Stránka 1 z 1

NTB se startuje i několik hodin

Napsal: 20 lis 2011 18:11
od Babu
Zdravím,

mám problém s notebookem. Po zapnutí se dívám několik hodin na černou obrazovku a až po několika hodinách (doba je vždy jiná), se začne načítat. Když najede plocha, funguje už všechno v pořádku. Není zpomalený, ani se nechová nijak zavirovaně. Potom ho normálně vypnu a při dalším zapnutí dělá zase to samé. Nevíte někdo, co s tím? Nikdy předtím to nedělal.

Díky za odpověď.. :)

Re: NTB se startuje i několik hodin

Napsal: 20 lis 2011 18:23
od JaRon
ahoj,
1. pozri aku mas velkost adresara plocha :???:
2. ak bude v poriadku t.j. max. 300MB, tak otestuj disk z HDTune - vysledky z casti benchmark vloz sem

Re: NTB se startuje i několik hodin

Napsal: 20 lis 2011 18:49
od Babu
Plocha je v poradku

HD Tune:

Transfer rate:
Minimum 6,4 MB/sec
Maximum 63,7 MB/sec
Average 47,4 MB/sec

Acces time 16,6 ms
Burst rate 87,0 MB/sec
CPU usage 14,9 %

Re: NTB se startuje i několik hodin

Napsal: 20 lis 2011 18:55
od JaRon
vycisti NTB s CCleanerom a vloz oba logy RSIT - rano sa na to pozriem

Re: NTB se startuje i několik hodin

Napsal: 20 lis 2011 19:13
od Babu
log.txt


Logfile of random's system information tool 1.09 (written by random/random)
Run by Petr at 2011-11-20 19:08:21
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 46 GB (66%) free of 70 GB
Total RAM: 2815 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:09:30, on 20.11.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\HD Tune\HDTune.exe
C:\Users\Petr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Petr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Petr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Petr\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Petr\Downloads\RSIT.exe
C:\Program Files\trend micro\Petr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe

