info.txt logfile of random's system information tool 1.09 2011-08-09 17:35:15
======Uninstall list======
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Program Files\Sony Ericsson\Update Engine\uninst.exe
-->C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\Windows\UNNeroShowTime.exe /UNINSTALL
-->C:\Windows\UNNeroVision.exe /UNINSTALL
-->C:\Windows\UNRecode.exe /UNINSTALL
-->MsiExec /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
3DVIA Shape-->MsiExec.exe /X{64374640-CFDA-4F4C-887A-1CA665B9294C}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.exe -maintain activex
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\FlashUtil10s_Plugin.exe -maintain plugin
Adobe Reader X (10.1.0)-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-AA1000000001}
Advanced SystemCare 4-->"C:\Program Files\IObit\Advanced SystemCare 4\unins000.exe"
Aktualizácie NVIDIA 1.3.5-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVI2.DLL",UninstallPackage Display.Update
AntikVirtualSTB 10.1.7-->"C:\Program Files\AntikVirtualSTB\unins000.exe"
ASCOM Platform 5.0b-->MsiExec.exe /I{14C10725-0018-4534-AE5E-547C08B737B7}
avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
Babylon toolbar on IE-->"C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\uninstall.exe"
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
Dassault Systemes Software VC9 Prerequisites x86-->MsiExec.exe /X{50BFDB3B-9CA8-477E-82FE-D3CD5F58F8C4}
DC++ 0.782-->"C:\Program Files\DC++\uninstall.exe"
FORM studio-->"C:\Program Files\KASTNER software\FORM studio SK\unins000.exe"
Frontlines: Fuel of War-->"C:\Program Files\InstallShield Installation Information\{C711E88C-9DC2-4254-A989-D6E017844DDF}\setup.exe" -runfromtemp -l0x0009 -removeonly
Game Booster-->"C:\Program Files\IObit\Game Booster\unins000.exe"
Google Earth-->MsiExec.exe /X{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
IObit Malware Fighter-->"C:\Program Files\IObit\IObit Malware Fighter\unins001.exe"
IObit Toolbar v4.5-->MsiExec.exe /X{B5C46C83-CF59-4A5F-AD95-AED24DB07D00}
Java(TM) 6 Update 26-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216023FF}
Media Go-->MsiExec.exe /X{C6AC04F5-5916-4A02-BC36-AF5BC0A3CBD4}
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft VC9 runtime libraries-->MsiExec.exe /I{553C904F-57A2-4113-888E-BA0C3D1C69C0}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{6AFCA4E1-9B78-3640-8F72-A7BF33448200}
Microsoft WorldWide Telescope-->MsiExec.exe /I{B10D5B3D-1CCD-4019-9287-8FC8CFD62A60}
Moj CEWE FOTOSVET-->"C:\Program Files\Fotolab\Moj CEWE FOTOSVET\uninstall.exe"
Mozilla Firefox 5.0 (x86 sk)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Ultra Edition-->MsiExec.exe /I{4908C75E-E5E2-43F7-B1DF-023CBA831051}
NVIDIA Grafický ovládač 275.33-->"C:\Windows\system32\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.1\NVI2.DLL",UninstallPackage Display.Driver
OpenOffice.org 3.2-->MsiExec.exe /I{FAB43061-FEFB-46E8-A159-96710395DB5E}
Protected Folder-->"C:\Program Files\IObit\Protected Folder\unins000.exe"
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
Skype Toolbars-->MsiExec.exe /I{B6CF2967-C81E-40C0-9815-C05774FEF120}
Skype™ 5.3-->MsiExec.exe /X{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}
Smart Defrag 2-->"C:\Program Files\IObit\Smart Defrag 2\unins000.exe"
Sony Ericsson PC Companion 2.01.210-->"C:\Program Files\InstallShield Installation Information\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}\setup.exe" -runfromtemp -l0x0009 -removeonly
Sony Ericsson Update Engine-->C:\Program Files\Sony Ericsson\Update Engine\uninst.exe
SweetIM for Messenger 3.3-->MsiExec.exe /X{1D301950-EA2F-4882-9AA0-49467756842A}
SweetIM Toolbar for Internet Explorer 4.0-->MsiExec.exe /X{BF67F764-95B6-4360-BB57-B2E5AA6C814B}
Total Commander (Remove or Repair)-->c:\program files\totalcmd\tcuninst.exe
Uniblue DriverScanner-->"C:\Program Files\Uniblue\DriverScanner\unins000.exe"
Uniblue RegistryBooster-->"C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe" REMOVE=TRUE MODIFY=FALSE
Uniblue SpeedUpMyPC-->"C:\Program Files\Uniblue\SpeedUpMyPC\unins000.exe"
VLC media player 1.1.10-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WinRAR archivátor-->C:\Program Files\WinRAR\uninstall.exe
X-Lite 3.0-->"C:\Program Files\CounterPath\X-Lite\unins000.exe"
======System event log======
Computer Name: Zizko-PC
Event Code: 7000
Message: Spustenie služby Computer Browser zlyhalo kvôli nasledujúcej chybe:
Služba neodpovedala na riadiaci alebo spúšťací pokyn načas.
