Odstranenie viru
Napsal: 23 pro 2011 13:35
Nazdar.
V PC sa mi usídlili nejaké víry. MSE ich dokáže identifikovať, no odstrániť ich už nedokáže. Resp ich odstráni ale oni sa tam akosi vždy zase dostanú. Už som ich deletoval asi 30 krát.
Zišla by sa mi teda menšia pomoc. Ďakujem
Logfile of random's system information tool 1.09 (written by random/random)
Run by zhulo at 2011-12-23 13:29:46
Microsoft Windows 7 Home Premium
System drive C: has 84 GB (52%) free of 162 GB
Total RAM: 3950 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:29:51, on 23. 12. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Program Files (x86)\SONY\Media Gallery\ElbServer.exe
C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe
C:\Program Files (x86)\QIP 2012\qip.exe
C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\JetAudio\JetAudio.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\zhulo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:61515
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\zhulo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\zhulo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
O4 - HKCU\..\Run: [Elbserver] C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe /Stay
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [Infium] "C:\Program Files (x86)\QIP 2012\qip.exe" /autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: networx - odkaz.lnk = D:\Programy\Networkx\networx.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - (no file)
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE1DD507-F8EB-473E-8404-24DC08E19615}: NameServer = 192.168.159.1
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Connectify - Unknown owner - C:\Program Files (x86)\Connectify\ConnectifyService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QipGuard - QIP.ru - C:\Program Files (x86)\QipGuard\QipGuard.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14737 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
atieclxx
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Connectify\ConnectifyService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"ConnectifyD.exe"
\??\C:\Windows\system32\conhost.exe "57414032494255252-1317325762-521202166131345650-2969980831824692596795876542
"C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe"
"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
"C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\Config"
C:\Windows\System32\svchost.exe -k HPZ12
"c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\QipGuard\QipGuard.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe"
"C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe"
"C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe"
C:\Windows\SysWOW64\DllHost.exe /Processid:{78FD0120-D39C-45D8-A9BE-2B802B3C23E5}
"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe"
"C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe"
"C:\Program Files\Sony\VAIO Smart Network\VSNService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe"
WLIDSvcM.exe 2116
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3f5259fa-b1d9-4781-8373-811e8053d49f -SystemEventPortName:HostProcess-49bd1781-c98f-4ec0-b655-281cda64e64e -IoCancelEventPortName:HostProcess-e3025db7-c01e-494c-9f94-0546dcf52192 -NonStateChangingEventPortName:HostProcess-1a9192e1-81b2-4a1f-8411-f2140873468b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5e126911-b112-4270-b802-8c7d64404242
"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {FB8240BD-FA2E-45F6-89CE-63029574ECD9}
"C:\Windows\system32\Dwm.exe"
"C:\Windows\explorer.exe"
/Device:000000a1
"C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" /Start
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Apoint\Apoint.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Apoint\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
"C:\Program Files (x86)\SONY\Media Gallery\ElbServer.exe" /Stay
"C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe" /p
"C:\Program Files (x86)\QIP 2012\qip.exe" /autorun
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe"
"C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Apoint\Apvfb.exe"
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "176492264837980681-1653284727-213745225588013939210793543051948117380-1244489485
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"D:\Programy\Networkx\networx.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Sony\VAIO Power Management\SPMService.exe"
"C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata"
C:\Program Files\Sony\VAIO Care/listener.exe /silent /slot=0
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Sony\VAIO Update Common\VUAgent.exe"
"C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe" /Stationary
"C:\Program Files\Sony\VAIO Care\VCsystray.exe"
"C:\Program Files\Sony\VAIO Care\VCService.exe"
"C:\Program Files\Sony\VAIO Care\VCAgent.exe"
C:\Windows\System32\vds.exe
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /startalways
StartVC*SelfHeal*silence+EU\sk-SK
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\JetAudio\JetAudio.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1744.ec9d5d0.604507084 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 1744 "\\.\pipe\gecko-crash-server-pipe.1744" plugin
taskeng.exe {171DDF94-6DE8-4BEA-8531-5C196F5FFAE0}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey FB5A471E-4A89-91CB-240E-F9F498497F17 -Reinvoke
"C:\Users\zhulo\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-949965917-3753343039-3259282721-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-949965917-3753343039-3259282721-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\zhulo\AppData\Roaming\Mozilla\Firefox\Profiles\bwbpj3wv.default
prefs.js - "browser.startup.homepage" - "http://www.google.com/ig"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Users\zhulo\AppData\Roaming\Mozilla\Firefox\Profiles\bwbpj3wv.default\extensions\
{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
C:\Users\zhulo\AppData\Roaming\Mozilla\Firefox\Profiles\bwbpj3wv.default\searchplugins\
conduit.xml
qip-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-10-26 75656]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\zhulo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2011-08-22 141184]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-08-03 42272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-16 9636896]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2009-11-04 208384]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SugarSync"=C:\Program Files (x86)\SugarSync\SugarSyncManager.exe [2011-11-11 12210176]
"Elbserver"=C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe [2009-10-15 72192]
"QIP Internet Guardian"=C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe [2011-11-23 191440]
"Infium"=C:\Program Files (x86)\QIP 2012\qip.exe [2011-11-23 7248848]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ISBMgr.exe"=C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2009-08-26 320880]
"MarketingTools"=C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [2011-10-03 26624]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-20 102400]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe [2011-08-31 1047208]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\zhulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
networx - odkaz.lnk - D:\Programy\Networkx\networx.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-12-16 268800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2010-06-22 253288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"HideSCAHealth"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-12-23 13:29:46 ----D---- C:\rsit