--
End of file - 4996 bytes

======Scheduled tasks folder======

C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1245867285-1556063811-897823704-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1245867285-1556063811-897823704-1000UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-12 343168]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1174016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\misc.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msoxmled.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mstore.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
"Debugger="C:\Program Files\TuneUp Utilities 2012\PMLauncher.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe]
"Debugger=""C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2011-11-20 19:08:21 ----D---- C:\rsit
2011-11-20 19:08:21 ----D---- C:\Program Files\trend micro
2011-11-20 19:03:11 ----D---- C:\Program Files\CCleaner
2011-11-20 18:38:21 ----D---- C:\Program Files\HD Tune
2011-11-17 13:44:29 ----D---- C:\ProgramData\vsosdk
2011-11-17 13:13:17 ----D---- C:\Users\Petr\AppData\Roaming\Vso
2011-11-17 13:12:50 ----A---- C:\Windows\system32\sipr3260.dll
2011-11-17 13:12:50 ----A---- C:\Windows\system32\Pncrt.dll
2011-11-17 13:12:50 ----A---- C:\Windows\system32\drv43260.dll
2011-11-17 13:12:50 ----A---- C:\Windows\system32\drv33260.dll
2011-11-17 13:12:50 ----A---- C:\Windows\system32\drv23260.dll
2011-11-17 13:12:50 ----A---- C:\Windows\system32\cook3260.dll
2011-11-17 13:12:49 ----A---- C:\Windows\system32\wvc1dmod.dll
2011-11-17 13:12:49 ----A---- C:\Windows\system32\vp7vfw.dll
2011-11-17 13:12:45 ----D---- C:\Program Files\VSO
2011-11-15 18:01:37 ----D---- C:\Users\Petr\AppData\Roaming\BSplayer Pro
2011-11-15 18:01:37 ----D---- C:\Users\Petr\AppData\Roaming\BSplayer
2011-11-15 18:01:27 ----D---- C:\Program Files\Webteh
2011-11-13 19:51:11 ----D---- C:\Users\Petr\AppData\Roaming\Macromedia
2011-11-13 19:02:51 ----D---- C:\Users\Petr\AppData\Roaming\Adobe
2011-11-13 18:57:36 ----D---- C:\Users\Petr\AppData\Roaming\Nero
2011-11-13 18:45:48 ----D---- C:\Program Files\Common Files\Nero
2011-11-13 18:45:31 ----D---- C:\ProgramData\Nero
2011-11-13 18:38:31 ----A---- C:\Windows\system32\drivers\NBVolUp.sys
2011-11-13 18:38:28 ----DC---- C:\Windows\system32\DRVSTORE
2011-11-13 18:38:28 ----D---- C:\Program Files\Nero
2011-11-13 18:38:28 ----A---- C:\Windows\system32\drivers\NBVol.sys
2011-11-13 18:38:09 ----D---- C:\Windows\system32\Macromed
2011-11-13 18:36:13 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2011-11-13 18:36:12 ----A---- C:\Windows\system32\D3DX9_43.dll
2011-11-13 18:36:12 ----A---- C:\Windows\system32\d3dx11_43.dll
2011-11-13 18:36:12 ----A---- C:\Windows\system32\d3dx10_43.dll
2011-11-13 18:36:12 ----A---- C:\Windows\system32\d3dcsx_43.dll
2011-11-13 18:35:50 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2011-11-13 18:35:32 ----A---- C:\Windows\system32\D3DX9_42.dll
2011-11-13 18:35:14 ----A---- C:\Windows\system32\D3DX9_40.dll
2011-11-13 18:34:55 ----A---- C:\Windows\system32\d3dx9_35.dll
2011-11-13 18:34:36 ----A---- C:\Windows\system32\d3dx9_34.dll
2011-11-13 18:34:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2011-11-13 18:17:34 ----A---- C:\Windows\system32\drivers\usbport.sys
2011-11-13 18:17:34 ----A---- C:\Windows\system32\drivers\usbhub.sys
2011-11-13 18:17:34 ----A---- C:\Windows\system32\drivers\usbehci.sys
2011-11-13 18:17:33 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2011-11-13 18:17:33 ----A---- C:\Windows\system32\drivers\usbohci.sys
2011-11-13 18:17:33 ----A---- C:\Windows\system32\drivers\usbd.sys
2011-11-13 18:17:33 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2011-11-13 18:17:31 ----A---- C:\Windows\system32\esent.dll
2011-11-13 18:17:30 ----A---- C:\Windows\system32\fsutil.exe
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\storport.sys
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\nvstor.sys
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\nvraid.sys
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\ntfs.sys
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\amdxata.sys
2011-11-13 18:17:30 ----A---- C:\Windows\system32\drivers\amdsata.sys
2011-11-13 18:17:16 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-11-13 18:17:16 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-11-13 02:15:45 ----D---- C:\Windows\AutoKMS
2011-11-13 02:02:07 ----A---- C:\Windows\system32\TURegOpt.exe
2011-11-13 02:02:07 ----A---- C:\Windows\system32\authuitu.dll
2011-11-13 02:01:51 ----D---- C:\Users\Petr\AppData\Roaming\TuneUp Software
2011-11-13 02:01:38 ----D---- C:\Program Files\TuneUp Utilities 2012
2011-11-13 02:00:46 ----D---- C:\ProgramData\TuneUp Software
2011-11-13 02:00:36 ----SHD---- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2011-11-13 01:54:24 ----D---- C:\Users\Petr\AppData\Roaming\Windows Live Writer
2011-11-13 01:52:20 ----D---- C:\Windows\cs
2011-11-13 01:47:31 ----D---- C:\Program Files\Windows Live
2011-11-13 01:47:08 ----A---- C:\Windows\system32\XAudio2_5.dll
2011-11-13 01:47:08 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2011-11-13 01:47:08 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-11-13 01:46:38 ----A---- C:\Windows\system32\d3dx9_32.dll
2011-11-13 01:45:12 ----D---- C:\Program Files\Common Files\Windows Live
2011-11-13 01:25:38 ----D---- C:\Program Files\Synaptics
2011-11-13 01:25:04 ----A---- C:\Windows\system32\WdfCoInstaller01000.dll
2011-11-13 01:25:04 ----A---- C:\Windows\system32\SynTPCo4.dll
2011-11-13 01:25:03 ----A---- C:\Windows\system32\SynCtrl.dll
2011-11-13 01:25:03 ----A---- C:\Windows\system32\SynCOM.dll
2011-11-13 01:25:02 ----A---- C:\Windows\system32\SynTPAPI.dll
2011-11-13 01:25:02 ----A---- C:\Windows\system32\drivers\SynTP.sys
2011-11-13 01:15:15 ----D---- C:\Program Files\Microsoft Security Client
2011-11-13 01:14:58 ----A---- C:\Windows\system32\MRT.exe
2011-11-13 01:14:18 ----A---- C:\Windows\system32\shell32.dll
2011-11-13 01:14:10 ----A---- C:\Windows\system32\FntCache.dll
2011-11-13 01:14:09 ----A---- C:\Windows\system32\DWrite.dll
2011-11-13 01:14:09 ----A---- C:\Windows\system32\d2d1.dll
2011-11-13 01:07:29 ----D---- C:\Windows\system32\Wat
2011-11-13 00:33:59 ----A---- C:\Windows\system32\drivers\AsUpIO.sys
2011-11-13 00:33:58 ----A---- C:\Windows\system32\drivers\AsIO.sys
2011-11-13 00:33:58 ----A---- C:\Windows\system32\AsIO.dll
2011-11-13 00:26:37 ----HD---- C:\Program Files\InstallShield Installation Information
2011-11-13 00:26:37 ----D---- C:\Program Files\ASUS
2011-11-13 00:10:59 ----D---- C:\Users\Petr\AppData\Roaming\WinRAR
2011-11-13 00:10:52 ----D---- C:\Program Files\WinRAR
2011-11-12 22:53:47 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-11-12 22:53:30 ----A---- C:\Windows\system32\poqexec.exe
2011-11-12 22:53:28 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2011-11-12 22:53:27 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-11-12 22:53:27 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-11-12 22:53:27 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-11-12 22:53:27 ----A---- C:\Windows\system32\drivers\srv.sys
2011-11-12 22:53:26 ----A---- C:\Windows\system32\drivers\afd.sys
2011-11-12 22:53:17 ----A---- C:\Windows\system32\xmllite.dll
2011-11-12 22:53:17 ----A---- C:\Windows\system32\prevhost.exe
2011-11-12 22:53:16 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-11-12 22:53:15 ----A---- C:\Windows\system32\ntkrnlpa.exe
2011-11-12 22:53:12 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-11-12 22:53:12 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-11-12 22:53:12 ----A---- C:\Windows\system32\dnsapi.dll
2011-11-12 22:53:11 ----A---- C:\Windows\system32\fontsub.dll