Record Number: 29939
Source Name: Service Control Manager
Time Written: 20110306133607.500000-000
Event Type: Error
User:
Computer Name: Zizko-PC
Event Code: 7011
Message: Počas čakania na odpoveď transakcie od služby Browser bol dosiahnutý časový limit (30000 ms).
Record Number: 29938
Source Name: Service Control Manager
Time Written: 20110306133607.500000-000
Event Type: Error
User:
Computer Name: Zizko-PC
Event Code: 1014
Message: Name resolution for the name www.google.sk timed out after none of the configured DNS servers responded.
Record Number: 29926
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20110306124530.179888-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: Zizko-PC
Event Code: 1014
Message: Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Record Number: 29799
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20110306032516.758836-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
Computer Name: Zizko-PC
Event Code: 1014
Message: Name resolution for the name photos-d.ak.fbcdn.net timed out after none of the configured DNS servers responded.
Record Number: 29796
Source Name: Microsoft-Windows-DNS-Client
Time Written: 20110306032453.439592-000
Event Type: Warning
User: NT AUTHORITY\NETWORK SERVICE
=====Application event log=====
Computer Name: Zizko-PC
Event Code: 1000
Message:
Record Number: 172
Source Name: Microsoft-Windows-User Profiles General
Time Written: 20101210161805.000000-000
Event Type: Error
User:
Computer Name: Zizko-PC
Event Code: 1000
Message:
Record Number: 171
Source Name: Microsoft-Windows-User Profiles General
Time Written: 20101210161805.000000-000
Event Type: Error
User:
Computer Name: Zizko-PC
Event Code: 1000
Message:
Record Number: 170
Source Name: Microsoft-Windows-User Profiles General
Time Written: 20101210161805.000000-000
Event Type: Error
User:
Computer Name: Zizko-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 164
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20101210161431.202892-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Zizko-PC
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 94
Source Name: Microsoft-Windows-Search
Time Written: 20101210161204.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: 37L4247D28-05
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247D28-05$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101210160056.985650-000
Event Type: Audit Success
User:
Computer Name: 37L4247D28-05
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247D28-05$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101210160056.985650-000
Event Type: Audit Success
User:
Computer Name: 37L4247D28-05
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x234bd
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101210160056.814049-000
Event Type: Audit Success
User:
Computer Name: 37L4247D28-05
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101210160055.581647-000
Event Type: Audit Success
User:
Computer Name: 37L4247D28-05
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20101210160055.503647-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=2
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 23 Stepping 10, GenuineIntel
"PROCESSOR_REVISION"=170a
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Zizko at 2011-08-09 17:35:06
Microsoft Windows 7 Ultimate
System drive C: has 24 GB (47%) free of 50 GB
Total RAM: 3070 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:35:13, on 09.08.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe
C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe
C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
D:\HRY\RSIT.exe
C:\Program Files\trend micro\Zizko.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IObit Toolbar - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.5\iobitToolbarIE.dll
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: (no name) - {d1fce654-5fd1-48ad-b13c-5064736120b7} - (no file)
