Prosim o kontrolu logu-zatezove spicky(svchost,...)
Napsal: 28 led 2012 11:33
Zdravim,
uz nekolik tydnu mam problemem se "zatezovymi spickami"..Proste chvili na PC treba ani nemusim pracovat,na pozadi by nemela zadna narocna cinnost probihat,nicmene znicehonic zacne silene hucet vetrak a vytizeni CPU se dostane na 99%...Pri pohledu na proces co to zpusobuje to jsou vzdy dva-svchost.exe spusteny systemem (tj.neumim ho sestrelit) a plugin-container.exe (spusteny pode mnou a umim ho sestrelit,soucas Firefoxe,predpokladam asi nejaky spatny plugin..
Nicmene ve vetsine pripadu je to ten svchost...
Dale mam z netradicnejsich pgmu spusteny pgm Wuala coz je program na backup syncing and sharing na cloudu a Evernote pro poznamky...System mam Windows 7 x64,jinak mam Avira Internet Security..
Dal posilam vypis z RSIT,dekuji moc..!
Logfile of random's system information tool 1.09 (written by random/random)
Run by phairnix at 2012-01-28 07:48:27
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 55 GB (53%) free of 104 GB
Total RAM: 3583 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:48:40, on 28.1.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
D:\PORTABLE\uTorrent\utorrent.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\G-Recorder\G-Recorder.exe
C:\Users\phairnix\AppData\Roaming\Wuala\Wuala.exe
C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Altap Salamander\salamand.exe
D:\PORTABLE\AIMP\AIMP3.exe
D:\PORTABLE\Winamp\winamp.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
C:\Program Files (x86)\Sony\Content Transfer\ContentTransfer.exe
D:\PORTABLE\SkypePortable\App\Skype\Phone\Skype.exe
C:\Program Files (x86)\The KMPlayer\KMPlayer.exe
D:\PORTABLE\esmska\jre\launch4j-tmp\esmska-portable.exe
C:\Program Files (x86)\Trillian\trillian.exe
c:\program files (x86)\trillian\plugins\skypekit.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\program files (x86)\avira\antivir desktop\avscan.exe
D:\PORTABLE\GoogleChromePortable\GoogleChromePortable.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\usrreq.exe
C:\Program Files\trend micro\phairnix.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\PORTABLE\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O4 - Startup: EvernoteTray.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
O4 - Startup: G-Recorder.lnk = C:\Program Files (x86)\G-Recorder\G-Recorder.exe
O4 - Startup: Wuala.lnk = phairnix\AppData\Roaming\Wuala\Wuala.exe
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\G-Recorder\Skype4COM.dll
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O23 - Service: ABBYY FineReader 10 CE Licensing Service (ABBYY.Licensing.FineReader.Corporate.10.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\httpd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: SluĹľba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: SluĹľba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - c:\xampp\mysql\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10934 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"c:\xampp\apache\bin\httpd.exe" -k runservice
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe"
"C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe"
c:\xampp\mysql\bin\mysqld.exe --defaults-file=c:\xampp\mysql\bin\my.ini mysql
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\xampp\apache\bin\httpd.exe -d C:/xampp/apache
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"D:\PORTABLE\uTorrent\utorrent.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
"C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe"
"C:\Program Files (x86)\G-Recorder\G-Recorder.exe"
"C:\Users\phairnix\AppData\Roaming\Wuala\Wuala.exe" -silent
"C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_0000066c
\??\C:\Windows\system32\conhost.exe "2094170491926193660611031634-2054667384-8162304231243279574-1689610033-1676429469
"C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE"
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Altap Salamander\salamand.exe"
"D:\PORTABLE\procexp64.exe"
"D:\PORTABLE\AIMP\AIMP3.exe"
"D:\PORTABLE\Winamp\winamp.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Program Files (x86)\Evernote\Evernote\Evernote.exe"
"C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-83785e93-a51c-4639-acb0-b98f9311fa10 -SystemEventPortName:HostProcess-f8f5107a-9b5b-43bd-9e55-dfa2101070a8 -IoCancelEventPortName:HostProcess-643d51d7-992e-4110-90ef-5de9d4c82a0f -NonStateChangingEventPortName:HostProcess-dac607f9-fc47-4f64-942a-68b3531f207e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:678d13c7-699f-40cd-99d7-78f7a3c8f687
"C:\Program Files (x86)\Sony\Content Transfer\ContentTransfer.exe" -s