2011-12-23 13:29:46 ----D---- C:\Program Files\trend micro
2011-12-23 12:08:01 ----D---- C:\Users\zhulo\AppData\Roaming\Malwarebytes
2011-12-23 12:07:46 ----D---- C:\ProgramData\Malwarebytes
2011-12-23 12:07:43 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-23 12:07:43 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-12-14 23:35:18 ----D---- C:\Program Files (x86)\StarUML
2011-12-10 21:39:04 ----D---- C:\Program Files\NETGATE
2011-12-09 19:55:43 ----D---- C:\Program Files (x86)\5E4AF
2011-12-09 19:55:10 ----D---- C:\Users\zhulo\AppData\Roaming\C2E5E
2011-12-09 19:55:10 ----D---- C:\Program Files (x86)\LP
2011-12-04 18:06:23 ----D---- C:\Users\zhulo\AppData\Roaming\TeamViewer
2011-12-01 17:02:04 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-12-01 17:02:00 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-12-01 17:01:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-12-01 16:50:29 ----D---- C:\Program Files (x86)\Ubisoft
2011-11-30 20:30:21 ----A---- C:\Windows\SYSWOW64\perf-ReportServer$DATABAZA-rsctr.dll
2011-11-30 20:30:21 ----A---- C:\Windows\system32\perf-ReportServer$DATABAZA-rsctr.dll
2011-11-30 20:29:35 ----A---- C:\Windows\SYSWOW64\perf-MSSQL10_50.DATABAZA-sqlagtctr.dll
2011-11-30 20:29:34 ----A---- C:\Windows\system32\perf-MSSQL10_50.DATABAZA-sqlagtctr.dll
2011-11-30 20:29:20 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$DATABAZA-sqlctr10.50.1600.1.dll
2011-11-30 20:29:19 ----A---- C:\Windows\system32\perf-MSSQL$DATABAZA-sqlctr10.50.1600.1.dll
2011-11-30 20:25:52 ----D---- C:\Windows\system32\RsFx
2011-11-30 20:25:38 ----D---- C:\Program Files\Microsoft Analysis Services
2011-11-30 20:25:04 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-11-30 20:25:04 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0
2011-11-30 20:23:32 ----D---- C:\Windows\system32\1033
2011-11-30 18:23:10 ----D---- C:\Users\zhulo\AppData\Roaming\postgresql
2011-11-30 18:11:11 ----D---- C:\Program Files\PostgreSQL
2011-11-30 17:39:57 ----D---- C:\Program Files\SQLXML 4.0
2011-11-30 17:39:57 ----D---- C:\Program Files (x86)\SQLXML 4.0
2011-11-30 17:34:10 ----D---- C:\Windows\SYSWOW64\1033
2011-11-30 17:16:25 ----D---- C:\Program Files\Microsoft.NET
2011-11-30 17:02:26 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2011-11-30 17:02:04 ----D---- C:\Program Files\Microsoft SQL Server
2011-11-26 12:48:28 ----D---- C:\Users\zhulo\AppData\Roaming\InstallShield
2011-11-26 12:30:59 ----D---- C:\Users\zhulo\AppData\Roaming\Stardock
2011-11-26 12:30:58 ----HDC---- C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
2011-11-26 12:30:57 ----D---- C:\Program Files (x86)\Stardock
2011-11-26 11:56:35 ----HD---- C:\SPLASH.SYS
2011-11-25 23:43:59 ----D---- C:\Users\zhulo\AppData\Roaming\QIP
2011-11-25 23:32:40 ----D---- C:\Windows\system32\Macromed
2011-11-25 23:01:10 ----A---- C:\Windows\system32\win32k.sys
2011-11-25 23:00:03 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-11-25 22:59:16 ----A---- C:\Windows\system32\msfeeds.dll
2011-11-25 22:59:16 ----A---- C:\Windows\system32\ieui.dll
2011-11-25 22:59:16 ----A---- C:\Windows\system32\iepeers.dll
2011-11-25 22:59:15 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-11-25 22:59:15 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-11-25 22:59:15 ----A---- C:\Windows\system32\mshtmled.dll
2011-11-25 22:59:15 ----A---- C:\Windows\system32\mshtml.dll
2011-11-25 22:59:15 ----A---- C:\Windows\system32\ieframe.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\url.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\mstime.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\msfeedssync.exe
2011-11-25 22:59:14 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\licmgr10.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\iedkcs32.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\url.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\wininet.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\urlmon.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\jsproxy.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\iertutil.dll
2011-11-25 22:51:14 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-11-25 22:51:13 ----A---- C:\Windows\system32\psisdecd.dll
2011-11-25 22:50:43 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-11-25 22:50:43 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2011-11-25 22:50:43 ----A---- C:\Windows\system32\oleaut32.dll
2011-11-25 22:50:43 ----A---- C:\Windows\system32\oleacc.dll
2011-11-25 22:49:46 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-11-25 22:49:46 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-11-25 22:49:46 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbctrac.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbccu32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbccr32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbccp32.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\user.exe
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-11-25 22:48:24 ----A---- C:\Windows\system32\wow64win.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\wow64cpu.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\wow64.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\winsrv.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\ntvdm64.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\KernelBase.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\kernel32.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\conhost.exe
2011-11-25 22:47:55 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-11-25 22:47:55 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-11-25 22:47:55 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-11-25 22:47:32 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-11-25 22:46:32 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-11-25 22:42:39 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-11-25 22:42:39 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-11-25 22:42:39 ----A---- C:\Windows\system32\drivers\srv.sys
2011-11-25 22:42:04 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-11-25 22:41:42 ----A---- C:\Windows\system32\drivers\afd.sys
2011-11-25 22:40:43 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-11-25 22:40:43 ----A---- C:\Windows\system32\inetcomm.dll
2011-11-25 22:40:24 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-11-25 22:40:24 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-11-25 22:40:24 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-11-25 22:40:24 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-11-25 22:40:24 ----A---- C:\Windows\system32\dnsapi.dll
2011-11-25 22:40:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-11-25 22:40:06 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-11-25 22:40:06 ----A---- C:\Windows\system32\vbscript.dll
2011-11-25 22:40:06 ----A---- C:\Windows\system32\jscript.dll
2011-11-25 22:39:48 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-11-25 22:39:48 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-11-25 22:39:48 ----A---- C:\Windows\system32\atmlib.dll
2011-11-25 22:39:48 ----A---- C:\Windows\system32\atmfd.dll
2011-11-25 22:39:14 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-11-25 22:39:00 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-11-25 22:38:44 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-11-25 22:38:44 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-11-25 22:38:44 ----A---- C:\Windows\system32\mfc42u.dll
2011-11-25 22:38:44 ----A---- C:\Windows\system32\mfc42.dll