O2 - BHO: IObit Toolbar - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.5\iobitToolbarIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: IObit Toolbar - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.5\iobitToolbarIE.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
O4 - HKCU\..\Run: [SpeedUpMyPC] "C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe" delay 20000
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3813502773-2544309892-3725276685-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3813502773-2544309892-3725276685-1001\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - http://195.28.70.134/kapor2/lib/mgaxctrl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - (no file)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Sony Ericsson PCCompanion - Avanquest Software - C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe
--
End of file - 7246 bytes
======Scheduled tasks folder======
C:\Windows\tasks\DriverScanner.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\RegistryBooster.job
C:\Windows\tasks\SpeedUpMyPC.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Zizko\AppData\Roaming\Mozilla\Firefox\Profiles\juz6r2qv.default
prefs.js - "keyword.URL" - "http://search.babylon.com/?babsrc=SP_ss ... =100370&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files\Sony\Media Go\npmediago.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.65\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=1.1.10]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
ffxtlbr@babylon.com
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
yahoo.xml
zoznam-sk.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F}]
IObit Toolbar - C:\Program Files\IObit Toolbar\IE\4.5\iobitToolbarIE.dll [2011-06-24 734048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\bh\BabylonToolbar.dll [2011-06-27 270960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-05-16 1164680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2010-10-18 1485112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.4.31.2\BabylonToolbarTlbr.dll [2011-06-27 237168]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2010-10-18 1485112]
{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - IObit Toolbar - C:\Program Files\IObit Toolbar\IE\4.5\iobitToolbarIE.dll [2011-06-24 734048]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-11-30 9914984]
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2011-07-04 3493720]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-06-16 413072]
"SpeedUpMyPC"=C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe [2011-05-23 67960]
"DriverScanner"=C:\Program Files\Uniblue\DriverScanner\launcher.exe [2011-05-16 338296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-05 1305408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
C:\Program Files\uTorrent\uTorrent.exe [2011-04-04 399736]
C:\Users\Zizko\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 3 months======
2011-08-09 17:35:06 ----D---- C:\rsit
2011-08-04 13:22:39 ----D---- C:\ProgramData\SXR Software
2011-08-04 01:28:25 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-08-04 01:27:30 ----RHD---- C:\MSOCache
2011-08-03 22:15:33 ----D---- C:\Users\Zizko\AppData\Roaming\DassaultSystemes
2011-08-03 22:15:33 ----D---- C:\ProgramData\DassaultSystemes
2011-08-03 22:15:26 ----D---- C:\Program Files\Dassault Systemes
2011-08-03 19:43:35 ----D---- C:\Users\Zizko\AppData\Roaming\OpenOffice.org
2011-08-03 19:37:03 ----D---- C:\Program Files\OpenOffice.org 3
2011-07-19 00:31:27 ----D---- C:\Windows\system32\Wat
2011-07-19 00:14:03 ----A---- C:\Windows\system32\XpsPrint.dll