"D:\PORTABLE\SkypePortable\App\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\The KMPlayer\KMPlayer.exe"
"D:\PORTABLE\esmska\jre\launch4j-tmp\esmska-portable.exe" -jar "D:\PORTABLE\esmska\esmska.jar" -c config
"C:\Program Files (x86)\Trillian\trillian.exe"
skypekit.exe -f "c:\users\phairnix\appdata\roaming\trillian\users\phairnix\skype"
\??\C:\Windows\system32\conhost.exe "1918199290-1204787487-2204236587004736171544541836-584324748-1348621957-1864879321
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6900.ac5eb70.569956581 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 6900 "\\.\pipe\gecko-crash-server-pipe.6900" plugin
"C:\program files (x86)\avira\antivir desktop\avscan.exe" /CFG="C:\program files (x86)\avira\antivir desktop\sysscan.avp"
"D:\PORTABLE\GoogleChromePortable\GoogleChromePortable.exe"
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --disk-cache-dir="C:\Users\phairnix\AppData\Local\Temp\GoogleChromePortable"
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --type=renderer --disable-client-side-phishing-detection --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_2s_queue_prefetch/DnsParallelism/parallel_8/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --channel=5416.05108868.1961429424 /prefetch:3
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --type=renderer --disable-client-side-phishing-detection --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_2s_queue_prefetch/DnsParallelism/parallel_8/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --channel=5416.075B66C0.65531656 /prefetch:3
C:\Windows\system32\rundll32.exe "D:\PORTABLE\GOOGLE~1\App\CHROME~1\120742~1.100\gcswf32.dll",BrokerMain browser=chrome
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --type=plugin --plugin-path="D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\12.0.742.100\gcswf32.dll" --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --lang=cs --channel=5416.0752CFA0.656417793 /prefetch:4 --flash-broker=5772
"C:\Program Files (x86)\Opera\opera.exe"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe"
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe" -RunMxAddonsMgr -UserName:"guest" -LangIni:"C:\Program Files (x86)\Maxthon3\Language\cs-cz.ini"
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe" -RunResMgr -MainFrmIpc:"IPC_M_R_000009C0" -UsersFolder:"C:\Users\phairnix\AppData\Roaming\Maxthon3\Users\" -UserName:"guest" -LangIni:"C:\Program Files (x86)\Maxthon3\Language\cs-cz.ini" -AppDataPath:"C:\Users\phairnix\AppData\Roaming\Maxthon3\" -ProductType:"intl"
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe" -RunCore -CoreType:"webkit-normal-0-000009C0" -MainFrmIpc:"IPC_M_C_000009C0" -ResMgrIpc:"IPC_R_C_000009C0" -UserName:"guest" -LangIni:"C:\Program Files (x86)\Maxthon3\Language\cs-cz.ini" -AppDataPath:"C:\Users\phairnix\AppData\Roaming\Maxthon3\" -ProductType:"intl" -CustomCacheFolder:"%TEMP%\Maxthon3Cache\Temp\Webkit\Cache"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-43d0031a-88dd-4831-b2b9-96f3356c2491 -SystemEventPortName:HostProcess-0cc4992f-6f32-44ee-9e9a-f5bfbd378d6d -IoCancelEventPortName:HostProcess-a156902a-aee5-4df1-bcc9-3059b816cf04 -NonStateChangingEventPortName:HostProcess-e0934d74-3f19-445f-9549-c37488c69da3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6bf5a79b-55e0-455e-97e8-82e02dac5320
wmiadap.exe /R /T
C:\Windows\system32\wbem\wmiprvse.exe
"D:\DOWNLOAD\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
/u
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\phairnix\AppData\Roaming\Mozilla\Firefox\Profiles\i0zo0t83.default
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, LogMeInClient@logmein.com:1.0.0.608, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=1.1.9]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\phairnix\AppData\Roaming\Mozilla\Firefox\Profiles\i0zo0t83.default\extensions\
LogMeInClient@logmein.com
{53A03D43-5363-4669-8190-99061B2DEBA6}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5FF49FE8-B332-4CB9-B102-FB6951629E55}]
Virtual Storage Mount Notification - C:\Windows\system32\CbFsMntNtf3.dll [2011-11-04 191504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5FF49FE8-B332-4CB9-B102-FB6951629E55}]
Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll [2011-11-04 158224]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-05-03 11842152]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-09-17 57928]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=D:\PORTABLE\uTorrent\utorrent.exe [2010-12-17 396152]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-01-15 147456]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ContentTransferWMDetector.exe"=C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe [2009-11-19 583016]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-10-05 258512]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
