Ahoj prosim o kontrolu logu dik.
Napsal: 26 led 2013 20:30
Logfile of random's system information tool 1.08 (written by random/random)
Run by Dada at 2013-01-26 20:30:19
Microsoft Windows 7 Home Basic Service Pack 1
System drive C: has 15 GB (50%) free of 31 GB
Total RAM: 8189 MB (71% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe"
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\Sandboxie\SbieSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallService.exe"
"C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1736
taskeng.exe {F60ADF09-9EDD-4A55-8AD7-DC063AD4569C}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchgaming
"C:\Program Files\YesShield\ShieldDaemon.exe" /Auto
"C:\Program Files\Sandboxie\SbieCtrl.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
"C:\Program Files (x86)\EXPERTool\TBPANEL.exe" /A
"C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallControl.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
KHALMNPR.EXE /API
"C:\Program Files\Java\jre7\bin\javaw.exe" -Xms32m -Xmx128m -jar "D:\zaloha programy\FreeRapid-0.9\FreeRapid-0.9\frd.jar"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Asc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Sandboxie\SandboxieRpcSs.exe"
"C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe"
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1228.2.1141306075\1977628803" --supports-dual-gpus=false --skip-gpu-full-info-collection --gpu-vendor-id=0x10de --gpu-device-id=0x1245 --gpu-driver-vendor=NVIDIA --gpu-driver-version=8.17.13.142 --ignored=" --type=renderer " /prefetch:12
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --extension-process --renderer-print-preview --channel="1228.4.1227761279\1710628318" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Dada\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\Plugin/ASCPlugin_Protect.dll" --lang=cs --channel="1228.5.811790284\517134580" /prefetch:4
"C:\Program Files\Sandboxie\SandboxieCrypto.exe"
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1228.21.1623523035\2055649357" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --extension-process --renderer-print-preview --channel="1228.22.1470766412\40673192" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/HttpPipeliningCompatibility/disable_test/InfiniteCache/No/NetworkConnectivity/disable_network_stats/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --renderer-print-preview --channel="1228.62.2018221141\558617094" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/HttpPipeliningCompatibility/disable_test/InfiniteCache/No/NetworkConnectivity/disable_network_stats/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --renderer-print-preview --channel="1228.73.723788160\1835427741" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/HttpPipeliningCompatibility/disable_test/InfiniteCache/No/NetworkConnectivity/disable_network_stats/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --renderer-print-preview --channel="1228.74.1030064270\1748284773" /prefetch:3
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Dada\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1620825976-2890253755-659159866-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1620825976-2890253755-659159866-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-22 551840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-22 209824]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-01-22 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\ADVANC~2\BROWER~1\ASCPLU~1.DLL [2012-10-15 662400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-01-22 170912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"=c:\program files\logitech\setpointp\setpoint.exe [2011-10-07 1744152]
"YesShield Daemon"=C:\Program Files\YesShield\ShieldDaemon.exe [2012-10-24 289472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SandboxieControl"=C:\Program Files\Sandboxie\SbieCtrl.exe [2012-12-16 765200]
"Google Update"=C:\Users\Dada\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-11 116648]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"GAINWARD"=C:\Program Files (x86)\EXPERTool\TBPanel.exe [2011-08-02 2273608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GAINWARD]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Windows7FirewallControl"=C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallControl.exe [2012-09-21 806912]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro36]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro36.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=1
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2013-01-26 20:30:19 ----D---- C:\rsit
2013-01-26 20:30:19 ----D---- C:\Program Files\trend micro
2013-01-23 20:29:51 ----SH---- C:\diskpt0.sys
2013-01-22 13:36:16 ----A---- C:\Windows\SYSWOW64\drivers\TBPanelx64.sys
2013-01-22 13:36:15 ----D---- C:\Program Files (x86)\EXPERTool
2013-01-22 12:23:47 ----D---- C:\Users\Dada\AppData\Roaming\YesShield
2013-01-22 12:16:05 ----D---- C:\Users\Dada\AppData\Roaming\Boredom Software