2011-07-19 00:14:03 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2011-07-19 00:13:45 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-07-19 00:13:45 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-19 00:13:45 ----A---- C:\Windows\system32\cdd.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\wscsvc.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\wscapi.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\winhttp.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\WebClnt.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\upnp.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\slwga.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\msxml6.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\msxml3.dll
2011-07-19 00:13:37 ----A---- C:\Windows\system32\davclnt.dll
2011-07-19 00:13:23 ----A---- C:\Windows\system32\kerberos.dll
2011-07-19 00:13:15 ----A---- C:\Windows\system32\odbc32.dll
2011-07-19 00:13:02 ----A---- C:\Windows\system32\tzres.dll
2011-07-19 00:12:48 ----A---- C:\Windows\system32\consent.exe
2011-07-19 00:12:39 ----A---- C:\Windows\system32\webio.dll
2011-07-19 00:12:32 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2011-07-18 21:59:50 ----A---- C:\Windows\system32\RTNUninst32.dll
2011-07-18 21:59:50 ----A---- C:\Windows\system32\RtNicProp32.dll
2011-07-18 21:59:50 ----A---- C:\Windows\system32\drivers\Rt86win7.sys
2011-07-18 21:58:48 ----A---- C:\Windows\system32\nvvsvc.exe
2011-07-18 21:58:48 ----A---- C:\Windows\system32\nvsvcr.dll
2011-07-18 21:58:48 ----A---- C:\Windows\system32\nvsvc.dll
2011-07-18 21:58:48 ----A---- C:\Windows\system32\nvshext.dll
2011-07-18 21:58:48 ----A---- C:\Windows\system32\nvmctray.dll
2011-07-18 21:58:48 ----A---- C:\Windows\system32\nvcpl.dll
2011-07-18 21:58:47 ----A---- C:\Windows\system32\easyupdatusapiu.dll
2011-07-18 21:55:54 ----A---- C:\Windows\system32\OpenCL.dll
2011-07-18 21:55:54 ----A---- C:\Windows\system32\nvoglv32.dll
2011-07-18 21:55:54 ----A---- C:\Windows\system32\nvgenco322090.dll
2011-07-18 21:55:54 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvdispco3220150.dll
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvcuvid.dll
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvcuvenc.dll
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvcuda.dll
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvcompiler.dll
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvapi.dll
2011-07-18 21:37:18 ----D---- C:\ProgramData\Uniblue
2011-07-18 19:10:31 ----D---- C:\Program Files\IObit Toolbar
2011-07-18 19:10:31 ----D---- C:\Program Files\Common Files\Spigot
2011-07-18 19:10:31 ----D---- C:\Program Files\Application Updater
2011-07-18 19:10:26 ----A---- C:\Windows\system32\SmartDefragBootTime.exe
2011-07-18 19:10:26 ----A---- C:\Windows\system32\drivers\SmartDefragDriver.sys
2011-07-18 19:10:23 ----D---- C:\ProgramData\IObit
2011-07-18 19:09:44 ----D---- C:\Users\Zizko\AppData\Roaming\IObit
2011-07-18 19:09:43 ----D---- C:\Program Files\IObit
2011-07-18 18:53:27 ----HDC---- C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-07-14 23:12:15 ----A---- C:\Windows\system32\d3dx9_26.dll
2011-07-14 23:11:50 ----D---- C:\Windows\7104189AC5924A56AC9E7C0CA135DA3C.TMP
2011-07-14 23:11:14 ----D---- C:\ProgramData\SweetIM
2011-07-14 23:11:14 ----D---- C:\Program Files\SweetIM
2011-07-14 23:07:03 ----D---- C:\Program Files\BabylonToolbar
2011-07-14 23:06:59 ----D---- C:\Users\Zizko\AppData\Roaming\Babylon
2011-07-14 23:06:59 ----D---- C:\ProgramData\Babylon
2011-07-13 12:50:16 ----D---- C:\ProgramData\tmp
2011-07-13 12:50:15 ----D---- C:\ProgramData\hps
2011-07-13 12:49:35 ----D---- C:\Program Files\Fotolab
2011-07-11 11:59:35 ----ASH---- C:\pagefile.sys
2011-06-27 17:59:54 ----D---- C:\Program Files\Microsoft Silverlight
2011-06-27 17:53:09 ----D---- C:\Program Files\Common Files\ASCOM
2011-06-27 17:53:09 ----D---- C:\Program Files\ASCOM
2011-06-15 13:42:43 ----D---- C:\Program Files\Common Files\Adobe
2011-06-11 00:15:16 ----D---- C:\Program Files\Mozilla Firefox
2011-06-10 12:36:06 ----D---- C:\Program Files\Common Files\Java