C:\Users\phairnix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EvernoteClipper.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
EvernoteTray.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
G-Recorder.lnk - C:\Program Files (x86)\G-Recorder\G-Recorder.exe
Wuala.lnk - C:\Users\phairnix\AppData\Roaming\Wuala\Wuala.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll [2011-11-04 191504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll [2011-11-04 191504]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoFolderOptions"=0
"NoDriveTypeAutoRun"=95
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
"Debugger=""Nç?"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files\EmEditor\EMEDITOR.EXE" "%1"
======List of files/folders created in the last 1 month======
2012-01-28 07:48:28 ----D---- C:\Program Files\trend micro
2012-01-28 07:48:27 ----D---- C:\rsit
2012-01-26 18:29:10 ----D---- C:\Program Files (x86)\Evernote
2012-01-26 07:47:45 ----D---- C:\Users\phairnix\AppData\Roaming\SpiderOak
2012-01-26 07:46:30 ----D---- C:\Program Files (x86)\SpiderOak
2012-01-26 07:16:52 ----D---- C:\Program Files (x86)\SugarSync
2012-01-22 09:49:22 ----D---- C:\Program Files (x86)\Evopedia
2012-01-21 15:23:12 ----D---- C:\Program Files (x86)\Audiograbber
2012-01-21 13:35:05 ----D---- C:\Users\phairnix\AppData\Roaming\Trillian
2012-01-21 13:34:12 ----D---- C:\Program Files (x86)\Trillian
2012-01-21 11:07:14 ----D---- C:\Program Files\CDBurnerXP
2012-01-21 11:01:23 ----D---- C:\ProgramData\Skype
2012-01-20 07:33:51 ----D---- C:\Users\phairnix\AppData\Roaming\Faces
2012-01-19 18:46:01 ----D---- C:\Program Files (x86)\Vitware
2012-01-19 18:18:05 ----SHD---- C:\~LD
2012-01-19 18:17:04 ----A---- C:\Windows\system32\drivers\cbfs.sys
2012-01-19 15:23:25 ----D---- C:\Users\phairnix\AppData\Roaming\Maxthon3
2012-01-19 15:23:21 ----D---- C:\Program Files (x86)\Maxthon3
2012-01-19 11:55:18 ----D---- C:\Program Files (x86)\Wuala OverlayIcons
2012-01-19 11:55:17 ----A---- C:\Windows\system32\CbFsMntNtf3.dll
2012-01-19 11:55:16 ----A---- C:\Windows\SYSWOW64\CbFsNetRdr3.dll
2012-01-19 11:55:16 ----A---- C:\Windows\SYSWOW64\CbFsMntNtf3.dll
2012-01-19 11:55:16 ----A---- C:\Windows\system32\CbFsNetRdr3.dll
2012-01-19 11:55:14 ----A---- C:\Windows\system32\drivers\cbfs3.sys
2012-01-19 11:55:13 ----D---- C:\Program Files (x86)\Wuala CBFS
2012-01-19 11:55:02 ----D---- C:\Users\phairnix\AppData\Roaming\Wuala
2012-01-14 16:11:10 ----D---- C:\Users\phairnix\AppData\Roaming\Ulozto File Manager
2012-01-14 11:29:55 ----D---- C:\smazaratory
2012-01-12 17:51:49 ----D---- C:\Program Files (x86)\Microsoft Lync
2012-01-12 07:01:48 ----D---- C:\ProgramData\Cisco
2012-01-11 14:03:47 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-01-11 14:03:47 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-01-11 14:03:47 ----A---- C:\Windows\system32\quartz.dll
2012-01-11 14:03:46 ----A---- C:\Windows\system32\qdvd.dll
2012-01-11 14:01:44 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-01-11 14:01:44 ----A---- C:\Windows\system32\ntdll.dll
2012-01-11 14:00:03 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-01-11 14:00:03 ----A---- C:\Windows\system32\packager.dll
2011-12-29 19:08:28 ----D---- C:\ProgramData\realtech VR
2011-12-29 19:08:22 ----D---- C:\Program Files (x86)\realtech VR
2011-12-29 19:04:26 ----D---- C:\Program Files (x86)\Angry Birds Seasons
======List of files/folders modified in the last 1 month======
2012-01-28 07:48:41 ----D---- C:\Windows\Prefetch
2012-01-28 07:48:35 ----D---- C:\Windows\Temp
2012-01-28 07:48:28 ----RD---- C:\Program Files
2012-01-28 07:36:21 ----SHD---- C:\System Volume Information
2012-01-28 07:04:07 ----D---- C:\Users\phairnix\AppData\Roaming\Skype
2012-01-28 04:23:20 ----D---- C:\Windows\system32\config
2012-01-27 23:08:55 ----D---- C:\ProgramData\LogMeIn
2012-01-27 15:09:01 ----SHD---- C:\Windows\Installer
2012-01-27 15:09:00 ----A---- C:\Windows\ODBC.INI
2012-01-27 08:20:20 ----D---- C:\Program Files (x86)\Opera
2012-01-26 23:15:57 ----D---- C:\Windows\System32
2012-01-26 23:15:57 ----D---- C:\Windows\inf
2012-01-26 23:15:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-26 23:09:01 ----D---- C:\Users\phairnix\AppData\Roaming\G-Recorder
2012-01-26 23:08:31 ----D---- C:\Windows\Minidump
2012-01-26 23:08:21 ----D---- C:\Windows
2012-01-26 18:29:10 ----RD---- C:\Program Files (x86)
2012-01-26 11:13:18 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-26 08:05:28 ----D---- C:\Windows\system32\drivers
2012-01-26 08:05:19 ----D---- C:\Windows\SysWOW64