2011-11-25 22:38:16 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-11-25 22:38:16 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-11-25 22:38:16 ----A---- C:\Windows\system32\mstscax.dll
2011-11-25 22:38:16 ----A---- C:\Windows\system32\mstsc.exe
2011-11-25 22:37:55 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-11-25 22:37:55 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-11-25 22:37:55 ----A---- C:\Windows\system32\sbe.dll
2011-11-25 22:37:55 ----A---- C:\Windows\system32\CPFilters.dll
2011-11-25 22:37:54 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-11-25 22:37:54 ----A---- C:\Windows\system32\EncDec.dll
2011-11-25 22:37:20 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-11-25 22:37:20 ----A---- C:\Windows\system32\ntdll.dll
2011-11-25 22:36:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-11-25 22:36:03 ----A---- C:\Windows\system32\kerberos.dll
2011-11-25 22:35:44 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-11-25 22:35:44 ----A---- C:\Windows\system32\odbc32.dll
2011-11-25 22:35:28 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-11-25 22:35:28 ----A---- C:\Windows\system32\t2embed.dll
2011-11-25 22:35:11 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-11-25 22:35:11 ----A---- C:\Windows\system32\ole32.dll
2011-11-25 22:34:55 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-11-25 22:34:55 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-11-25 22:34:42 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-11-25 22:34:42 ----A---- C:\Windows\system32\comctl32.dll
2011-11-25 22:34:26 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-11-25 22:34:26 ----A---- C:\Windows\system32\wmpmde.dll
2011-11-25 22:34:10 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-11-25 22:34:10 ----A---- C:\Windows\system32\schannel.dll
2011-11-25 22:33:59 ----A---- C:\Windows\system32\consent.exe
2011-11-25 22:33:29 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-11-25 22:33:29 ----A---- C:\Windows\system32\webio.dll
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-11-25 22:33:10 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-11-25 22:33:10 ----A---- C:\Windows\system32\taskschd.dll
2011-11-25 22:33:10 ----A---- C:\Windows\system32\taskeng.exe
2011-11-25 22:33:10 ----A---- C:\Windows\system32\taskcomp.dll
2011-11-25 22:33:10 ----A---- C:\Windows\system32\schtasks.exe
2011-11-25 22:33:10 ----A---- C:\Windows\system32\schedsvc.dll
2011-11-25 22:32:25 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-11-25 22:32:25 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-11-25 22:32:25 ----A---- C:\Windows\system32\wmploc.DLL
2011-11-25 22:32:25 ----A---- C:\Windows\system32\wmp.dll
2011-11-25 22:32:08 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-11-25 22:32:08 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-11-25 22:31:59 ----A---- C:\Windows\system32\spoolsv.exe
2011-11-25 22:31:46 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-11-25 22:31:46 ----A---- C:\Windows\system32\msxml3.dll
2011-11-25 22:31:31 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-11-25 22:31:31 ----A---- C:\Windows\system32\rtutils.dll
2011-11-25 22:31:22 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-11-25 22:30:55 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-11-25 22:30:55 ----A---- C:\Windows\system32\shell32.dll
2011-11-25 22:30:42 ----A---- C:\Windows\system32\cdd.dll
2011-11-25 22:30:28 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-11-25 22:30:28 ----A---- C:\Windows\system32\asycfilt.dll
2011-11-25 22:30:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-11-25 22:30:13 ----A---- C:\Windows\system32\wintrust.dll
2011-11-25 22:30:06 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-11-25 22:30:06 ----A---- C:\Windows\system32\cabview.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\tsbyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\quartz.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\msyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\iyuv_32.dll
2011-11-25 22:29:45 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-11-25 22:29:45 ----A---- C:\Windows\system32\msvidc32.dll
2011-11-25 22:29:45 ----A---- C:\Windows\system32\msrle32.dll
2011-11-25 22:21:23 ----D---- C:\Users\zhulo\AppData\Roaming\IObit
2011-11-25 22:12:42 ----D---- C:\Windows\Profiles
======List of files/folders modified in the last 1 month======
2011-12-23 13:29:51 ----D---- C:\Windows\Prefetch
2011-12-23 13:29:46 ----RD---- C:\Program Files
2011-12-23 13:29:28 ----D---- C:\Windows\Temp
2011-12-23 12:40:48 ----D---- C:\Windows
2011-12-23 12:22:43 ----SHD---- C:\Windows\Installer
2011-12-23 12:22:38 ----HD---- C:\Config.Msi
2011-12-23 12:22:34 ----RD---- C:\Program Files (x86)
2011-12-23 12:22:34 ----D---- C:\ProgramData\Apple Computer
2011-12-23 12:20:57 ----D---- C:\Program Files (x86)\Black_Box
2011-12-23 12:20:56 ----DC---- C:\Windows\system32\DRVSTORE
2011-12-23 12:20:56 ----D---- C:\Windows\SysWOW64
2011-12-23 12:20:56 ----D---- C:\Windows\system32\drivers
2011-12-23 12:20:56 ----D---- C:\Windows\System32
2011-12-23 12:20:09 ----SHD---- C:\System Volume Information
2011-12-23 12:17:40 ----D---- C:\Windows\system32\DriverStore
2011-12-23 12:17:40 ----D---- C:\Windows\system32\catroot
2011-12-23 12:17:40 ----D---- C:\Windows\inf
2011-12-23 12:17:32 ----D---- C:\Program Files\Common Files
2011-12-23 12:16:23 ----D---- C:\Windows\system32\Tasks
2011-12-23 12:13:27 ----D---- C:\Users\zhulo\AppData\Roaming\DAEMON Tools Lite
2011-12-23 12:12:40 ----D---- C:\Windows\Minidump
2011-12-23 12:12:40 ----D---- C:\Windows\Logs
2011-12-23 12:08:35 ----D---- C:\Windows\SYSWOW64\drivers
2011-12-23 12:07:46 ----HD---- C:\ProgramData
2011-12-23 11:24:03 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-12-23 11:23:39 ----D---- C:\Windows\system32\config
2011-12-23 11:13:36 ----D---- C:\Windows\Tasks
2011-12-23 11:12:59 ----A---- C:\Windows\SYSWOW64\log.txt
2011-12-19 23:40:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-18 19:01:50 ----D---- C:\Users\zhulo\AppData\Roaming\Skype
2011-12-11 20:29:53 ----D---- C:\Users\zhulo\AppData\Roaming\codeblocks
2011-12-11 19:00:53 ----SD---- C:\Users\zhulo\AppData\Roaming\Microsoft
2011-12-10 23:04:30 ----D---- C:\Users\zhulo\AppData\Roaming\BSplayer
2011-12-10 11:46:00 ----D---- C:\Windows\system32\catroot2
2011-12-09 22:23:31 ----SD---- C:\ProgramData\Microsoft
2011-12-09 15:26:36 ----RSD---- C:\Windows\Fonts
2011-12-08 20:32:11 ----D---- C:\Program Files (x86)\Connectify
2011-12-04 15:15:36 ----D---- C:\Users\zhulo\AppData\Roaming\FileZilla
2011-12-03 20:42:11 ----RSD---- C:\Windows\assembly
2011-12-01 23:53:33 ----D---- C:\Windows\Microsoft.NET
2011-12-01 16:59:51 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-01 14:32:22 ----D---- C:\Program Files (x86)\CodeBlocks
2011-11-30 20:24:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-30 20:24:32 ----D---- C:\Windows\winsxs
2011-11-30 20:23:54 ----D---- C:\Program Files (x86)\Microsoft Office
2011-11-30 18:12:56 ----RD---- C:\Users
2011-11-30 17:50:54 ----D---- C:\Windows\system32\NDF
2011-11-30 17:48:12 ----D---- C:\ProgramData\Microsoft Help
2011-11-30 17:39:40 ----D---- C:\Windows\Registration
2011-11-30 17:34:11 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-11-30 17:34:03 ----D---- C:\Program Files (x86)\Common Files
2011-11-30 17:16:27 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-11-30 17:15:26 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2011-11-29 13:46:53 ----D---- C:\Update
2011-11-26 12:51:25 ----D---- C:\Program Files\Sony