2011-06-10 12:35:53 ----A---- C:\Windows\system32\javaws.exe
2011-06-10 12:35:53 ----A---- C:\Windows\system32\javaw.exe
2011-06-10 12:35:53 ----A---- C:\Windows\system32\java.exe
2011-05-26 23:51:59 ----RSH---- C:\boot.ini
2011-05-26 23:47:19 ----RASH---- C:\MSDOS.SYS
2011-05-26 23:47:19 ----RASH---- C:\IO.SYS
2011-05-26 23:46:43 ----D---- C:\Program Files\Wopti
2011-05-26 23:29:02 ----D---- C:\Users\Zizko\AppData\Roaming\Smart PC Solutions
2011-05-26 17:53:51 ----D---- C:\Users\Zizko\AppData\Roaming\Uniblue
2011-05-26 17:53:48 ----D---- C:\Program Files\Uniblue
2011-05-26 17:48:56 ----D---- C:\Users\Zizko\AppData\Roaming\com.w3i.FlipToast
2011-05-26 17:48:47 ----D---- C:\Program Files\Zrychlenie PC
2011-05-26 17:48:40 ----SHD---- C:\Windows\system32\AI_RecycleBin
2011-05-26 17:48:37 ----D---- C:\ProgramData\W3i
2011-05-26 17:48:37 ----D---- C:\Program Files\W3i
2011-05-10 20:23:21 ----A---- C:\Windows\system32\xinput1_3.dll
2011-05-10 20:23:21 ----A---- C:\Windows\system32\d3dx9_31.dll
2011-05-10 20:22:51 ----D---- C:\Windows\system32\AGEIA
2011-05-10 20:22:48 ----D---- C:\Program Files\AGEIA Technologies
2011-05-10 20:22:44 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2011-05-10 20:22:01 ----D---- C:\ProgramData\THQ
======List of files/folders modified in the last 3 months======
2011-08-09 17:35:07 ----D---- C:\Program Files\trend micro
2011-08-09 17:07:02 ----D---- C:\Windows\Temp
2011-08-09 17:05:04 ----D---- C:\Windows\system32\config
2011-08-09 16:56:45 ----D---- C:\Windows\System32
2011-08-09 16:56:45 ----D---- C:\Windows\inf
2011-08-09 16:56:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-08 19:19:50 ----D---- C:\Users\Zizko\AppData\Roaming\vlc
2011-08-08 17:02:24 ----D---- C:\Windows
2011-08-08 13:57:22 ----D---- C:\Windows\Minidump
2011-08-08 00:31:06 ----D---- C:\Users\Zizko\AppData\Roaming\Skype
2011-08-07 14:34:55 ----D---- C:\Windows\system32\wbem
2011-08-07 14:30:15 ----D---- C:\Windows\Tasks
2011-08-07 14:30:15 ----D---- C:\Windows\system32\wfp
2011-08-07 14:29:26 ----D---- C:\Windows\system32\DriverStore
2011-08-07 14:29:26 ----D---- C:\Windows\system32\catroot2
2011-08-07 14:28:40 ----SHD---- C:\System Volume Information
2011-08-06 20:31:47 ----D---- C:\Users\Zizko\AppData\Roaming\DC++
2011-08-05 11:52:23 ----D---- C:\Windows\system32\drivers
2011-08-05 11:52:23 ----D---- C:\Users\Zizko\AppData\Roaming\uTorrent
2011-08-05 11:52:19 ----RSD---- C:\Windows\assembly
2011-08-05 11:52:18 ----HD---- C:\ProgramData
2011-08-05 11:52:18 ----D---- C:\Program Files\Common Files\System
2011-08-05 11:52:18 ----D---- C:\Program Files
2011-08-04 01:28:00 ----D---- C:\Program Files\Microsoft Office
2011-08-03 22:59:58 ----SHD---- C:\Windows\Installer
2011-08-03 22:15:03 ----D---- C:\Windows\winsxs
2011-08-03 20:37:32 ----D---- C:\Windows\system32\wdi
2011-08-03 19:37:08 ----RSD---- C:\Windows\Fonts
2011-07-24 18:45:13 ----D---- C:\Users\Zizko\AppData\Roaming\dvdcss
2011-07-21 23:23:39 ----D---- C:\Windows\Prefetch
2011-07-19 20:10:28 ----RD---- C:\Program Files\Skype
2011-07-19 20:10:21 ----D---- C:\Windows\system32\Tasks
2011-07-19 20:10:14 ----D---- C:\ProgramData\Skype
2011-07-19 20:10:12 ----D---- C:\Program Files\Common Files
2011-07-19 20:09:44 ----D---- C:\Users\Zizko\AppData\Roaming\skypePM
2011-07-19 19:00:41 ----D---- C:\ProgramData\DAEMON Tools Lite
2011-07-19 15:04:18 ----D---- C:\Windows\rescache
2011-07-19 14:26:47 ----D---- C:\Windows\system32\NDF
2011-07-19 00:31:27 ----D---- C:\Windows\system32\sk-SK
2011-07-19 00:31:27 ----D---- C:\Program Files\Windows Mail
2011-07-19 00:29:46 ----D---- C:\Windows\system32\catroot
2011-07-18 23:16:40 ----D---- C:\ProgramData\Microsoft Help
2011-07-18 23:16:27 ----SD---- C:\ProgramData\Microsoft
2011-07-18 23:16:27 ----D---- C:\Program Files\Microsoft.NET
2011-07-18 23:16:27 ----D---- C:\Program Files\Common Files\microsoft shared