2012-01-26 07:59:49 ----D---- C:\Program Files (x86)\Proxy Checker Pro
2012-01-24 03:17:26 ----D---- C:\temp
2012-01-21 17:50:40 ----D---- C:\Users\phairnix\AppData\Roaming\Azuon
2012-01-21 15:35:33 ----SHD---- C:\$Recycle.Bin
2012-01-21 11:01:39 ----D---- C:\Windows\system32\Tasks
2012-01-21 11:01:23 ----HD---- C:\ProgramData
2012-01-20 17:04:26 ----SD---- C:\Users\phairnix\AppData\Roaming\Microsoft
2012-01-20 09:25:18 ----D---- C:\Windows\Logs
2012-01-20 07:50:35 ----D---- C:\Users\phairnix\AppData\Roaming\vlc
2012-01-20 01:37:10 ----D---- C:\Windows\system32\catroot2
2012-01-19 18:15:46 ----D---- C:\Windows\winsxs
2012-01-19 15:23:33 ----RSD---- C:\Windows\Fonts
2012-01-18 23:23:37 ----D---- C:\Program Files (x86)\FitLinie
2012-01-12 17:55:23 ----D---- C:\Windows\system32\drivers\etc
2012-01-12 11:26:48 ----D---- C:\Windows\ehome
2012-01-12 07:02:04 ----D---- C:\Windows\system32\DriverStore
2012-01-12 07:02:04 ----D---- C:\Windows\system32\catroot
2012-01-12 03:02:41 ----A---- C:\Windows\system32\MRT.exe
2012-01-04 17:12:44 ----D---- C:\Windows\Microsoft.NET
2012-01-04 17:12:43 ----RSD---- C:\Windows\assembly
2012-01-04 16:46:57 ----D---- C:\Program Files (x86)\Microsoft Office
2012-01-04 16:46:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-12-29 19:12:50 ----D---- C:\Users\phairnix\AppData\Roaming\Rovio
2011-12-29 15:39:48 ----D---- C:\Program Files (x86)\Angry Birds
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 avfwot;avfwot; C:\Windows\system32\DRIVERS\avfwot.sys [2011-09-16 139512]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-12-08 130760]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2011-09-15 27760]
R1 CbFs;CbFs; \??\C:\Windows\system32\drivers\cbfs.sys [2010-02-16 191960]
R1 cbfs3;cbfs3; \??\C:\Windows\system32\drivers\cbfs3.sys [2011-11-04 349072]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2011-05-15 230352]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-08-15 224048]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-08-15 128816]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-09-15 97312]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2010-09-17 72216]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-13 5020672]
R3 avfwim;AvFw Packet Filter Miniport; C:\Windows\system32\DRIVERS\avfwim.sys [2011-09-16 113768]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-15 254528]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-05-03 2854504]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2010-09-17 11552]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-08-15 146736]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-08-15 165680]
R3 WinUsb;WinUsb Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\PORTABLE\Mediacoder\SysInfoX64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []
S3 vpnva;Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64; C:\Windows\system32\DRIVERS\vpnva64.sys []
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 AntiVirFirewallService;Avira FireWall; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [2011-10-05 616400]
R2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [2011-12-08 342480]
R2 AntiVirService;Avira Realtime Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-10-05 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-05 86224]
R2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-10-05 463824]
R2 Apache2.2;Apache2.2; c:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-12-19 375176]
R2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2011-12-19 147336]
R2 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2010-11-08 407424]
R2 mysql;mysql; c:\xampp\mysql\bin\mysqld.exe [2010-12-03 8133120]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-01-15 266240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;SluĹľba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;SluĹľba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-05-14 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
uz nekolik tydnu mam problemem se "zatezovymi spickami"..Proste chvili na PC treba ani nemusim pracovat,na pozadi by nemela zadna narocna cinnost probihat,nicmene znicehonic zacne silene hucet vetrak a vytizeni CPU se dostane na 99%...Pri pohledu na proces co to zpusobuje to jsou vzdy dva-svchost.exe spusteny systemem (tj.neumim ho sestrelit) a plugin-container.exe (spusteny pode mnou a umim ho sestrelit,soucas Firefoxe,predpokladam asi nejaky spatny plugin..
Nicmene ve vetsine pripadu je to ten svchost...

Dale mam z netradicnejsich pgmu spusteny pgm Wuala coz je program na backup syncing and sharing na cloudu a Evernote pro poznamky...System mam Windows 7 x64,jinak mam Avira Internet Security..