2011-11-12 22:53:11 ----A---- C:\Windows\system32\atmlib.dll
2011-11-12 22:53:11 ----A---- C:\Windows\system32\atmfd.dll
2011-11-12 22:53:05 ----A---- C:\Windows\system32\psisdecd.dll
2011-11-12 22:53:04 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-11-12 22:53:03 ----A---- C:\Windows\system32\kerberos.dll
2011-11-12 22:53:03 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-11-12 22:53:03 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-11-12 22:53:03 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-11-12 22:53:02 ----A---- C:\Windows\system32\oleaut32.dll
2011-11-12 22:53:02 ----A---- C:\Windows\system32\oleacc.dll
2011-11-12 22:53:00 ----A---- C:\Windows\system32\tzres.dll
2011-11-12 22:52:55 ----A---- C:\Windows\system32\inetcomm.dll
2011-11-12 22:52:25 ----A---- C:\Windows\system32\tquery.dll
2011-11-12 22:52:25 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-11-12 22:52:25 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-11-12 22:52:25 ----A---- C:\Windows\system32\mssvp.dll
2011-11-12 22:52:25 ----A---- C:\Windows\system32\mssrch.dll
2011-11-12 22:52:25 ----A---- C:\Windows\system32\mssph.dll
2011-11-12 22:52:24 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-11-12 22:52:24 ----A---- C:\Windows\system32\mssphtb.dll
2011-11-12 22:52:24 ----A---- C:\Windows\system32\msscntrs.dll
2011-11-12 22:52:23 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-11-12 22:52:22 ----A---- C:\Windows\system32\XpsPrint.dll
2011-11-12 22:52:20 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-11-12 22:52:19 ----A---- C:\Windows\system32\sbe.dll
2011-11-12 22:52:19 ----A---- C:\Windows\system32\EncDec.dll
2011-11-12 22:52:19 ----A---- C:\Windows\system32\CPFilters.dll
2011-11-12 22:52:15 ----A---- C:\Windows\explorer.exe
2011-11-12 22:52:14 ----A---- C:\Windows\system32\win32k.sys
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-11-12 22:52:13 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-11-12 22:52:13 ----A---- C:\Windows\system32\winsrv.dll
2011-11-12 22:52:13 ----A---- C:\Windows\system32\KernelBase.dll
2011-11-12 22:52:13 ----A---- C:\Windows\system32\kernel32.dll
2011-11-12 22:52:13 ----A---- C:\Windows\system32\conhost.exe
2011-11-12 22:52:09 ----A---- C:\Windows\system32\odbctrac.dll
2011-11-12 22:52:09 ----A---- C:\Windows\system32\odbcjt32.dll
2011-11-12 22:52:09 ----A---- C:\Windows\system32\odbccu32.dll
2011-11-12 22:52:09 ----A---- C:\Windows\system32\odbccr32.dll
2011-11-12 22:52:09 ----A---- C:\Windows\system32\odbccp32.dll
2011-11-12 22:52:09 ----A---- C:\Windows\system32\d3d10_1.dll
2011-11-12 22:52:08 ----A---- C:\Windows\system32\mfc42u.dll
2011-11-12 22:52:08 ----A---- C:\Windows\system32\mfc42.dll
2011-11-12 22:52:07 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-11-12 22:49:30 ----D---- C:\Users\Petr\AppData\Roaming\Opera
2011-11-12 22:49:26 ----D---- C:\Program Files\Opera
2011-11-12 11:31:03 ----A---- C:\Windows\AutoKMS.exe
2011-11-12 06:45:28 ----D---- C:\Program Files\Microsoft Synchronization Services
2011-11-12 06:45:28 ----D---- C:\Program Files\Common Files\DESIGNER
2011-11-12 06:45:13 ----D---- C:\Windows\PCHEALTH
2011-11-12 06:45:13 ----D---- C:\Program Files\Microsoft.NET
2011-11-12 06:45:13 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2011-11-12 06:43:38 ----D---- C:\Program Files\Microsoft Analysis Services
2011-11-12 06:43:30 ----D---- C:\ProgramData\Microsoft Help
2011-11-12 06:43:30 ----D---- C:\Program Files\Microsoft Office
2011-11-12 06:43:20 ----RHD---- C:\MSOCache
2011-11-12 00:55:03 ----A---- C:\Windows\system32\wininet.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\wextract.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\webcheck.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\vbscript.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\urlmon.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\url.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\pngfilt.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\occache.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\msrating.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\msls31.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\mshtmler.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\mshtmled.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\mshtml.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\mshta.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\msfeedssync.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\msfeeds.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\licmgr10.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\jsproxy.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\jscript9.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\jscript.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\inseng.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\imgutil.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iexpress.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieUnatt.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieui.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iesysprep.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iesetup.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iertutil.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iernonce.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iepeers.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieframe.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\iedkcs32.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieapfltr.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieapfltr.dat
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieakui.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieaksie.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ieakeng.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\ie4uinit.exe
2011-11-12 00:55:03 ----A---- C:\Windows\system32\icardie.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\dxtrans.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\dxtmsft.dll
2011-11-12 00:55:03 ----A---- C:\Windows\system32\admparse.dll
2011-11-12 00:47:40 ----N---- C:\Windows\system32\MpSigStub.exe
2011-11-12 00:43:06 ----D---- C:\Users\Petr\AppData\Roaming\ATI
2011-11-12 00:43:06 ----D---- C:\ProgramData\ATI
2011-11-12 00:43:04 ----D---- C:\Program Files\AMD APP
2011-11-12 00:43:02 ----D---- C:\Program Files\Common Files\ATI Technologies
2011-11-12 00:42:48 ----D---- C:\ProgramData\AMD
2011-11-12 00:42:43 ----A---- C:\Windows\system32\drivers\amdiox86.sys
2011-11-12 00:42:13 ----SHD---- C:\Windows\Installer
2011-11-12 00:42:04 ----D---- C:\Program Files\ATI Technologies
2011-11-12 00:42:01 ----D---- C:\Program Files\ATI
2011-11-12 00:41:23 ----D---- C:\ATI
2011-11-12 00:40:36 ----D---- C:\AMD
2011-11-12 00:31:08 ----D---- C:\Users\Petr\AppData\Roaming\Identities
2011-11-12 00:30:45 ----SD---- C:\Users\Petr\AppData\Roaming\Microsoft
2011-11-12 00:30:45 ----D---- C:\Users\Petr\AppData\Roaming\Media Center Programs
2011-11-12 00:30:37 ----SHD---- C:\Recovery
2011-11-12 00:30:36 ----SHD---- C:\ProgramData\Šablony
2011-11-12 00:30:36 ----SHD---- C:\ProgramData\Plocha
2011-11-12 00:30:36 ----SHD---- C:\ProgramData\Oblíbené položky
2011-11-12 00:30:36 ----SHD---- C:\ProgramData\Nabídka Start
2011-11-12 00:30:36 ----SHD---- C:\ProgramData\Dokumenty
2011-11-12 00:30:36 ----SHD---- C:\ProgramData\Data aplikací
2011-11-12 00:27:00 ----D---- C:\Windows\SoftwareDistribution
2011-11-12 00:24:51 ----D---- C:\Windows\Prefetch
2011-11-12 00:23:50 ----SHD---- C:\System Volume Information
2011-11-12 00:23:50 ----ASH---- C:\pagefile.sys
2011-11-12 00:23:50 ----ASH---- C:\hiberfil.sys
2011-11-12 00:23:02 ----D---- C:\Windows\Panther