2011-11-26 12:51:09 ----D---- C:\ProgramData\Sony Corporation
2011-11-26 12:49:49 ----D---- C:\Program Files (x86)\SONY
2011-11-26 12:44:38 ----D---- C:\Program Files\Common Files\Sony Shared
2011-11-26 11:56:32 ----D---- C:\Program Files (x86)\Downloaded Installations
2011-11-25 23:43:59 ----D---- C:\Users\zhulo\AppData\Roaming\QipGuard
2011-11-25 23:43:55 ----D---- C:\Program Files (x86)\QIP 2012
2011-11-25 23:31:09 ----D---- C:\Program Files (x86)\Google
2011-11-25 23:29:08 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-11-25 23:19:20 ----D---- C:\Program Files\Common Files\System
2011-11-25 23:19:20 ----D---- C:\Program Files (x86)\Internet Explorer
2011-11-25 23:19:19 ----D---- C:\Windows\SYSWOW64\migration
2011-11-25 23:19:19 ----D---- C:\Windows\system32\migration
2011-11-25 23:19:19 ----D---- C:\Program Files\Internet Explorer
2011-11-25 23:19:18 ----D---- C:\Windows\ehome
2011-11-25 23:19:16 ----D---- C:\Windows\AppPatch
2011-11-25 23:19:11 ----D---- C:\Program Files\Windows Mail
2011-11-25 23:19:10 ----D---- C:\Program Files\Windows Media Player
2011-11-25 23:19:10 ----D---- C:\Program Files (x86)\Windows Media Player
2011-11-25 23:19:10 ----D---- C:\Program Files (x86)\Windows Mail
2011-11-25 22:38:25 ----D---- C:\Program Files\DVD Maker
2011-11-25 22:38:24 ----D---- C:\OS
2011-11-25 22:24:48 ----D---- C:\ProgramData\Partner
2011-11-25 22:24:48 ----D---- C:\ProgramData\EA Logs
2011-11-25 00:48:11 ----D---- C:\Users\zhulo\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2009-11-21 537112]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-05-20 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 cnnctfy2;Connectify LightWeight Filter; C:\Windows\system32\DRIVERS\cnnctfy2.sys [2011-11-13 31344]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 rimspci;rimspci; C:\Windows\system32\drivers\rimssne64.sys [2009-11-06 93696]
R2 risdsnpe;risdsnpe; C:\Windows\system32\drivers\risdsne64.sys [2009-09-15 75776]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-10-08 6661120]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-10-08 195584]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-11-04 253488]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2009-05-26 19968]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-11-12 1542656]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-03 270912]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-12-14 56344]
R3 Impcd;Impcd; C:\Windows\system32\drivers\Impcd.sys [2009-11-13 151936]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-16 2212640]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-08-31 25416]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-12-16 213280]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-10-09 109056]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\drivers\SFEP.sys [2009-08-19 11392]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R4 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-10-08 6661120]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-11-18 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-11-18 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-11-18 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-11-18 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-11-18 21160]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-12-16 7778176]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2009-12-16 244736]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-05-10 51712]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S4 RsFx0150;RsFx0150 Driver; C:\Windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-10-08 202752]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 873248]
R2 Connectify;Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [2011-12-01 69632]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-11-21 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-14 268824]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
R2 MsDtsServer;SQL Server Integration Services; C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [2005-10-14 195288]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 MSSQLSERVER;SQL Server (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2005-10-14 39379672]
R2 MSSQLServerOLAPService;SQL Server Analysis Services (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe [2005-10-14 29323480]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 QipGuard;QipGuard; C:\Program Files (x86)\QipGuard\QipGuard.exe [2011-11-23 191440]
R2 SampleCollector;VAIO Care Performance Service; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [2011-01-29 259192]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R2 uCamMonitor;CamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-14 2320920]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe [2010-05-28 205168]
R2 VCFw;VAIO Content Folder Watcher; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-01-20 887000]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2011-05-19 549616]
R2 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager; C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-10-25 387896]
R2 VSNService;VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2010-08-11 845312]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SpfService;VAIO Entertainment Common Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2011-01-20 286936]
R3 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2009-11-30 571248]
R3 VCService;VCService; C:\Program Files\Sony\VAIO Care\VCService.exe [2011-02-14 44736]
R3 VUAgent;VUAgent; C:\Program Files\Sony\VAIO Update Common\VUAgent.exe [2011-09-23 1429608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
S2 msftesql;SQL Server FullText Search (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [2005-08-26 155856]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-08-31 362992]
S2 SQLAgent$DATABAZA;SQL Server Agent (DATABAZA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.DATABAZA\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MSSQLFDLauncher$DATABAZA;SQL Full-text Filter Daemon Launcher (DATABAZA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.DATABAZA\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-08-31 313840]
S3 SOHCImp;VAIO Media plus Content Importer; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2010-09-10 108400]
S3 SOHDms;VAIO Media plus Digital Media Server; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2010-10-12 423280]
S3 SOHDs;VAIO Media plus Device Searcher; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2010-09-10 67952]
S3 SQLSERVERAGENT;SQL Server Agent (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE [2005-10-14 389848]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [2010-09-27 74496]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2011-02-18 99104]
S4 MSOLAP$DATABAZA;SQL Server Analysis Services (DATABAZA); C:\Program Files\Microsoft SQL Server\MSAS10_50.DATABAZA\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]
S4 MSSQL$DATABAZA;SQL Server (DATABAZA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.DATABAZA\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 64216]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 ReportServer$DATABAZA;SQL Server Reporting Services (DATABAZA); C:\Program Files\Microsoft SQL Server\MSRS10_50.DATABAZA\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]
-----------------EOF-----------------
V PC sa mi usídlili nejaké víry. MSE ich dokáže identifikovať, no odstrániť ich už nedokáže. Resp ich odstráni ale oni sa tam akosi vždy zase dostanú. Už som ich deletoval asi 30 krát.