Dal posilam vypis z RSIT,dekuji moc..!
Logfile of random's system information tool 1.09 (written by random/random)
Run by phairnix at 2012-01-28 07:48:27
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 55 GB (53%) free of 104 GB
Total RAM: 3583 MB (31% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:48:40, on 28.1.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
D:\PORTABLE\uTorrent\utorrent.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files (x86)\G-Recorder\G-Recorder.exe
C:\Users\phairnix\AppData\Roaming\Wuala\Wuala.exe
C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Altap Salamander\salamand.exe
D:\PORTABLE\AIMP\AIMP3.exe
D:\PORTABLE\Winamp\winamp.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
C:\Program Files (x86)\Sony\Content Transfer\ContentTransfer.exe
D:\PORTABLE\SkypePortable\App\Skype\Phone\Skype.exe
C:\Program Files (x86)\The KMPlayer\KMPlayer.exe
D:\PORTABLE\esmska\jre\launch4j-tmp\esmska-portable.exe
C:\Program Files (x86)\Trillian\trillian.exe
c:\program files (x86)\trillian\plugins\skypekit.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\program files (x86)\avira\antivir desktop\avscan.exe
D:\PORTABLE\GoogleChromePortable\GoogleChromePortable.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\usrreq.exe
C:\Program Files\trend micro\phairnix.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "D:\PORTABLE\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
O4 - Startup: EvernoteTray.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
O4 - Startup: G-Recorder.lnk = C:\Program Files (x86)\G-Recorder\G-Recorder.exe
O4 - Startup: Wuala.lnk = phairnix\AppData\Roaming\Wuala\Wuala.exe
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\G-Recorder\Skype4COM.dll
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll
O23 - Service: ABBYY FineReader 10 CE Licensing Service (ABBYY.Licensing.FineReader.Corporate.10.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\httpd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: SluĹľba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: SluĹľba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - c:\xampp\mysql\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10934 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"c:\xampp\apache\bin\httpd.exe" -k runservice
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
"C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe"
"C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe"
c:\xampp\mysql\bin\mysqld.exe --defaults-file=c:\xampp\mysql\bin\my.ini mysql
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\xampp\apache\bin\httpd.exe -d C:/xampp/apache
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
"C:\Windows\WindowsMobile\wmdcBase.exe"
"D:\PORTABLE\uTorrent\utorrent.exe"
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
"C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe"
"C:\Program Files (x86)\G-Recorder\G-Recorder.exe"
"C:\Users\phairnix\AppData\Roaming\Wuala\Wuala.exe" -silent
"C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe" -Embedding
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_0000066c
\??\C:\Windows\system32\conhost.exe "2094170491926193660611031634-2054667384-8162304231243279574-1689610033-1676429469
"C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE"
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Altap Salamander\salamand.exe"
"D:\PORTABLE\procexp64.exe"
"D:\PORTABLE\AIMP\AIMP3.exe"
"D:\PORTABLE\Winamp\winamp.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Internet Explorer\IELowutil.exe" -embedding
"C:\Program Files (x86)\Evernote\Evernote\Evernote.exe"
"C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-83785e93-a51c-4639-acb0-b98f9311fa10 -SystemEventPortName:HostProcess-f8f5107a-9b5b-43bd-9e55-dfa2101070a8 -IoCancelEventPortName:HostProcess-643d51d7-992e-4110-90ef-5de9d4c82a0f -NonStateChangingEventPortName:HostProcess-dac607f9-fc47-4f64-942a-68b3531f207e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:678d13c7-699f-40cd-99d7-78f7a3c8f687
"C:\Program Files (x86)\Sony\Content Transfer\ContentTransfer.exe" -s
"D:\PORTABLE\SkypePortable\App\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\The KMPlayer\KMPlayer.exe"
"D:\PORTABLE\esmska\jre\launch4j-tmp\esmska-portable.exe" -jar "D:\PORTABLE\esmska\esmska.jar" -c config
"C:\Program Files (x86)\Trillian\trillian.exe"
skypekit.exe -f "c:\users\phairnix\appdata\roaming\trillian\users\phairnix\skype"
\??\C:\Windows\system32\conhost.exe "1918199290-1204787487-2204236587004736171544541836-584324748-1348621957-1864879321