======List of files/folders modified in the last 1 month======

2011-11-20 19:08:21 ----RD---- C:\Program Files
2011-11-20 19:07:55 ----D---- C:\Windows\Temp
2011-11-20 19:04:04 ----D---- C:\Windows\debug
2011-11-20 19:04:04 ----D---- C:\Windows
2011-11-20 17:56:01 ----D---- C:\Windows\system32\config
2011-11-20 17:39:23 ----D---- C:\Windows\System32
2011-11-20 17:39:23 ----D---- C:\Windows\inf
2011-11-20 17:39:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-11-20 17:35:36 ----D---- C:\Windows\Tasks
2011-11-17 17:08:38 ----D---- C:\Windows\rescache
2011-11-17 13:44:29 ----HD---- C:\ProgramData
2011-11-16 18:36:31 ----D---- C:\Windows\system32\Tasks
2011-11-15 23:57:56 ----D---- C:\Windows\Microsoft.NET
2011-11-15 23:57:48 ----RSD---- C:\Windows\assembly
2011-11-14 13:27:13 ----D---- C:\Windows\winsxs
2011-11-14 09:38:54 ----D---- C:\Windows\system32\drivers
2011-11-14 09:38:54 ----D---- C:\Windows\system32\cs-CZ
2011-11-14 09:38:53 ----D---- C:\Windows\system32\DriverStore
2011-11-13 19:45:08 ----SD---- C:\ProgramData\Microsoft
2011-11-13 18:55:27 ----D---- C:\Windows\Cursors
2011-11-13 18:45:48 ----D---- C:\Program Files\Common Files
2011-11-13 18:38:31 ----D---- C:\Windows\system32\catroot
2011-11-13 02:04:02 ----D---- C:\Windows\system32\en-US
2011-11-13 01:47:16 ----D---- C:\Program Files\Common Files\microsoft shared
2011-11-13 01:46:17 ----D---- C:\Windows\Logs
2011-11-13 01:46:04 ----D---- C:\Windows\system32\catroot2
2011-11-13 01:07:36 ----D---- C:\Windows\AppPatch
2011-11-13 01:07:36 ----D---- C:\Program Files\Common Files\System
2011-11-13 01:07:35 ----RSD---- C:\Windows\Fonts
2011-11-13 01:07:35 ----D---- C:\Windows\ehome
2011-11-12 22:47:23 ----D---- C:\Windows\system32\LogFiles
2011-11-12 12:20:35 ----D---- C:\Windows\system32\wdi
2011-11-12 06:45:51 ----D---- C:\Windows\ShellNew
2011-11-12 06:31:18 ----D---- C:\Program Files\Internet Explorer
2011-11-12 00:56:27 ----D---- C:\Windows\servicing
2011-11-12 00:55:17 ----D---- C:\Windows\system32\migration
2011-11-12 00:55:17 ----D---- C:\Windows\PolicyDefinitions
2011-11-12 00:39:00 ----D---- C:\Windows\system32\CodeIntegrity
2011-11-12 00:36:10 ----D---- C:\Windows\system32\restore
2011-11-12 00:31:06 ----SHD---- C:\$Recycle.Bin
2011-11-12 00:30:44 ----RD---- C:\Users
2011-11-12 00:30:37 ----D---- C:\Windows\system32\Recovery
2011-11-12 00:30:36 ----D---- C:\Program Files\Windows NT
2011-11-12 00:27:47 ----D---- C:\Windows\system32\sysprep
2011-11-12 00:26:35 ----D---- C:\Windows\system32\drivers\UMDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 NBVol;Nero Backup Volume Filter Driver; C:\Windows\system32\DRIVERS\NBVol.sys [2011-07-13 56496]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver; C:\Windows\system32\DRIVERS\NBVolUp.sys [2011-07-13 12464]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 AsIO;AsIO; C:\Windows\system32\drivers\AsIO.sys [2009-08-04 11296]
R1 AsUpIO;AsUpIO; C:\Windows\system32\drivers\AsUpIO.sys [2009-07-06 11448]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKslb65d2eb4;MpKslb65d2eb4; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CC4F52E1-5087-4DA4-A49A-845B256AC4AC}\MpKslb65d2eb4.sys [2011-11-20 28752]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 amdiox86;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox86.sys [2010-02-18 37944]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-10-12 8598528]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-10-12 257024]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2011-06-27 2191872]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2007-07-31 7680]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2009-07-13 1068032]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-12-06 196400]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [2011-10-31 10064]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-10-12 8598528]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BS_DEF;BS_DEF; \??\C:\Program Files\ASUS\ASUSUpdate\BS_DEF.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393728]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 PhyDMACC;PhyDMACC; \??\C:\Users\Petr\Documents\PhyDMACCx86.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-10-12 176128]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-10-12 291840]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [2011-11-02 1479488]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-11-13 1343400]
S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