2013-01-22 12:03:56 ----A---- C:\Windows\system32\javaws.exe
2013-01-22 12:03:45 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2013-01-22 12:03:45 ----A---- C:\Windows\system32\javaw.exe
2013-01-22 12:03:45 ----A---- C:\Windows\system32\java.exe
2013-01-22 12:02:35 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-01-22 12:02:32 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-01-22 12:02:31 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-01-22 12:02:31 ----A---- C:\Windows\SYSWOW64\java.exe
2013-01-22 11:55:28 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2013-01-22 11:55:17 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-01-10 14:02:28 ----D---- C:\Users\Dada\AppData\Roaming\Wise Disk Cleaner
2013-01-09 22:01:33 ----D---- C:\Program Files (x86)\Microsoft WSE
2013-01-09 21:25:05 ----D---- C:\Program Files\YesShield
2013-01-09 21:25:05 ----A---- C:\Windows\system32\drivers\diskpt.sys
2013-01-09 21:24:06 ----D---- C:\Program Files (x86)\Boredom Software
2013-01-09 21:22:35 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-09 21:22:35 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-01-09 21:04:42 ----D---- C:\Users\Dada\AppData\Roaming\vlc
2013-01-09 19:52:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-01-09 19:52:49 ----A---- C:\Windows\system32\mshtmled.dll
2013-01-09 19:52:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-01-09 19:52:47 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-01-09 19:52:47 ----A---- C:\Windows\system32\ieUnatt.exe
2013-01-09 19:52:47 ----A---- C:\Windows\system32\ieui.dll
2013-01-09 19:52:46 ----A---- C:\Windows\SYSWOW64\url.dll
2013-01-09 19:52:46 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-01-09 19:52:46 ----A---- C:\Windows\system32\url.dll
2013-01-09 19:52:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-01-09 19:52:43 ----A---- C:\Windows\system32\urlmon.dll
2013-01-09 19:52:42 ----A---- C:\Windows\system32\msfeeds.dll
2013-01-09 19:52:42 ----A---- C:\Windows\system32\jscript9.dll
2013-01-09 19:52:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-01-09 19:52:41 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-01-09 19:52:40 ----A---- C:\Windows\system32\wininet.dll
2013-01-09 19:52:40 ----A---- C:\Windows\system32\jsproxy.dll
2013-01-09 19:52:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-01-09 19:52:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-01-09 19:52:38 ----A---- C:\Windows\system32\vbscript.dll
2013-01-09 19:52:38 ----A---- C:\Windows\system32\jscript.dll
2013-01-09 19:52:37 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-01-09 19:52:37 ----A---- C:\Windows\system32\iertutil.dll
2013-01-09 19:52:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-01-09 19:52:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-01-09 19:52:28 ----A---- C:\Windows\system32\mshtml.dll
2013-01-09 19:52:26 ----A---- C:\Windows\system32\ieframe.dll
2013-01-09 19:52:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-01-09 19:52:07 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-01-09 19:52:07 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-01-09 19:52:07 ----A---- C:\Windows\system32\atmlib.dll
2013-01-09 19:52:07 ----A---- C:\Windows\system32\atmfd.dll
2013-01-09 19:50:29 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-01-09 19:50:29 ----A---- C:\Windows\system32\tzres.dll
2013-01-09 19:50:17 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-01-09 19:50:17 ----A---- C:\Windows\system32\win32spl.dll
2013-01-09 19:50:01 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-01-09 19:50:01 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-01-09 19:50:01 ----A---- C:\Windows\system32\Wpc.dll
2013-01-09 19:50:01 ----A---- C:\Windows\system32\gameux.dll
2013-01-09 19:49:35 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-01-09 19:49:35 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-09 19:49:35 ----A---- C:\Windows\system32\kernel32.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 19:49:34 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-01-09 19:49:34 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-01-09 19:49:34 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\wow64win.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\wow64cpu.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\wow64.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\winsrv.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\ntvdm64.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\conhost.exe
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 19:49:33 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-01-09 19:49:33 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-01-09 19:49:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 19:49:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 19:49:32 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 19:49:32 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 19:49:32 ----A---- C:\Windows\SYSWOW64\user.exe