Zišla by sa mi teda menšia pomoc. Ďakujem
Logfile of random's system information tool 1.09 (written by random/random)
Run by zhulo at 2011-12-23 13:29:46
Microsoft Windows 7 Home Premium
System drive C: has 84 GB (52%) free of 162 GB
Total RAM: 3950 MB (39% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:29:51, on 23. 12. 2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16869)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\SugarSync\SugarSyncManager.exe
C:\Program Files (x86)\SONY\Media Gallery\ElbServer.exe
C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe
C:\Program Files (x86)\QIP 2012\qip.exe
C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\JetAudio\JetAudio.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\zhulo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:61515
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\zhulo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Pomocník pri prihlasovaní v konte Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\zhulo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [SugarSync] "C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
O4 - HKCU\..\Run: [Elbserver] C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe /Stay
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [Infium] "C:\Program Files (x86)\QIP 2012\qip.exe" /autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: networx - odkaz.lnk = D:\Programy\Networkx\networx.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - (no file)
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE1DD507-F8EB-473E-8404-24DC08E19615}: NameServer = 192.168.159.1
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Connectify - Unknown owner - C:\Program Files (x86)\Connectify\ConnectifyService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QipGuard - QIP.ru - C:\Program Files (x86)\QipGuard\QipGuard.exe
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: VAIO Care Performance Service (SampleCollector) - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCPerfService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: VCService - Sony Corporation - C:\Program Files\Sony\VAIO Care\VCService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14737 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
atieclxx
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Connectify\ConnectifyService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"ConnectifyD.exe"
\??\C:\Windows\system32\conhost.exe "57414032494255252-1317325762-521202166131345650-2969980831824692596795876542
"C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe"
"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER
"C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe" -s "C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\Config"
C:\Windows\System32\svchost.exe -k HPZ12
"c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\QipGuard\QipGuard.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe"
"C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe"
"C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe"
C:\Windows\SysWOW64\DllHost.exe /Processid:{78FD0120-D39C-45D8-A9BE-2B802B3C23E5}
"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe"
"C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe"
"C:\Program Files\Sony\VAIO Smart Network\VSNService.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe"
WLIDSvcM.exe 2116
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-3f5259fa-b1d9-4781-8373-811e8053d49f -SystemEventPortName:HostProcess-49bd1781-c98f-4ec0-b655-281cda64e64e -IoCancelEventPortName:HostProcess-e3025db7-c01e-494c-9f94-0546dcf52192 -NonStateChangingEventPortName:HostProcess-1a9192e1-81b2-4a1f-8411-f2140873468b -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5e126911-b112-4270-b802-8c7d64404242
"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
taskeng.exe {FB8240BD-FA2E-45F6-89CE-63029574ECD9}
"C:\Windows\system32\Dwm.exe"
"C:\Windows\explorer.exe"
/Device:000000a1
"C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" /Start
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Apoint\Apoint.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Apoint\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
"C:\Program Files (x86)\SugarSync\SugarSyncManager.exe" -startInTray -usedelay=true
"C:\Program Files (x86)\SONY\Media Gallery\ElbServer.exe" /Stay
"C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe" /p
"C:\Program Files (x86)\QIP 2012\qip.exe" /autorun
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe"
"C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Apoint\Apvfb.exe"
"Apntex.exe"
\??\C:\Windows\system32\conhost.exe "176492264837980681-1653284727-213745225588013939210793543051948117380-1244489485
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"D:\Programy\Networkx\networx.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Sony\VAIO Power Management\SPMService.exe"
"C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata"
C:\Program Files\Sony\VAIO Care/listener.exe /silent /slot=0
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Sony\VAIO Update Common\VUAgent.exe"
"C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe" /Stationary
"C:\Program Files\Sony\VAIO Care\VCsystray.exe"
"C:\Program Files\Sony\VAIO Care\VCService.exe"
"C:\Program Files\Sony\VAIO Care\VCAgent.exe"
C:\Windows\System32\vds.exe
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /startalways
StartVC*SelfHeal*silence+EU\sk-SK
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\JetAudio\JetAudio.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=1744.ec9d5d0.604507084 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 1744 "\\.\pipe\gecko-crash-server-pipe.1744" plugin
taskeng.exe {171DDF94-6DE8-4BEA-8531-5C196F5FFAE0}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe9_ Global\UsGthrCtrlFltPipeMssGthrPipe9 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey FB5A471E-4A89-91CB-240E-F9F498497F17 -Reinvoke
"C:\Users\zhulo\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\AutoKMS.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-949965917-3753343039-3259282721-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-949965917-3753343039-3259282721-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\zhulo\AppData\Roaming\Mozilla\Firefox\Profiles\bwbpj3wv.default
prefs.js - "browser.startup.homepage" - "http://www.google.com/ig"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Users\zhulo\AppData\Roaming\Mozilla\Firefox\Profiles\bwbpj3wv.default\extensions\
{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
C:\Users\zhulo\AppData\Roaming\Mozilla\Firefox\Profiles\bwbpj3wv.default\searchplugins\
conduit.xml
qip-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-10-26 75656]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\zhulo\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2011-08-22 141184]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-08-03 42272]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-12-16 9636896]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2009-11-04 208384]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 1436736]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SugarSync"=C:\Program Files (x86)\SugarSync\SugarSyncManager.exe [2011-11-11 12210176]
"Elbserver"=C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe [2009-10-15 72192]
"QIP Internet Guardian"=C:\Users\zhulo\AppData\Roaming\QipGuard\QipGuard.exe [2011-11-23 191440]
"Infium"=C:\Program Files (x86)\QIP 2012\qip.exe [2011-11-23 7248848]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ISBMgr.exe"=C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2009-08-26 320880]
"MarketingTools"=C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [2011-10-03 26624]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-20 102400]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
"Malwarebytes' Anti-Malware (reboot)"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe [2011-08-31 1047208]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\zhulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