Re: NTB se startuje i několik hodin

Napsal: 20 lis 2011 19:14
od Babu
info.txt


info.txt logfile of random's system information tool 1.09 2011-11-20 19:09:32

======Uninstall list======

Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe -maintain activex
AMD APP SDK Runtime-->MsiExec.exe /I{A25FF1C0-80B6-4B8B-A551-DC525697A408}
AMD Catalyst Install Manager-->msiexec /q/x{381A5EDA-7135-09B7-9599-259B7B9829DA} REBOOT=ReallySuppress
AMD Media Foundation Decoders-->MsiExec.exe /X{ABC26CEE-07FF-5A83-4AF6-50BB9ACAF8C9}
BS.Player FREE-->"C:\Program Files\Webteh\BSplayer\uninstall.exe"
Catalyst Control Center - Branding-->MsiExec.exe /I{0E33EC53-22CE-426C-A88B-2AAC231BAC85}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
ConvertXtoDVD 4.1.19.365-->"C:\Program Files\VSO\ConvertX\4\unins000.exe"
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
Definition update for Microsoft Office 2010 (KB982726) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{0DA5C61E-18AE-4BBE-A29B-0BFACADB5C6A}" "1029" "0"
HD Tune 2.55-->"C:\Program Files\HD Tune\unins000.exe"
High-Definition Video Playback-->MsiExec.exe /X{9193490D-5229-4FC4-9BB9-A6D63C09574A}
Junk Mail filter update-->MsiExec.exe /I{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}
Mesh Runtime-->MsiExec.exe /I{8C6D6116-B724-4810-8F2D-D047E6B7D68E}
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ClientLP
Microsoft .NET Framework 4 Client Profile CSY Language Pack-->MsiExec.exe /X{7036A6F4-5DAD-3908-956D-1752CD7F7E5A}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft .NET Framework 4 Extended CSY Language Pack-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ExtendedLP\Setup.exe /repair /x86 /lcid 1029 /parameterfolder ExtendedLP
Microsoft .NET Framework 4 Extended CSY Language Pack-->MsiExec.exe /X{A2DE62D8-EF1B-36CB-B461-B1E221ED8608}
Microsoft .NET Framework 4 Extended-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe /repair /x86 /parameterfolder Extended
Microsoft .NET Framework 4 Extended-->MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}
Microsoft Antimalware Service CS-CZ Language Pack-->MsiExec.exe /X{17CA32D1-73BD-4990-B8F6-369D8D34B05D}
Microsoft Antimalware-->MsiExec.exe /X{05BFB060-4F22-4710-B0A2-2801A1B606C5}
Microsoft Office Access MUI (Czech) 2010-->MsiExec.exe /X{90140000-0015-0405-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2010-->MsiExec.exe /X{90140000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2010-->MsiExec.exe /X{90140000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2010-->MsiExec.exe /X{90140000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2010-->MsiExec.exe /X{90140000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2010-->MsiExec.exe /X{90140000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2010-->MsiExec.exe /X{90140000-0018-0405-0000-0000000FF1CE}
Microsoft Office Professional Plus 2010-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\setup.exe" /uninstall PROPLUSR /dll OSETUP.DLL
Microsoft Office Professional Plus 2010-->MsiExec.exe /X{91140000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2010-->MsiExec.exe /X{90140000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2010-->MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2010-->MsiExec.exe /X{90140000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2010-->MsiExec.exe /X{90140000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2010-->MsiExec.exe /X{90140000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2010-->MsiExec.exe /X{90140000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2010-->MsiExec.exe /X{90140000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2010-->MsiExec.exe /X{90140000-001B-0405-0000-0000000FF1CE}
Microsoft Security Client CS-CZ Language Pack-->MsiExec.exe /I{50779A29-834E-4E36-BBEB-B7CABC67A825}
Microsoft Security Client-->MsiExec.exe /I{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}
Microsoft Security Essentials-->C:\Program Files\Microsoft Security Client\Setup.exe /x
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
Nero 11 Cliparts-->MsiExec.exe /X{B160A672-F326-4414-9BB0-A056C61B357C}
Nero 11 Disc Menus 1-->MsiExec.exe /X{A0F34849-D9AB-46DD-B1BE-BB0DB60B1FE8}
Nero 11 Disc Menus 2-->MsiExec.exe /X{7DF2B5EE-2C16-4E86-9C71-8678068AD805}
Nero 11 Disc Menus 3-->MsiExec.exe /X{5E98FDD6-3672-4DBE-AB8B-2C9A0BED1382}
Nero 11 Disc Menus Basic-->MsiExec.exe /X{F49EF443-B2BD-4F10-8A46-87AFCDB90EDD}
Nero 11 Effects Basic-->MsiExec.exe /X{E51BC4B0-EA5E-49CC-AF3B-93B5C627EC22}
Nero 11 Image Samples-->MsiExec.exe /X{F3743A2C-5D5F-4456-8F98-5DF36A954C50}
Nero 11 Kwik Themes 1-->MsiExec.exe /X{B1F69AF3-B5B5-4CA5-ADC5-8A738EB6E574}
Nero 11 Kwik Themes 2-->MsiExec.exe /X{A4F6BE36-4826-45BA-A396-04F265A3B61D}
Nero 11 Kwik Themes 3-->MsiExec.exe /X{BA499CC0-12C0-4BA5-9007-76844B721158}
Nero 11 Kwik Themes 4-->MsiExec.exe /X{ACD6B383-EC5B-4000-A455-CCB308B447FE}
Nero 11 Kwik Themes Basic-->MsiExec.exe /X{5A212B2D-140D-46F4-B625-2D1CA5A00594}
Nero 11 PiP Effects 1-->MsiExec.exe /X{3B418709-D688-4E3A-BE0E-7D71FA84C948}
Nero 11 PiP Effects Basic-->MsiExec.exe /X{2CA7225D-CB12-462A-9DD1-50319E158BA5}