2011-07-18 23:16:17 ----D---- C:\Windows\ShellNew
2011-07-18 23:15:44 ----D---- C:\Program Files\MSBuild
2011-07-18 23:14:59 ----A---- C:\Windows\win.ini
2011-07-18 21:58:54 ----RD---- C:\Users
2011-07-18 21:58:54 ----D---- C:\ProgramData\NVIDIA
2011-07-18 21:58:52 ----D---- C:\Program Files\NVIDIA Corporation
2011-07-18 21:58:47 ----D---- C:\Windows\Help
2011-07-18 21:55:54 ----A---- C:\Windows\system32\nvwgf2um.dll
2011-07-18 21:55:53 ----A---- C:\Windows\system32\nvd3dum.dll
2011-07-18 18:34:54 ----D---- C:\Windows\Logs
2011-07-18 18:29:40 ----HD---- C:\Program Files\InstallShield Installation Information
2011-07-04 13:43:51 ----A---- C:\Windows\system32\aswBoot.exe
2011-06-25 09:09:46 ----D---- C:\Program Files\Google
2011-06-15 13:42:44 ----D---- C:\ProgramData\Adobe
2011-06-12 14:36:29 ----D---- C:\ProgramData\Sony Ericsson
2011-06-12 14:36:26 ----D---- C:\Program Files\Sony Ericsson
2011-06-11 00:15:29 ----D---- C:\Users\Zizko\AppData\Roaming\Mozilla
2011-06-10 12:35:49 ----D---- C:\Program Files\Java
2011-06-07 15:53:18 ----D---- C:\Program Files\Common Files\AOL
2011-06-07 15:45:45 ----D---- C:\Windows\system32\appmgmt
2011-05-26 23:43:49 ----AD---- C:\ProgramData\TEMP
2011-05-26 22:31:47 ----D---- C:\Windows\Downloaded Program Files
2011-05-26 17:48:47 ----D---- C:\Program Files\Adobe
2011-05-26 17:48:45 ----D---- C:\Users\Zizko\AppData\Roaming\Adobe
2011-05-14 20:24:14 ----SD---- C:\Users\Zizko\AppData\Roaming\Microsoft
2011-05-11 02:46:15 ----D---- C:\PerfLogs
2011-05-10 20:22:46 ----D---- C:\Windows\LiveKernelReports
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-02-09 431672]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R2 Angelnt;Angelnt; C:\Windows\System32\Drivers\ANGELNT.SYS [2011-02-11 51072]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 PfFilter;PfFilter; \??\C:\Program Files\IObit\Protected Folder\pffilter.sys [2011-03-16 32672]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-30 3317800]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2011-07-18 267880]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2010-12-19 27632]
S3 agw3llqk;agw3llqk; C:\Windows\system32\drivers\agw3llqk.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2010-12-19 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2010-12-19 25512]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsu.sys [2010-12-02 137600]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RegFilter;RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2011-03-23 30600]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 UrlFilter;UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2011-03-23 19280]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 WinUsb;Sony Ericsson USB Device sa0101 Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S3 WoptiHWDetect;WoptiHWDetect; C:\Windows\system32\drivers\WoptiHWDetect.sys []
S4 FileMonitor;FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2011-07-11 18768]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe [2011-06-16 353168]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2011-06-24 393112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-07-04 42184]
R2 IMFservice;IMF Service; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-07-14 820568]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-27 136176]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-03-27 136176]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S3 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-05-21 615528]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-07-19 1343400]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
pekne vas prosiim o kontrolu rsit log
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 41
- Registrován: 27 říj 2010 12:10
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: pekne vas prosiim o kontrolu rsit log
Log vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.