networx - odkaz.lnk - D:\Programy\Networkx\networx.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-12-16 268800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll [2010-06-22 253288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"HideSCAHealth"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-12-23 13:29:46 ----D---- C:\rsit
2011-12-23 13:29:46 ----D---- C:\Program Files\trend micro
2011-12-23 12:08:01 ----D---- C:\Users\zhulo\AppData\Roaming\Malwarebytes
2011-12-23 12:07:46 ----D---- C:\ProgramData\Malwarebytes
2011-12-23 12:07:43 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-23 12:07:43 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-12-14 23:35:18 ----D---- C:\Program Files (x86)\StarUML
2011-12-10 21:39:04 ----D---- C:\Program Files\NETGATE
2011-12-09 19:55:43 ----D---- C:\Program Files (x86)\5E4AF
2011-12-09 19:55:10 ----D---- C:\Users\zhulo\AppData\Roaming\C2E5E
2011-12-09 19:55:10 ----D---- C:\Program Files (x86)\LP
2011-12-04 18:06:23 ----D---- C:\Users\zhulo\AppData\Roaming\TeamViewer
2011-12-01 17:02:04 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2011-12-01 17:02:00 ----A---- C:\Windows\system32\d3dx10_42.dll
2011-12-01 17:01:56 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2011-12-01 16:50:29 ----D---- C:\Program Files (x86)\Ubisoft
2011-11-30 20:30:21 ----A---- C:\Windows\SYSWOW64\perf-ReportServer$DATABAZA-rsctr.dll
2011-11-30 20:30:21 ----A---- C:\Windows\system32\perf-ReportServer$DATABAZA-rsctr.dll
2011-11-30 20:29:35 ----A---- C:\Windows\SYSWOW64\perf-MSSQL10_50.DATABAZA-sqlagtctr.dll
2011-11-30 20:29:34 ----A---- C:\Windows\system32\perf-MSSQL10_50.DATABAZA-sqlagtctr.dll
2011-11-30 20:29:20 ----A---- C:\Windows\SYSWOW64\perf-MSSQL$DATABAZA-sqlctr10.50.1600.1.dll
2011-11-30 20:29:19 ----A---- C:\Windows\system32\perf-MSSQL$DATABAZA-sqlctr10.50.1600.1.dll
2011-11-30 20:25:52 ----D---- C:\Windows\system32\RsFx
2011-11-30 20:25:38 ----D---- C:\Program Files\Microsoft Analysis Services
2011-11-30 20:25:04 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2011-11-30 20:25:04 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0
2011-11-30 20:23:32 ----D---- C:\Windows\system32\1033
2011-11-30 18:23:10 ----D---- C:\Users\zhulo\AppData\Roaming\postgresql
2011-11-30 18:11:11 ----D---- C:\Program Files\PostgreSQL
2011-11-30 17:39:57 ----D---- C:\Program Files\SQLXML 4.0
2011-11-30 17:39:57 ----D---- C:\Program Files (x86)\SQLXML 4.0
2011-11-30 17:34:10 ----D---- C:\Windows\SYSWOW64\1033
2011-11-30 17:16:25 ----D---- C:\Program Files\Microsoft.NET
2011-11-30 17:02:26 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2011-11-30 17:02:04 ----D---- C:\Program Files\Microsoft SQL Server
2011-11-26 12:48:28 ----D---- C:\Users\zhulo\AppData\Roaming\InstallShield
2011-11-26 12:30:59 ----D---- C:\Users\zhulo\AppData\Roaming\Stardock
2011-11-26 12:30:58 ----HDC---- C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
2011-11-26 12:30:57 ----D---- C:\Program Files (x86)\Stardock
2011-11-26 11:56:35 ----HD---- C:\SPLASH.SYS
2011-11-25 23:43:59 ----D---- C:\Users\zhulo\AppData\Roaming\QIP
2011-11-25 23:32:40 ----D---- C:\Windows\system32\Macromed
2011-11-25 23:01:10 ----A---- C:\Windows\system32\win32k.sys
2011-11-25 23:00:03 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-11-25 22:59:16 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-11-25 22:59:16 ----A---- C:\Windows\system32\msfeeds.dll
2011-11-25 22:59:16 ----A---- C:\Windows\system32\ieui.dll
2011-11-25 22:59:16 ----A---- C:\Windows\system32\iepeers.dll
2011-11-25 22:59:15 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-11-25 22:59:15 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-11-25 22:59:15 ----A---- C:\Windows\system32\mshtmled.dll
2011-11-25 22:59:15 ----A---- C:\Windows\system32\mshtml.dll
2011-11-25 22:59:15 ----A---- C:\Windows\system32\ieframe.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-11-25 22:59:14 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\url.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\mstime.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\msfeedssync.exe
2011-11-25 22:59:14 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\licmgr10.dll
2011-11-25 22:59:14 ----A---- C:\Windows\system32\iedkcs32.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\url.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-11-25 22:59:13 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\wininet.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\urlmon.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\jsproxy.dll
2011-11-25 22:59:13 ----A---- C:\Windows\system32\iertutil.dll
2011-11-25 22:51:14 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-11-25 22:51:13 ----A---- C:\Windows\system32\psisdecd.dll
2011-11-25 22:50:43 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-11-25 22:50:43 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2011-11-25 22:50:43 ----A---- C:\Windows\system32\oleaut32.dll
2011-11-25 22:50:43 ----A---- C:\Windows\system32\oleacc.dll
2011-11-25 22:49:46 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-11-25 22:49:46 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-11-25 22:49:46 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbctrac.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbccu32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbccr32.dll
2011-11-25 22:48:51 ----A---- C:\Windows\system32\odbccp32.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-11-25 22:48:24 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\user.exe
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-11-25 22:48:24 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-11-25 22:48:24 ----A---- C:\Windows\system32\wow64win.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\wow64cpu.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\wow64.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\winsrv.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\ntvdm64.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\KernelBase.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\kernel32.dll
2011-11-25 22:48:24 ----A---- C:\Windows\system32\conhost.exe
2011-11-25 22:47:55 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-11-25 22:47:55 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-11-25 22:47:55 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-11-25 22:47:32 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-11-25 22:47:32 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-11-25 22:46:32 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-11-25 22:42:39 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-11-25 22:42:39 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-11-25 22:42:39 ----A---- C:\Windows\system32\drivers\srv.sys
2011-11-25 22:42:04 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-11-25 22:41:42 ----A---- C:\Windows\system32\drivers\afd.sys
2011-11-25 22:40:43 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-11-25 22:40:43 ----A---- C:\Windows\system32\inetcomm.dll
2011-11-25 22:40:24 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2011-11-25 22:40:24 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2011-11-25 22:40:24 ----A---- C:\Windows\system32\dnsrslvr.dll
2011-11-25 22:40:24 ----A---- C:\Windows\system32\dnscacheugc.exe
2011-11-25 22:40:24 ----A---- C:\Windows\system32\dnsapi.dll
2011-11-25 22:40:06 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-11-25 22:40:06 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-11-25 22:40:06 ----A---- C:\Windows\system32\vbscript.dll
2011-11-25 22:40:06 ----A---- C:\Windows\system32\jscript.dll
2011-11-25 22:39:48 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2011-11-25 22:39:48 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2011-11-25 22:39:48 ----A---- C:\Windows\system32\atmlib.dll
2011-11-25 22:39:48 ----A---- C:\Windows\system32\atmfd.dll
2011-11-25 22:39:14 ----A---- C:\Windows\system32\FXSCOVER.exe
2011-11-25 22:39:00 ----A---- C:\Windows\system32\drivers\bowser.sys