2013-01-09 19:47:52 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-01-09 19:47:52 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-01-09 19:47:52 ----A---- C:\Windows\system32\msxml6.dll
2013-01-09 19:47:52 ----A---- C:\Windows\system32\msxml3.dll
2013-01-09 19:47:49 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-01-09 19:47:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-01-09 19:47:49 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 19:47:49 ----A---- C:\Windows\system32\dpnet.dll
2013-01-09 19:47:47 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-01-09 19:47:47 ----A---- C:\Windows\system32\usp10.dll
2013-01-09 19:47:16 ----A---- C:\Windows\system32\win32k.sys
2013-01-09 19:47:16 ----A---- C:\Windows\system32\taskhost.exe
2013-01-09 19:46:02 ----D---- C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
======List of files/folders modified in the last 1 months======
2013-01-26 20:30:19 ----RD---- C:\Program Files
2013-01-26 18:31:24 ----D---- C:\Windows\system32\config
2013-01-26 18:19:28 ----D---- C:\Windows\Temp
2013-01-26 18:19:28 ----D---- C:\Windows\System32
2013-01-26 18:19:28 ----D---- C:\Windows\inf
2013-01-26 18:19:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-23 20:28:57 ----D---- C:\Windows\system32\catroot2
2013-01-23 20:27:48 ----D---- C:\Windows
2013-01-23 20:27:47 ----D---- C:\Windows\debug
2013-01-23 08:59:50 ----D---- C:\Windows\SoftwareDistribution
2013-01-23 08:57:12 ----A---- C:\Windows\Sandboxie.ini
2013-01-22 13:36:16 ----D---- C:\Windows\SYSWOW64\drivers
2013-01-22 13:36:15 ----RD---- C:\Program Files (x86)
2013-01-22 12:22:32 ----D---- C:\Windows\system32\LogFiles
2013-01-22 12:20:27 ----D---- C:\Windows\winsxs
2013-01-22 12:11:30 ----SHD---- C:\Windows\Installer
2013-01-22 12:11:30 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-01-22 12:09:50 ----SHD---- C:\Boot
2013-01-22 12:03:04 ----D---- C:\Program Files\Java
2013-01-22 12:03:04 ----A---- C:\Windows\system32\npDeployJava1.dll
2013-01-22 12:03:04 ----A---- C:\Windows\system32\deployJava1.dll
2013-01-22 12:02:35 ----D---- C:\Windows\SysWOW64
2013-01-22 12:02:14 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2013-01-22 12:02:14 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-01-22 12:02:11 ----D---- C:\Program Files (x86)\Java
2013-01-22 11:59:50 ----D---- C:\Users\Dada\AppData\Roaming\TS3Client
2013-01-22 11:55:29 ----D---- C:\Windows\system32\drivers
2013-01-22 11:55:29 ----D---- C:\Windows\system32\catroot
2013-01-22 11:55:28 ----D---- C:\Windows\system32\DriverStore
2013-01-10 14:04:04 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2013-01-10 14:03:37 ----SHD---- C:\System Volume Information
2013-01-10 14:02:46 ----D---- C:\Users\Dada\AppData\Roaming\DAEMON Tools Lite
2013-01-09 22:39:49 ----RSD---- C:\Windows\assembly
2013-01-09 22:39:49 ----D---- C:\Windows\Microsoft.NET
2013-01-09 22:20:45 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2013-01-09 22:19:47 ----D---- C:\Users\Dada\AppData\Roaming\HLSW
2013-01-09 21:11:55 ----D---- C:\Windows\system32\Tasks
2013-01-09 20:51:50 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-01-09 20:44:58 ----HD---- C:\ProgramData
2013-01-09 20:01:44 ----D---- C:\Windows\SYSWOW64\en-US
2013-01-09 20:01:44 ----D---- C:\Windows\system32\en-US
2013-01-09 19:58:09 ----D---- C:\Windows\SYSWOW64\migration
2013-01-09 19:58:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-01-09 19:58:09 ----D---- C:\Windows\system32\migration
2013-01-09 19:58:09 ----D---- C:\Windows\system32\cs-CZ
2013-01-09 19:58:09 ----D---- C:\Program Files (x86)\Internet Explorer
2013-01-09 19:58:08 ----D---- C:\Program Files\Internet Explorer
2013-01-09 19:58:07 ----D---- C:\Windows\AppPatch
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 diskpt;diskpt; C:\Windows\SYSTEM32\drivers\diskpt.sys [2012-10-24 258376]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-01-22 283200]
R2 bdfsfltr;bdfsfltr; \??\C:\Windows\system32\Drivers\bdfsfltr.sys [2011-03-24 431176]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2011-09-02 42776]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2012-12-16 202632]
R3 skfiltv;skfiltv; C:\Windows\system32\drivers\skfiltv.sys [2008-08-14 24064]
R3 Trufos;Trufos; C:\Windows\system32\DRIVERS\TRUFOS.sys [2011-11-21 329800]
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\PhenomMsrTweaker\WinRing0x64.sys [2010-06-03 14544]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-11 19456]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-11-04 15712]
S3 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 tizeqdrv;tizeqdrv; \??\C:\Users\Dada\AppData\Roaming\TZAC2\tizeq64.sys [2012-09-10 171704]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-11-11 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-11-11 30208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-11-27 1050496]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2012-11-13 625536]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 889664]