Nero 11 Video Samples-->MsiExec.exe /X{A2CDC001-F8B3-4C64-9E74-2E3FA0FAC9D9}
Nero 11 Video Transitions 1-->MsiExec.exe /X{4382FC76-8100-4951-8658-31834E625E88}
Nero 11-->MsiExec.exe /I{8A7ABBD4-A617-4AE8-9C6D-1510DE46EC35}
Nero Audio Pack 1-->MsiExec.exe /X{A7A0BF2E-31CC-49E3-9913-52C503EB969D}
Nero BackItUp 11 Help (CHM)-->MsiExec.exe /X{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}
Nero Backup Drivers-->MsiExec.exe /X{F8EF9B71-53E7-41F5-8E54-47B4C979CB38}
Nero Burning ROM 11 Help (CHM)-->MsiExec.exe /X{53F7746A-96AA-49A5-86B8-59989680DAC5}
Nero Burning ROM 11-->MsiExec.exe /X{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}
Nero ControlCenter 11 Help (CHM)-->MsiExec.exe /X{D4D66270-9147-4BDF-9946-FCA2B303AA8F}
Nero ControlCenter 11-->MsiExec.exe /X{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}
Nero Core Components 11-->MsiExec.exe /X{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}
Nero CoverDesigner 11 Help (CHM)-->MsiExec.exe /X{55C2143E-FBA5-442F-9AFA-726FF068F39D}
Nero CoverDesigner 11-->MsiExec.exe /X{FF44BCE5-5A18-4051-85F0-BC172D7B4695}
Nero Express 11 Help (CHM)-->MsiExec.exe /X{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}
Nero Express 11-->MsiExec.exe /X{E10AAE4A-98B8-420A-BD93-E0520C23D624}
Nero Kwik Media Help (CHM)-->MsiExec.exe /X{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}
Nero Kwik Media-->MsiExec.exe /X{BE814218-3919-4EA3-868A-2F60BC135CB4}
Nero Recode 11 Help (CHM)-->MsiExec.exe /X{57F80ECF-E27C-4EEE-AB58-E971BACE2639}
Nero Recode 11-->MsiExec.exe /X{F69FB940-5031-4FE8-AFAD-085802D0BF63}
Nero RescueAgent 11 Help (CHM)-->MsiExec.exe /X{D01CE99A-8802-483C-A79F-298B691EB432}
Nero RescueAgent 11-->MsiExec.exe /X{034DCAF9-96E7-4936-9A07-712F80B5181E}
Nero SoundTrax 11 Help (CHM)-->MsiExec.exe /X{390757AA-8830-43DC-AEE0-4E5B6F8439EB}
Nero SoundTrax 11-->MsiExec.exe /X{0713D1F9-DD77-42C1-8C7D-54D479E2E743}
Nero Video 11 Help (CHM)-->MsiExec.exe /X{FAC3C37E-EDAB-4F3A-A173-A7C70CC88F09}
Nero Video 11-->MsiExec.exe /X{0D7A4289-99CF-4B8D-B812-86BE50A54552}
Nero WaveEditor 11 Help (CHM)-->MsiExec.exe /X{EB8DED20-A887-4A9C-BB5A-F3E7523DFB44}
Nero WaveEditor 11-->MsiExec.exe /X{8014FACB-1D1D-48C2-94AA-E29EE2E6B9CE}
Opera 11.52-->"C:\Program Files\Opera\Opera.exe" /uninstall
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení-->MsiExec.exe /I{B6190387-0036-4BEB-8D74-A0AFC5F14706}
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7E97AB83-C1FE-38DE-B848-877E0A4BD81E} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {DB31DEDD-BF95-31E7-A9B7-5480561CEFF3} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2478663)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {728D9A6A-2206-31E8-9F65-C3EABEFCF53E} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Client Profile CSY Language Pack (KB2518870)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\ClientLP\setup.exe /uninstallpatch {2CE2EB39-45C8-32D4-8A99-5529C38F1B99} /parameterfolder ClientLP
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {7A2C18A1-D2A2-3177-82F1-5FE9CC08ECB0} /parameterfolder Extended
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {42A3562E-8B4E-39A4-B82D-CC12F82889E3} /parameterfolder Extended
Security Update for Microsoft Excel 2010 (KB2553070)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{294BAA9E-9209-497F-A71F-7E52EFB194D4}" "1029" "0"
Security Update for Microsoft InfoPath 2010 (KB2510065)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{3C6C6854-EB6B-455C-B0A6-9871F0538028}" "1029" "0"
Security Update for Microsoft Office 2010 (KB2289078)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{1D1A4F08-2F17-475B-BA72-476CE5992FEE}" "1029" "0"
Security Update for Microsoft Office 2010 (KB2553091)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{07CA44F3-F5B3-4D12-8C91-EDC5FE91D45C}" "1029" "0"
Security Update for Microsoft Office 2010 (KB2553096)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{10802A6D-EDBF-4383-BCBD-9D5B32F56D35}" "1029" "0"
Security Update for Microsoft PowerPoint 2010 (KB2519975)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{45D7C5CD-B967-44AF-9DAB-E5C8545558AD}" "1029" "0"
Security Update for Microsoft Publisher 2010 (KB2409055)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{C3C277D5-36E3-4B1A-926A-175B2BC019CF}" "1029" "0"
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{337A3FB9-281D-4EC8-9CC1-7F6DDAC2359F}" "1029" "0"
Security Update for Microsoft Word 2010 (KB2345000)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{A6D422EE-1196-45EE-B9AE-6B5B64975E8B}" "1029" "0"
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
TuneUp Utilities 2012-->C:\Program Files\TuneUp Utilities 2012\TUInstallHelper.exe --Trigger-Uninstall
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FD988F49-E1C8-3C84-9683-0448B6BB8E20} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Client
Update for Microsoft .NET Framework 4 Extended (KB2468871)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {5E9CF3A4-ADB3-3080-A8BF-976A28340758} /parameterfolder Extended
Update for Microsoft .NET Framework 4 Extended (KB2533523)-->c:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\setup.exe /uninstallpatch {81EBB9D7-173C-32E3-B477-149C8DE075E4} /parameterfolder Extended