2011-11-25 22:38:44 ----A---- C:\Windows\SYSWOW64\mfc42u.dll
2011-11-25 22:38:44 ----A---- C:\Windows\SYSWOW64\mfc42.dll
2011-11-25 22:38:44 ----A---- C:\Windows\system32\mfc42u.dll
2011-11-25 22:38:44 ----A---- C:\Windows\system32\mfc42.dll
2011-11-25 22:38:16 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2011-11-25 22:38:16 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2011-11-25 22:38:16 ----A---- C:\Windows\system32\mstscax.dll
2011-11-25 22:38:16 ----A---- C:\Windows\system32\mstsc.exe
2011-11-25 22:37:55 ----A---- C:\Windows\SYSWOW64\sbe.dll
2011-11-25 22:37:55 ----A---- C:\Windows\SYSWOW64\CPFilters.dll
2011-11-25 22:37:55 ----A---- C:\Windows\system32\sbe.dll
2011-11-25 22:37:55 ----A---- C:\Windows\system32\CPFilters.dll
2011-11-25 22:37:54 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-11-25 22:37:54 ----A---- C:\Windows\system32\EncDec.dll
2011-11-25 22:37:20 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2011-11-25 22:37:20 ----A---- C:\Windows\system32\ntdll.dll
2011-11-25 22:36:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2011-11-25 22:36:03 ----A---- C:\Windows\system32\kerberos.dll
2011-11-25 22:35:44 ----A---- C:\Windows\SYSWOW64\odbc32.dll
2011-11-25 22:35:44 ----A---- C:\Windows\system32\odbc32.dll
2011-11-25 22:35:28 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2011-11-25 22:35:28 ----A---- C:\Windows\system32\t2embed.dll
2011-11-25 22:35:11 ----A---- C:\Windows\SYSWOW64\ole32.dll
2011-11-25 22:35:11 ----A---- C:\Windows\system32\ole32.dll
2011-11-25 22:34:55 ----A---- C:\Windows\SYSWOW64\mfc40u.dll
2011-11-25 22:34:55 ----A---- C:\Windows\SYSWOW64\mfc40.dll
2011-11-25 22:34:42 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2011-11-25 22:34:42 ----A---- C:\Windows\system32\comctl32.dll
2011-11-25 22:34:26 ----A---- C:\Windows\SYSWOW64\wmpmde.dll
2011-11-25 22:34:26 ----A---- C:\Windows\system32\wmpmde.dll
2011-11-25 22:34:10 ----A---- C:\Windows\SYSWOW64\schannel.dll
2011-11-25 22:34:10 ----A---- C:\Windows\system32\schannel.dll
2011-11-25 22:33:59 ----A---- C:\Windows\system32\consent.exe
2011-11-25 22:33:29 ----A---- C:\Windows\SYSWOW64\webio.dll
2011-11-25 22:33:29 ----A---- C:\Windows\system32\webio.dll
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\taskschd.dll
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\taskeng.exe
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\taskcomp.dll
2011-11-25 22:33:10 ----A---- C:\Windows\SYSWOW64\schtasks.exe
2011-11-25 22:33:10 ----A---- C:\Windows\system32\wmicmiplugin.dll
2011-11-25 22:33:10 ----A---- C:\Windows\system32\taskschd.dll
2011-11-25 22:33:10 ----A---- C:\Windows\system32\taskeng.exe
2011-11-25 22:33:10 ----A---- C:\Windows\system32\taskcomp.dll
2011-11-25 22:33:10 ----A---- C:\Windows\system32\schtasks.exe
2011-11-25 22:33:10 ----A---- C:\Windows\system32\schedsvc.dll
2011-11-25 22:32:25 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2011-11-25 22:32:25 ----A---- C:\Windows\SYSWOW64\wmp.dll
2011-11-25 22:32:25 ----A---- C:\Windows\system32\wmploc.DLL
2011-11-25 22:32:25 ----A---- C:\Windows\system32\wmp.dll
2011-11-25 22:32:08 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2011-11-25 22:32:08 ----A---- C:\Windows\system32\StructuredQuery.dll
2011-11-25 22:31:59 ----A---- C:\Windows\system32\spoolsv.exe
2011-11-25 22:31:46 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2011-11-25 22:31:46 ----A---- C:\Windows\system32\msxml3.dll
2011-11-25 22:31:31 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2011-11-25 22:31:31 ----A---- C:\Windows\system32\rtutils.dll
2011-11-25 22:31:22 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2011-11-25 22:30:55 ----A---- C:\Windows\SYSWOW64\shell32.dll
2011-11-25 22:30:55 ----A---- C:\Windows\system32\shell32.dll
2011-11-25 22:30:42 ----A---- C:\Windows\system32\cdd.dll
2011-11-25 22:30:28 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2011-11-25 22:30:28 ----A---- C:\Windows\system32\asycfilt.dll
2011-11-25 22:30:13 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2011-11-25 22:30:13 ----A---- C:\Windows\system32\wintrust.dll
2011-11-25 22:30:06 ----A---- C:\Windows\SYSWOW64\cabview.dll
2011-11-25 22:30:06 ----A---- C:\Windows\system32\cabview.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\tsbyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\quartz.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\msyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\msvidc32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\mciavi32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\iyuv_32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\SYSWOW64\avifil32.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\tsbyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\quartz.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\msyuv.dll
2011-11-25 22:29:46 ----A---- C:\Windows\system32\iyuv_32.dll
2011-11-25 22:29:45 ----A---- C:\Windows\SYSWOW64\msrle32.dll
2011-11-25 22:29:45 ----A---- C:\Windows\system32\msvidc32.dll
2011-11-25 22:29:45 ----A---- C:\Windows\system32\msrle32.dll
2011-11-25 22:21:23 ----D---- C:\Users\zhulo\AppData\Roaming\IObit
2011-11-25 22:12:42 ----D---- C:\Windows\Profiles
======List of files/folders modified in the last 1 month======
2011-12-23 13:29:51 ----D---- C:\Windows\Prefetch
2011-12-23 13:29:46 ----RD---- C:\Program Files
2011-12-23 13:29:28 ----D---- C:\Windows\Temp
2011-12-23 12:40:48 ----D---- C:\Windows
2011-12-23 12:22:43 ----SHD---- C:\Windows\Installer
2011-12-23 12:22:38 ----HD---- C:\Config.Msi
2011-12-23 12:22:34 ----RD---- C:\Program Files (x86)
2011-12-23 12:22:34 ----D---- C:\ProgramData\Apple Computer
2011-12-23 12:20:57 ----D---- C:\Program Files (x86)\Black_Box
2011-12-23 12:20:56 ----DC---- C:\Windows\system32\DRVSTORE
2011-12-23 12:20:56 ----D---- C:\Windows\SysWOW64
2011-12-23 12:20:56 ----D---- C:\Windows\system32\drivers
2011-12-23 12:20:56 ----D---- C:\Windows\System32
2011-12-23 12:20:09 ----SHD---- C:\System Volume Information
2011-12-23 12:17:40 ----D---- C:\Windows\system32\DriverStore
2011-12-23 12:17:40 ----D---- C:\Windows\system32\catroot
2011-12-23 12:17:40 ----D---- C:\Windows\inf
2011-12-23 12:17:32 ----D---- C:\Program Files\Common Files
2011-12-23 12:16:23 ----D---- C:\Windows\system32\Tasks
2011-12-23 12:13:27 ----D---- C:\Users\zhulo\AppData\Roaming\DAEMON Tools Lite
2011-12-23 12:12:40 ----D---- C:\Windows\Minidump
2011-12-23 12:12:40 ----D---- C:\Windows\Logs
2011-12-23 12:08:35 ----D---- C:\Windows\SYSWOW64\drivers
2011-12-23 12:07:46 ----HD---- C:\ProgramData
2011-12-23 11:24:03 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-12-23 11:23:39 ----D---- C:\Windows\system32\config
2011-12-23 11:13:36 ----D---- C:\Windows\Tasks
2011-12-23 11:12:59 ----A---- C:\Windows\SYSWOW64\log.txt
2011-12-19 23:40:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-12-18 19:01:50 ----D---- C:\Users\zhulo\AppData\Roaming\Skype
2011-12-11 20:29:53 ----D---- C:\Users\zhulo\AppData\Roaming\codeblocks
2011-12-11 19:00:53 ----SD---- C:\Users\zhulo\AppData\Roaming\Microsoft
2011-12-10 23:04:30 ----D---- C:\Users\zhulo\AppData\Roaming\BSplayer
2011-12-10 11:46:00 ----D---- C:\Windows\system32\catroot2
2011-12-09 22:23:31 ----SD---- C:\ProgramData\Microsoft
2011-12-09 15:26:36 ----RSD---- C:\Windows\Fonts
2011-12-08 20:32:11 ----D---- C:\Program Files (x86)\Connectify
2011-12-04 15:15:36 ----D---- C:\Users\zhulo\AppData\Roaming\FileZilla
2011-12-03 20:42:11 ----RSD---- C:\Windows\assembly
2011-12-01 23:53:33 ----D---- C:\Windows\Microsoft.NET
2011-12-01 16:59:51 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-01 14:32:22 ----D---- C:\Program Files (x86)\CodeBlocks
2011-11-30 20:24:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-11-30 20:24:32 ----D---- C:\Windows\winsxs
2011-11-30 20:23:54 ----D---- C:\Program Files (x86)\Microsoft Office
2011-11-30 18:12:56 ----RD---- C:\Users
2011-11-30 17:50:54 ----D---- C:\Windows\system32\NDF
2011-11-30 17:48:12 ----D---- C:\ProgramData\Microsoft Help
2011-11-30 17:39:40 ----D---- C:\Windows\Registration