R2 PhenomMsrTweaker;PhenomMsrTweaker service; C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe [2010-06-03 188416]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-08-29 76888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2012-12-16 123664]
R2 Windows7FirewallService;Windows7FirewallService; C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallService.exe [2012-09-21 491520]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-09-03 529744]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-28 1255736]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-07-28 79360]
S4 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2010-01-27 286720]
S4 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Dada at 2013-01-26 20:30:19
Microsoft Windows 7 Home Basic Service Pack 1
System drive C: has 15 GB (50%) free of 31 GB
Total RAM: 8189 MB (71% free)
HijackThis download failed
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe"
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\Sandboxie\SbieSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallService.exe"
"C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 1736
taskeng.exe {F60ADF09-9EDD-4A55-8AD7-DC063AD4569C}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Monitor.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchgaming
"C:\Program Files\YesShield\ShieldDaemon.exe" /Auto
"C:\Program Files\Sandboxie\SbieCtrl.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe" /AutoStart
"C:\Program Files (x86)\EXPERTool\TBPANEL.exe" /A
"C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallControl.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
KHALMNPR.EXE /API
"C:\Program Files\Java\jre7\bin\javaw.exe" -Xms32m -Xmx128m -jar "D:\zaloha programy\FreeRapid-0.9\FreeRapid-0.9\frd.jar"
"C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\Asc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Sandboxie\SandboxieRpcSs.exe"
"C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe"
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1228.2.1141306075\1977628803" --supports-dual-gpus=false --skip-gpu-full-info-collection --gpu-vendor-id=0x10de --gpu-device-id=0x1245 --gpu-driver-vendor=NVIDIA --gpu-driver-version=8.17.13.142 --ignored=" --type=renderer " /prefetch:12
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --extension-process --renderer-print-preview --channel="1228.4.1227761279\1710628318" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Dada\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\Plugin/ASCPlugin_Protect.dll" --lang=cs --channel="1228.5.811790284\517134580" /prefetch:4
"C:\Program Files\Sandboxie\SandboxieCrypto.exe"
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1228.21.1623523035\2055649357" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --extension-process --renderer-print-preview --channel="1228.22.1470766412\40673192" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/HttpPipeliningCompatibility/disable_test/InfiniteCache/No/NetworkConnectivity/disable_network_stats/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --renderer-print-preview --channel="1228.62.2018221141\558617094" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/HttpPipeliningCompatibility/disable_test/InfiniteCache/No/NetworkConnectivity/disable_network_stats/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --renderer-print-preview --channel="1228.73.723788160\1835427741" /prefetch:3
"C:\Users\Dada\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/HttpPipeliningCompatibility/disable_test/InfiniteCache/No/NetworkConnectivity/disable_network_stats/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/12/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_03/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/warmest_socket/ --renderer-print-preview --channel="1228.74.1030064270\1748284773" /prefetch:3
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Dada\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1620825976-2890253755-659159866-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1620825976-2890253755-659159866-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-01-22 551840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-01-22 209824]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-01-22 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~2\IObit\ADVANC~2\BROWER~1\ASCPLU~1.DLL [2012-10-15 662400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-01-22 170912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"=c:\program files\logitech\setpointp\setpoint.exe [2011-10-07 1744152]
"YesShield Daemon"=C:\Program Files\YesShield\ShieldDaemon.exe [2012-10-24 289472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SandboxieControl"=C:\Program Files\Sandboxie\SbieCtrl.exe [2012-12-16 765200]