Update for Microsoft Office 2010 (KB2202188)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{86B7A074-265D-420C-9E1E-7A920EF0ECA7}" "1029" "0"
Update for Microsoft Office 2010 (KB2494150)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}" "1029" "0"
Update for Microsoft Office 2010 (KB2523113)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{C0FF04BF-A05E-408B-81CA-B7FACDA508A3}" "1029" "0"
Update for Microsoft Office 2010 (KB2553065)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{A8686D24-1E89-43A1-973E-05A258D2B3F8}" "1029" "0"
Update for Microsoft Office 2010 (KB2553092)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{7AC49FC8-F8D2-4DD8-9086-09E52385A21F}" "1029" "0"
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{48E1B6C2-7299-4F3F-AA63-42F0ACE55AA4}" "1029" "0"
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-006E-0405-0000-0000000FF1CE}" "{6F6FD0B7-2500-41ED-8425-A6AE5958EB52}" "1029" "0"
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{C8694FF0-8203-483B-A07A-2BC40433167D}" "1029" "0"
Update for Microsoft Office 2010 (KB2553455) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{147E3669-1EA6-454C-B53E-A2BE51D8E520}" "1029" "0"
Update for Microsoft Office 2010 (KB2566458)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{EFB525A0-E1C0-4E32-9968-FE401BC87363}" "1029" "0"
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-00A1-0405-0000-0000000FF1CE}" "{3CF6665E-28CD-4EBC-B0C1-34BF7FB09C53}" "1029" "0"
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{BEBC2484-290C-46AD-9834-6DAD1FA80273}" "1029" "0"
Update for Microsoft Outlook 2010 (KB2553323) 32-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{29E94638-D92F-4C40-BDA1-FEDCC92F478D}" "1029" "0"
Update for Microsoft Outlook Social Connector (KB2583935)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{90140000-001A-0405-0000-0000000FF1CE}" "{111B84C3-DACD-4F98-83E9-385598549B2B}" "1029" "0"
Update for Microsoft Outlook Social Connector (KB2583935)-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe" /removereleaseinpatch "{91140000-0011-0000-0000-0000000FF1CE}" "{EDF9874C-9E37-4110-9FC3-094247E114DF}" "1029" "0"
welcome-->MsiExec.exe /X{CCE210DF-7EEF-4A76-A63C-3EB091FDB992}
Windows Live Communications Platform-->MsiExec.exe /I{D45240D3-B6B3-4FF9-B243-54ECE3E10066}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}
Windows Live Fotogalerie-->MsiExec.exe /X{FB79FDB7-4DE1-453D-99FE-9A880F57380E}
Windows Live ID Sign-in Assistant-->MsiExec.exe /I{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}
Windows Live Installer-->MsiExec.exe /I{0B0F231F-CE6A-483D-AA23-77B364F75917}
Windows Live Mail-->MsiExec.exe /I{9D56775A-93F3-44A3-8092-840E3826DE30}
Windows Live Mail-->MsiExec.exe /I{C454280F-3C3E-4929-B60E-9E6CED5717E7}
Windows Live Mesh-->MsiExec.exe /I{80E8C65A-8F70-4585-88A2-ABC54BABD576}
Windows Live Mesh-->MsiExec.exe /I{DECDCB7C-58CC-4865-91AF-627F9798FE48}
Windows Live MIME IFilter-->MsiExec.exe /I{AF844339-2F8A-4593-81B3-9F4C54038C4E}
Windows Live Movie Maker-->MsiExec.exe /X{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}
Windows Live Movie Maker-->MsiExec.exe /X{92EA4134-10D1-418A-91E1-5A0453131A38}
Windows Live Photo Common-->MsiExec.exe /X{78906B56-0E81-42A7-AC25-F54C946E1538}
Windows Live Photo Common-->MsiExec.exe /X{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}
Windows Live Photo Gallery-->MsiExec.exe /X{3336F667-9049-4D46-98B6-4C743EEBC5B1}
Windows Live PIMT Platform-->MsiExec.exe /I{83C292B7-38A5-440B-A731-07070E81A64F}
Windows Live Remote Client Resources-->MsiExec.exe /I{454F5782-A4C3-480E-A629-D435795DEFD8}
Windows Live Remote Client-->MsiExec.exe /I{19A4A990-5343-4FF7-B3B5-6F046C091EDF}
Windows Live Remote Service Resources-->MsiExec.exe /I{0891B708-EF3F-4D7E-9724-265245F46276}
Windows Live Remote Service-->MsiExec.exe /I{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}
Windows Live SOXE Definitions-->MsiExec.exe /I{200FEC62-3C34-4D60-9CE8-EC372E01C08F}
Windows Live SOXE-->MsiExec.exe /I{682B3E4F-696A-42DE-A41C-4C07EA1678B4}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}
Windows Live UX Platform-->MsiExec.exe /I{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}
Windows Live Writer Resources-->MsiExec.exe /X{AB78C965-5C67-409B-8433-D7B5BDB12073}
Windows Live Writer-->MsiExec.exe /X{4264C020-850B-4F08-ACBE-98205D9C336C}
Windows Live Writer-->MsiExec.exe /X{A726AE06-AAA3-43D1-87E3-70F510314F04}
Windows Live Writer-->MsiExec.exe /X{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}
WinRAR 4.01 (32-bit)-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 http://www.nero.com
127.0.0.1 http://www.nero.com/rus/index.html
127.0.0.1 http://www.nero.com/rus/support.html
127.0.0.1 http://www.nero.com/rus/support-custome ... ation.html
127.0.0.1 http://www.nero.com/rus/store-upgrade-center.html
127.0.0.1 http://www.nero.com/rus/store-volume-licensing.html
127.0.0.1 http://www.nero.com/eng/support.html?Ne ... 25e97a3b80
127.0.0.1 http://www.nero.com/eng/store-upgrade-c ... 25e97a3b80
127.0.0.1 http://www.nero.com/eng/support-custome ... 25e97a3b80
127.0.0.1 http://www.nero.com/eng/index.html