2011-11-30 17:34:11 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-11-30 17:34:03 ----D---- C:\Program Files (x86)\Common Files
2011-11-30 17:16:27 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-11-30 17:15:26 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2011-11-29 13:46:53 ----D---- C:\Update
2011-11-26 12:51:25 ----D---- C:\Program Files\Sony
2011-11-26 12:51:09 ----D---- C:\ProgramData\Sony Corporation
2011-11-26 12:49:49 ----D---- C:\Program Files (x86)\SONY
2011-11-26 12:44:38 ----D---- C:\Program Files\Common Files\Sony Shared
2011-11-26 11:56:32 ----D---- C:\Program Files (x86)\Downloaded Installations
2011-11-25 23:43:59 ----D---- C:\Users\zhulo\AppData\Roaming\QipGuard
2011-11-25 23:43:55 ----D---- C:\Program Files (x86)\QIP 2012
2011-11-25 23:31:09 ----D---- C:\Program Files (x86)\Google
2011-11-25 23:29:08 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-11-25 23:19:20 ----D---- C:\Program Files\Common Files\System
2011-11-25 23:19:20 ----D---- C:\Program Files (x86)\Internet Explorer
2011-11-25 23:19:19 ----D---- C:\Windows\SYSWOW64\migration
2011-11-25 23:19:19 ----D---- C:\Windows\system32\migration
2011-11-25 23:19:19 ----D---- C:\Program Files\Internet Explorer
2011-11-25 23:19:18 ----D---- C:\Windows\ehome
2011-11-25 23:19:16 ----D---- C:\Windows\AppPatch
2011-11-25 23:19:11 ----D---- C:\Program Files\Windows Mail
2011-11-25 23:19:10 ----D---- C:\Program Files\Windows Media Player
2011-11-25 23:19:10 ----D---- C:\Program Files (x86)\Windows Media Player
2011-11-25 23:19:10 ----D---- C:\Program Files (x86)\Windows Mail
2011-11-25 22:38:25 ----D---- C:\Program Files\DVD Maker
2011-11-25 22:38:24 ----D---- C:\OS
2011-11-25 22:24:48 ----D---- C:\ProgramData\Partner
2011-11-25 22:24:48 ----D---- C:\ProgramData\EA Logs
2011-11-25 00:48:11 ----D---- C:\Users\zhulo\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2009-11-21 537112]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2009-05-20 55280]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 cnnctfy2;Connectify LightWeight Filter; C:\Windows\system32\DRIVERS\cnnctfy2.sys [2011-11-13 31344]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 rimspci;rimspci; C:\Windows\system32\drivers\rimssne64.sys [2009-11-06 93696]
R2 risdsnpe;risdsnpe; C:\Windows\system32\drivers\risdsne64.sys [2009-09-15 75776]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-10-08 6661120]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-10-08 195584]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-11-04 253488]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2009-05-26 19968]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2009-11-12 1542656]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-03 270912]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-12-14 56344]
R3 Impcd;Impcd; C:\Windows\system32\drivers\Impcd.sys [2009-11-13 151936]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-12-16 2212640]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-08-31 25416]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 84864]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2009-12-16 213280]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-10-09 109056]
R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\drivers\SFEP.sys [2009-08-19 11392]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R4 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-10-08 6661120]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-11-18 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-11-18 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-11-18 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-11-18 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-11-18 21160]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-12-16 7778176]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2009-12-16 244736]
S3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-05-10 51712]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S4 RsFx0150;RsFx0150 Driver; C:\Windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-10-08 202752]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 873248]
R2 Connectify;Connectify; C:\Program Files (x86)\Connectify\ConnectifyService.exe [2011-12-01 69632]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-11-21 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-12-14 268824]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
R2 MsDtsServer;SQL Server Integration Services; C:\Program Files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [2005-10-14 195288]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 12784]
R2 MSSQLSERVER;SQL Server (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2005-10-14 39379672]
R2 MSSQLServerOLAPService;SQL Server Analysis Services (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe [2005-10-14 29323480]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 QipGuard;QipGuard; C:\Program Files (x86)\QipGuard\QipGuard.exe [2011-11-23 191440]
R2 SampleCollector;VAIO Care Performance Service; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [2011-01-29 259192]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 146272]
R2 uCamMonitor;CamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-12-14 2320920]
R2 VAIO Event Service;VAIO Event Service; C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe [2010-05-28 205168]
R2 VCFw;VAIO Content Folder Watcher; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-01-20 887000]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2011-05-19 549616]
R2 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager; C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2010-10-25 387896]
R2 VSNService;VSNService; C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2010-08-11 845312]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 SpfService;VAIO Entertainment Common Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2011-01-20 286936]
R3 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2009-11-30 571248]
R3 VCService;VCService; C:\Program Files\Sony\VAIO Care\VCService.exe [2011-02-14 44736]
R3 VUAgent;VUAgent; C:\Program Files\Sony\VAIO Update Common\VUAgent.exe [2011-09-23 1429608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
S2 msftesql;SQL Server FullText Search (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe [2005-08-26 155856]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-08-31 362992]
S2 SQLAgent$DATABAZA;SQL Server Agent (DATABAZA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.DATABAZA\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-11 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MSSQLFDLauncher$DATABAZA;SQL Full-text Filter Daemon Launcher (DATABAZA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.DATABAZA\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10; C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-08-31 313840]
S3 SOHCImp;VAIO Media plus Content Importer; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2010-09-10 108400]
S3 SOHDms;VAIO Media plus Digital Media Server; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2010-10-12 423280]
S3 SOHDs;VAIO Media plus Device Searcher; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2010-09-10 67952]
S3 SQLSERVERAGENT;SQL Server Agent (MSSQLSERVER); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE [2005-10-14 389848]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe [2010-09-27 74496]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2011-02-18 99104]
S4 MSOLAP$DATABAZA;SQL Server Analysis Services (DATABAZA); C:\Program Files\Microsoft SQL Server\MSAS10_50.DATABAZA\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]
S4 MSSQL$DATABAZA;SQL Server (DATABAZA); C:\Program Files\Microsoft SQL Server\MSSQL10_50.DATABAZA\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 64216]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 ReportServer$DATABAZA;SQL Server Reporting Services (DATABAZA); C:\Program Files\Microsoft SQL Server\MSRS10_50.DATABAZA\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]
-----------------EOF-----------------