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6900.ac5eb70.569956581 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 6900 "\\.\pipe\gecko-crash-server-pipe.6900" plugin
"C:\program files (x86)\avira\antivir desktop\avscan.exe" /CFG="C:\program files (x86)\avira\antivir desktop\sysscan.avp"
"D:\PORTABLE\GoogleChromePortable\GoogleChromePortable.exe"
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --disk-cache-dir="C:\Users\phairnix\AppData\Local\Temp\GoogleChromePortable"
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --type=renderer --disable-client-side-phishing-detection --lang=cs --force-fieldtest=ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_2s_queue_prefetch/DnsParallelism/parallel_8/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --channel=5416.05108868.1961429424 /prefetch:3
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --type=renderer --disable-client-side-phishing-detection --lang=cs --force-fieldtest=CacheSize/CacheSizeGroup_0/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/max_2s_queue_prefetch/DnsParallelism/parallel_8/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_60/Prefetch/ContentPrefetchDisabled/ProxyConnectionImpact/proxy_connections_32/SSLFalseStart/FalseStart_enabled/SpdyCwnd/cwnd16/SpdyImpact/npn_with_spdy/ --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --channel=5416.075B66C0.65531656 /prefetch:3
C:\Windows\system32\rundll32.exe "D:\PORTABLE\GOOGLE~1\App\CHROME~1\120742~1.100\gcswf32.dll",BrokerMain browser=chrome
"D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\chrome.exe" --type=plugin --plugin-path="D:\PORTABLE\GoogleChromePortable\App\Chrome-bin\12.0.742.100\gcswf32.dll" --user-data-dir="D:\PORTABLE\GoogleChromePortable\Data\profile" --lang=cs --channel=5416.0752CFA0.656417793 /prefetch:4 --flash-broker=5772
"C:\Program Files (x86)\Opera\opera.exe"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe"
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe" -RunMxAddonsMgr -UserName:"guest" -LangIni:"C:\Program Files (x86)\Maxthon3\Language\cs-cz.ini"
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe" -RunResMgr -MainFrmIpc:"IPC_M_R_000009C0" -UsersFolder:"C:\Users\phairnix\AppData\Roaming\Maxthon3\Users\" -UserName:"guest" -LangIni:"C:\Program Files (x86)\Maxthon3\Language\cs-cz.ini" -AppDataPath:"C:\Users\phairnix\AppData\Roaming\Maxthon3\" -ProductType:"intl"
"C:\Program Files (x86)\Maxthon3\Bin\Maxthon.exe" -RunCore -CoreType:"webkit-normal-0-000009C0" -MainFrmIpc:"IPC_M_C_000009C0" -ResMgrIpc:"IPC_R_C_000009C0" -UserName:"guest" -LangIni:"C:\Program Files (x86)\Maxthon3\Language\cs-cz.ini" -AppDataPath:"C:\Users\phairnix\AppData\Roaming\Maxthon3\" -ProductType:"intl" -CustomCacheFolder:"%TEMP%\Maxthon3Cache\Temp\Webkit\Cache"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-43d0031a-88dd-4831-b2b9-96f3356c2491 -SystemEventPortName:HostProcess-0cc4992f-6f32-44ee-9e9a-f5bfbd378d6d -IoCancelEventPortName:HostProcess-a156902a-aee5-4df1-bcc9-3059b816cf04 -NonStateChangingEventPortName:HostProcess-e0934d74-3f19-445f-9549-c37488c69da3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:6bf5a79b-55e0-455e-97e8-82e02dac5320
wmiadap.exe /R /T
C:\Windows\system32\wbem\wmiprvse.exe
"D:\DOWNLOAD\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
/u
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\phairnix\AppData\Roaming\Mozilla\Firefox\Profiles\i0zo0t83.default
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, LogMeInClient@logmein.com:1.0.0.608, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=1.1.9]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\phairnix\AppData\Roaming\Mozilla\Firefox\Profiles\i0zo0t83.default\extensions\
LogMeInClient@logmein.com
{53A03D43-5363-4669-8190-99061B2DEBA6}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5FF49FE8-B332-4CB9-B102-FB6951629E55}]
Virtual Storage Mount Notification - C:\Windows\system32\CbFsMntNtf3.dll [2011-11-04 191504]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5FF49FE8-B332-4CB9-B102-FB6951629E55}]
Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll [2011-11-04 158224]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-05-03 11842152]
"LogMeIn GUI"=C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [2010-09-17 57928]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=D:\PORTABLE\uTorrent\utorrent.exe [2010-12-17 396152]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-01-15 147456]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ContentTransferWMDetector.exe"=C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe [2009-11-19 583016]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2011-10-05 258512]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