======System event log======

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Plug and Play byl změněn na: stopped
Record Number: 5
Source Name: Service Control Manager
Time Written: 20101120215742.697406-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 20010
Message: Došlo ke změně jednoho nebo více podsystémů služby Plug and Play.

Povolený instalační podsystém služby PlugPlay: 'false'
Povolený podsystém mezipaměti služby PlugPlay: 'false'

Record Number: 4
Source Name: Microsoft-Windows-UserPnp
Time Written: 20101120215742.697406-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Software Protection byl změněn na: stopped
Record Number: 3
Source Name: Service Control Manager
Time Written: 20101120215742.479005-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Windows Event Log byl změněn na: stopped
Record Number: 2
Source Name: Service Control Manager
Time Written: 20101120215742.338605-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 7036
Message: Stav služby Volume Shadow Copy byl změněn na: stopped
Record Number: 1
Source Name: Service Control Manager
Time Written: 20101120215742.323005-000
Event Type: Informace
User:

=====Application event log=====

Computer Name: 37L4247F27-08
Event Code: 1001
Message: Chybný blok , typ 0
Název události: PnPDriverNotFound
Reakce: Není k dispozici
ID souboru CAB: 0

Podpis problému:
P1: x86
P2: ACPI\ATK0100
P3:
P4:
P5:
P6:
P7:
P8:
P9:
P10:

Připojené soubory:
C:\Windows\Temp\DMI6A08.tmp.log.xml

Tyto soubory mohou být k dispozici zde:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_e3aed78fa5326e284d9379e9e532681a71d64aea_cab_07a26ad3

Symbol analýzy:
Opětovné hledání řešení: 0
ID hlášení: 8444b813-0cbc-11e1-b638-8122817ac480
Stav hlášení: 6
Record Number: 5
Source Name: Windows Error Reporting
Time Written: 20111111232602.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 5617
Message: Windows Management Instrumentation Service subsystems initialized successfully
Record Number: 4
Source Name: Microsoft-Windows-WMI
Time Written: 20111111232455.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 5615
Message: Windows Management Instrumentation Service started sucessfully
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20111111232451.000000-000
Event Type: Informace
User:

Computer Name: 37L4247F27-08
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 2
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20111111232447.119334-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: 37L4247F27-08
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20111111232447.000000-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: 37L4247F27-08
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20111111232425.591299-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: 37L4247F27-08$
Doména účtu: WORKGROUP
ID přihlášení: 0x3e7

Typ přihlášení: 5

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x1bc
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice:
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20111111232425.591299-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4902
Message: Tabulka zásad auditu pro jednotlivé uživatele byla vytvořena.

Počet prvků: 0
ID zásady: 0x24ac5
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20111111232413.516879-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-0-0
Název účtu: -
Doména účtu: -
ID přihlášení: 0x0

Typ přihlášení: 0

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3e7
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x4
Název procesu:

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: -
Balíček ověření: -
Přenosové služby: -
Název balíčku (pouze NTLM): -
Délka klíče: 0

Tato událost je generována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole s předmětem označují účet v místním systému, který požadoval přihlášení. Jedná se nejčastěji o službu, například službu serveru nebo místní proces, například Winlogon.exe nebo Services.exe.

Pole Typ přihlášení označuje, k jakému typu přihlášení došlo. Nejběžnější typy jsou 2 (interaktivní) a 3 (síť).

Pole Nové přihlášení označují účet, pro který bylo nové přihlášení vytvořeno, tj. účet, který byl přihlášen.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují, které pomocné služby se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje, který dílčí protokol z protokolů NTLM byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20111111232410.584074-000
Event Type: Úspěšný audit
User:

Computer Name: 37L4247F27-08
Event Code: 4608
Message: Spouští se systém Windows.

Tato událost je zaznamenána při spuštění procesu LSASS.EXE a inicializaci kontrolního podsystému.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20111111232410.474874-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Windows Live\Shared
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=17
"PROCESSOR_IDENTIFIER"=x86 Family 17 Model 3 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=0301
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3
"AMDAPPSDKROOT"=C:\Program Files\AMD APP\

-----------------EOF-----------------

Re: NTB se startuje i několik hodin

Napsal: 21 lis 2011 07:25
od JaRon
odstran z PC nelegalny SW :!:
potom:
stiahni a uloz na plochu ComboFix

potom spust pod uctom s administratorskym opravnenim


akcia trva cca. 5-10 minut, niekedy i dlhsie -, Pocas scanu nespustaj ziadne ine aplikacie

Nie je dovod na paniku ak stroj bude restartovany
upozornenie: ak pouzivas antispyware s rezidentnim stitem, ten pred scanom vypni.

po restarte aplikacie vytvori log, ulozeny na C:\Combofix.txt (jeho obsah vloz sem)

Re: NTB se startuje i několik hodin

Napsal: 21 lis 2011 12:38
od Babu
a dá se z těch logů vyčíst, co přesně za nelegální SW tam je? :oops:

Re: NTB se startuje i několik hodin

Napsal: 21 lis 2011 13:36
od JaRon
smeruje to k Office-u

Re: NTB se startuje i několik hodin

Napsal: 21 lis 2011 13:46
od Babu
ok, zatím dík.. až se to pustí, tak pak se ozvu.. ono to je totiž momentálně zase zamrznuté a ještě to nenajelo.. :?:

Re: NTB se startuje i několik hodin

Napsal: 25 lis 2011 13:56
od Babu
Tak už se to nerozjelo vůbec.. Tak jsem to zavezl ke známému a ten zjistil, že je chyba v hardwaru (základní deska).. nicméně to, co jsi zjistil z těch logů - je na tom ten comp hodně špatně? .. protože už ho mám doma, zatím funkční a chtěl bych se vyvarovat dalším zbytečným problémům.. :oops:

Re: NTB se startuje i několik hodin

Napsal: 25 lis 2011 14:04
od JaRon
pokial to bolo chyba HW - toto mozes tazko nejak predchadzat ,,,
preventivne prescanuj PC s AVPTool alebo CureIT - staci jednym :)

Re: NTB se startuje i několik hodin

Napsal: 25 lis 2011 14:07
od Babu
jj, já vím no.. právě jsem chtěl vědět, jestli je na tom špatně i ohledně těch dat a SW.. :) jestli je třeba pročistit a tak..

Re: NTB se startuje i několik hodin

Napsal: 27 lis 2011 02:19
od motji
A AVPtool něco našel?