9 -removeonly
Oblivion - Spell Tomes-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{16D919E6-F019-4E15-BFBE-4A85EF19DA57}\setup.exe" -l0x9 -removeonly
Oblivion - Thieves Den-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{FFFFFD17-B460-41EB-93F1-C48ABAD63828}\setup.exe" -l0x9 -removeonly
Oblivion Face Exchange Lite-->MsiExec.exe /I{0DBEC4D5-2CCA-45CB-A529-75CD83E698AB}
Oblivion-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
ON_OFF Charge B11.0110.1-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{3DECD372-76A1-4483-BF10-B547790A3261}\setup.exe" -l0x9 -removeonly
OpenOffice.org 3.3-->MsiExec.exe /I{10B43A43-FF73-47FD-83E8-A503E84F9ED6}
PC Translator-->C:\Users\vydla\AppData\Local\Temp\UN32.EXE -UP
Pidgin-->C:\Program Files (x86)\Pidgin\pidgin-uninst.exe
Plus500-->C:\Program Files (x86)\Plus500\Plus500.exe /uninstall
Python 2.7 comtypes-0.6.2-->"C:\Python27\Removecomtypes.exe" -u "C:\Python27\comtypes-wininst.log"
Python 2.7 pywin32-216-->"C:\Python27\Removepywin32.exe" -u "C:\Python27\pywin32-wininst.log"
Python 2.7.2-->MsiExec.exe /I{2E295B5B-1AD4-4D36-97C2-A316084722CF}
Real Alternative 1.9.0 Lite-->"C:\Program Files (x86)\Real Alternative\unins000.exe"
Realtek Ethernet Controller Driver-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.Exe -runfromtemp -removeonly
Realtek HDMI Audio Driver for ATI-->C:\Program Files\Realtek\Audio\HDA\RtkUpd64.exe -k -m -nrg2709
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -removeonly
Recuva-->"C:\Program Files\Recuva\uninst.exe"
RelevantKnowledge-->C:\Program Files (x86)\RelevantKnowledge\rlvknlg.exe -bootremove -uninst:RelevantKnowledge
Skype™ 5.5-->MsiExec.exe /X{AA59DDE4-B672-4621-A016-4C248204957A}
TextMaker Viewer-->C:\Windows\unTMV.exe
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
Visual Studio 2008 x64 Redistributables-->MsiExec.exe /I{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}
VLC media player 1.1.11-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
Winamp-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Wrye Bash-->"C:\Program Files (x86)\Common Files\Wrye Bash\uninstall.exe"
wxPython 2.8.12.1 (ansi) for Python 2.6-->"C:\Python27\site-packages\wx-2.8-msw-ansi\unins000.exe"
wxPython 2.8.12.1 (ansi) for Python 2.7-->"C:\Python27\Lib\site-packages\wx-2.8-msw-ansi\unins000.exe"
XAMPP 1.7.7-->"D:\xampp\uninstall.exe"
======System event log======
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name inferno.demonoid.com timed out after none of the configured DNS servers responded.
Record Number: 32404
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111016071645.636003-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: vydla-PC
Event Code: 11
Message: The driver detected a controller error on \Device\CdRom3.
Record Number: 32397
Source Name: cdrom
Time Written: 20111016051436.346197-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name www.seznamobchodu.cz timed out after none of the configured DNS servers responded.
Record Number: 32370
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111015113509.011348-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name www.h33t.com timed out after none of the configured DNS servers responded.
Record Number: 32187
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111014132119.620863-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: vydla-PC
Event Code: 1014
Message: Name resolution for the name tracker.openbittorrent.com timed out after none of the configured DNS servers responded.
Record Number: 32123
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20111013144726.791662-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
=====Application event log=====
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil . Error code = 0x80070002
Record Number: 104
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil . Error code = 0x80070002
Record Number: 103
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil . Error code = 0x80070002
Record Number: 102
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1101
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_64) - Failed to compile: BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64 . Error code = 0x80070002
Record Number: 101
Source Name: .NET Runtime Optimization Service
Time Written: 20110713175151.000000-000
Event Type: Error
User:
Computer Name: vydla-PC
Event Code: 1008
Message: The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
Record Number: 92
Source Name: Microsoft-Windows-Search
Time Written: 20110713175038.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: 37L4247E29-32
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174019.554859-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247E29-32$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174019.554859-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x2bd0b
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174019.336459-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174017.901256-000
Event Type: Audit Success
User:
Computer Name: 37L4247E29-32
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110714174017.870056-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=0503
-----------------EOF-----------------