C:\Users\phairnix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
EvernoteClipper.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
EvernoteTray.lnk - C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe
G-Recorder.lnk - C:\Program Files (x86)\G-Recorder\G-Recorder.exe
Wuala.lnk - C:\Users\phairnix\AppData\Roaming\Wuala\Wuala.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll [2011-11-04 191504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Virtual Storage Mount Notification - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll [2011-11-04 191504]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoFolderOptions"=0
"NoDriveTypeAutoRun"=95
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
"Debugger=""Nç?"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files\EmEditor\EMEDITOR.EXE" "%1"
======List of files/folders created in the last 1 month======
2012-01-28 07:48:28 ----D---- C:\Program Files\trend micro
2012-01-28 07:48:27 ----D---- C:\rsit
2012-01-26 18:29:10 ----D---- C:\Program Files (x86)\Evernote
2012-01-26 07:47:45 ----D---- C:\Users\phairnix\AppData\Roaming\SpiderOak
2012-01-26 07:46:30 ----D---- C:\Program Files (x86)\SpiderOak
2012-01-26 07:16:52 ----D---- C:\Program Files (x86)\SugarSync
2012-01-22 09:49:22 ----D---- C:\Program Files (x86)\Evopedia
2012-01-21 15:23:12 ----D---- C:\Program Files (x86)\Audiograbber
2012-01-21 13:35:05 ----D---- C:\Users\phairnix\AppData\Roaming\Trillian
2012-01-21 13:34:12 ----D---- C:\Program Files (x86)\Trillian
2012-01-21 11:07:14 ----D---- C:\Program Files\CDBurnerXP
2012-01-21 11:01:23 ----D---- C:\ProgramData\Skype
2012-01-20 07:33:51 ----D---- C:\Users\phairnix\AppData\Roaming\Faces
2012-01-19 18:46:01 ----D---- C:\Program Files (x86)\Vitware
2012-01-19 18:18:05 ----SHD---- C:\~LD
2012-01-19 18:17:04 ----A---- C:\Windows\system32\drivers\cbfs.sys
2012-01-19 15:23:25 ----D---- C:\Users\phairnix\AppData\Roaming\Maxthon3
2012-01-19 15:23:21 ----D---- C:\Program Files (x86)\Maxthon3
2012-01-19 11:55:18 ----D---- C:\Program Files (x86)\Wuala OverlayIcons
2012-01-19 11:55:17 ----A---- C:\Windows\system32\CbFsMntNtf3.dll
2012-01-19 11:55:16 ----A---- C:\Windows\SYSWOW64\CbFsNetRdr3.dll
2012-01-19 11:55:16 ----A---- C:\Windows\SYSWOW64\CbFsMntNtf3.dll
2012-01-19 11:55:16 ----A---- C:\Windows\system32\CbFsNetRdr3.dll
2012-01-19 11:55:14 ----A---- C:\Windows\system32\drivers\cbfs3.sys
2012-01-19 11:55:13 ----D---- C:\Program Files (x86)\Wuala CBFS
2012-01-19 11:55:02 ----D---- C:\Users\phairnix\AppData\Roaming\Wuala
2012-01-14 16:11:10 ----D---- C:\Users\phairnix\AppData\Roaming\Ulozto File Manager
2012-01-14 11:29:55 ----D---- C:\smazaratory
2012-01-12 17:51:49 ----D---- C:\Program Files (x86)\Microsoft Lync
2012-01-12 07:01:48 ----D---- C:\ProgramData\Cisco
2012-01-11 14:03:47 ----A---- C:\Windows\SYSWOW64\quartz.dll
2012-01-11 14:03:47 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2012-01-11 14:03:47 ----A---- C:\Windows\system32\quartz.dll
2012-01-11 14:03:46 ----A---- C:\Windows\system32\qdvd.dll
2012-01-11 14:01:44 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2012-01-11 14:01:44 ----A---- C:\Windows\system32\ntdll.dll
2012-01-11 14:00:03 ----A---- C:\Windows\SYSWOW64\packager.dll
2012-01-11 14:00:03 ----A---- C:\Windows\system32\packager.dll
2011-12-29 19:08:28 ----D---- C:\ProgramData\realtech VR
2011-12-29 19:08:22 ----D---- C:\Program Files (x86)\realtech VR
2011-12-29 19:04:26 ----D---- C:\Program Files (x86)\Angry Birds Seasons
======List of files/folders modified in the last 1 month======
2012-01-28 07:48:41 ----D---- C:\Windows\Prefetch
2012-01-28 07:48:35 ----D---- C:\Windows\Temp
2012-01-28 07:48:28 ----RD---- C:\Program Files
2012-01-28 07:36:21 ----SHD---- C:\System Volume Information
2012-01-28 07:04:07 ----D---- C:\Users\phairnix\AppData\Roaming\Skype
2012-01-28 04:23:20 ----D---- C:\Windows\system32\config
2012-01-27 23:08:55 ----D---- C:\ProgramData\LogMeIn
2012-01-27 15:09:01 ----SHD---- C:\Windows\Installer
2012-01-27 15:09:00 ----A---- C:\Windows\ODBC.INI
2012-01-27 08:20:20 ----D---- C:\Program Files (x86)\Opera
2012-01-26 23:15:57 ----D---- C:\Windows\System32
2012-01-26 23:15:57 ----D---- C:\Windows\inf
2012-01-26 23:15:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-26 23:09:01 ----D---- C:\Users\phairnix\AppData\Roaming\G-Recorder
2012-01-26 23:08:31 ----D---- C:\Windows\Minidump
2012-01-26 23:08:21 ----D---- C:\Windows
2012-01-26 18:29:10 ----RD---- C:\Program Files (x86)
2012-01-26 11:13:18 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-01-26 08:05:28 ----D---- C:\Windows\system32\drivers
2012-01-26 08:05:19 ----D---- C:\Windows\SysWOW64
2012-01-26 07:59:49 ----D---- C:\Program Files (x86)\Proxy Checker Pro
2012-01-24 03:17:26 ----D---- C:\temp
2012-01-21 17:50:40 ----D---- C:\Users\phairnix\AppData\Roaming\Azuon
2012-01-21 15:35:33 ----SHD---- C:\$Recycle.Bin
2012-01-21 11:01:39 ----D---- C:\Windows\system32\Tasks
2012-01-21 11:01:23 ----HD---- C:\ProgramData
2012-01-20 17:04:26 ----SD---- C:\Users\phairnix\AppData\Roaming\Microsoft
2012-01-20 09:25:18 ----D---- C:\Windows\Logs
2012-01-20 07:50:35 ----D---- C:\Users\phairnix\AppData\Roaming\vlc
2012-01-20 01:37:10 ----D---- C:\Windows\system32\catroot2
2012-01-19 18:15:46 ----D---- C:\Windows\winsxs
2012-01-19 15:23:33 ----RSD---- C:\Windows\Fonts
2012-01-18 23:23:37 ----D---- C:\Program Files (x86)\FitLinie
2012-01-12 17:55:23 ----D---- C:\Windows\system32\drivers\etc
2012-01-12 11:26:48 ----D---- C:\Windows\ehome
2012-01-12 07:02:04 ----D---- C:\Windows\system32\DriverStore
2012-01-12 07:02:04 ----D---- C:\Windows\system32\catroot
2012-01-12 03:02:41 ----A---- C:\Windows\system32\MRT.exe
2012-01-04 17:12:44 ----D---- C:\Windows\Microsoft.NET
2012-01-04 17:12:43 ----RSD---- C:\Windows\assembly
2012-01-04 16:46:57 ----D---- C:\Program Files (x86)\Microsoft Office
2012-01-04 16:46:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-12-29 19:12:50 ----D---- C:\Users\phairnix\AppData\Roaming\Rovio
2011-12-29 15:39:48 ----D---- C:\Program Files (x86)\Angry Birds
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 avfwot;avfwot; C:\Windows\system32\DRIVERS\avfwot.sys [2011-09-16 139512]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-12-08 130760]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2011-09-15 27760]
R1 CbFs;CbFs; \??\C:\Windows\system32\drivers\cbfs.sys [2010-02-16 191960]
R1 cbfs3;cbfs3; \??\C:\Windows\system32\drivers\cbfs3.sys [2011-11-04 349072]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2011-05-15 230352]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2011-08-15 224048]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2011-08-15 128816]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-09-15 97312]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [2010-09-17 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2010-09-17 72216]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-13 5020672]
R3 avfwim;AvFw Packet Filter Miniport; C:\Windows\system32\DRIVERS\avfwim.sys [2011-09-16 113768]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-05-15 254528]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-05-03 2854504]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2010-09-17 11552]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2011-08-15 146736]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2011-08-15 165680]
R3 WinUsb;WinUsb Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\PORTABLE\Mediacoder\SysInfoX64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2010-12-02 19968]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2010-11-21 20992]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2010-11-21 34816]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []
S3 vpnva;Cisco AnyConnect VPN Virtual Miniport Adapter for Windows x64; C:\Windows\system32\DRIVERS\vpnva64.sys []
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Corporate.10.0;ABBYY FineReader 10 CE Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\CE\NetworkLicenseServer.exe [2009-12-19 814344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
R2 AntiVirFirewallService;Avira FireWall; C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe [2011-10-05 616400]
R2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe [2011-12-08 342480]
R2 AntiVirService;Avira Realtime Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-10-05 110032]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-05 86224]
R2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [2011-10-05 463824]
R2 Apache2.2;Apache2.2; c:\xampp\apache\bin\httpd.exe [2010-10-18 20549]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-12-19 375176]
R2 LMIMaint;LogMeIn Maintenance Service; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [2011-12-19 147336]
R2 LogMeIn;LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [2010-11-08 407424]
R2 mysql;mysql; c:\xampp\mysql\bin\mysqld.exe [2010-12-03 8133120]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2007-01-15 266240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;SluĹľba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 gupdatem;SluĹľba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-19 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-05-14 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------