"Google Update"=C:\Users\Dada\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-11 116648]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"GAINWARD"=C:\Program Files (x86)\EXPERTool\TBPanel.exe [2011-08-02 2273608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GAINWARD]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Windows7FirewallControl"=C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallControl.exe [2012-09-21 806912]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2011-09-27 68376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro36.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro36]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro36.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=1
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2013-01-26 20:30:19 ----D---- C:\rsit
2013-01-26 20:30:19 ----D---- C:\Program Files\trend micro
2013-01-23 20:29:51 ----SH---- C:\diskpt0.sys
2013-01-22 13:36:16 ----A---- C:\Windows\SYSWOW64\drivers\TBPanelx64.sys
2013-01-22 13:36:15 ----D---- C:\Program Files (x86)\EXPERTool
2013-01-22 12:23:47 ----D---- C:\Users\Dada\AppData\Roaming\YesShield
2013-01-22 12:16:05 ----D---- C:\Users\Dada\AppData\Roaming\Boredom Software
2013-01-22 12:03:56 ----A---- C:\Windows\system32\javaws.exe
2013-01-22 12:03:45 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2013-01-22 12:03:45 ----A---- C:\Windows\system32\javaw.exe
2013-01-22 12:03:45 ----A---- C:\Windows\system32\java.exe
2013-01-22 12:02:35 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-01-22 12:02:32 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-01-22 12:02:31 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-01-22 12:02:31 ----A---- C:\Windows\SYSWOW64\java.exe
2013-01-22 11:55:28 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2013-01-22 11:55:17 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-01-10 14:02:28 ----D---- C:\Users\Dada\AppData\Roaming\Wise Disk Cleaner
2013-01-09 22:01:33 ----D---- C:\Program Files (x86)\Microsoft WSE
2013-01-09 21:25:05 ----D---- C:\Program Files\YesShield
2013-01-09 21:25:05 ----A---- C:\Windows\system32\drivers\diskpt.sys
2013-01-09 21:24:06 ----D---- C:\Program Files (x86)\Boredom Software
2013-01-09 21:22:35 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-09 21:22:35 ----A---- C:\Windows\system32\drivers\mbam.sys
2013-01-09 21:04:42 ----D---- C:\Users\Dada\AppData\Roaming\vlc
2013-01-09 19:52:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-01-09 19:52:49 ----A---- C:\Windows\system32\mshtmled.dll
2013-01-09 19:52:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-01-09 19:52:47 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-01-09 19:52:47 ----A---- C:\Windows\system32\ieUnatt.exe
2013-01-09 19:52:47 ----A---- C:\Windows\system32\ieui.dll
2013-01-09 19:52:46 ----A---- C:\Windows\SYSWOW64\url.dll
2013-01-09 19:52:46 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-01-09 19:52:46 ----A---- C:\Windows\system32\url.dll
2013-01-09 19:52:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-01-09 19:52:43 ----A---- C:\Windows\system32\urlmon.dll
2013-01-09 19:52:42 ----A---- C:\Windows\system32\msfeeds.dll
2013-01-09 19:52:42 ----A---- C:\Windows\system32\jscript9.dll
2013-01-09 19:52:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-01-09 19:52:41 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-01-09 19:52:40 ----A---- C:\Windows\system32\wininet.dll
2013-01-09 19:52:40 ----A---- C:\Windows\system32\jsproxy.dll
2013-01-09 19:52:38 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-01-09 19:52:38 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-01-09 19:52:38 ----A---- C:\Windows\system32\vbscript.dll
2013-01-09 19:52:38 ----A---- C:\Windows\system32\jscript.dll
2013-01-09 19:52:37 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-01-09 19:52:37 ----A---- C:\Windows\system32\iertutil.dll
2013-01-09 19:52:36 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-01-09 19:52:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-01-09 19:52:28 ----A---- C:\Windows\system32\mshtml.dll
2013-01-09 19:52:26 ----A---- C:\Windows\system32\ieframe.dll
2013-01-09 19:52:25 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-01-09 19:52:07 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-01-09 19:52:07 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-01-09 19:52:07 ----A---- C:\Windows\system32\atmlib.dll
2013-01-09 19:52:07 ----A---- C:\Windows\system32\atmfd.dll
2013-01-09 19:50:29 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-01-09 19:50:29 ----A---- C:\Windows\system32\tzres.dll
2013-01-09 19:50:17 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-01-09 19:50:17 ----A---- C:\Windows\system32\win32spl.dll
2013-01-09 19:50:01 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-01-09 19:50:01 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-01-09 19:50:01 ----A---- C:\Windows\system32\Wpc.dll
2013-01-09 19:50:01 ----A---- C:\Windows\system32\gameux.dll
2013-01-09 19:49:35 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-01-09 19:49:35 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-09 19:49:35 ----A---- C:\Windows\system32\kernel32.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 19:49:34 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 19:49:34 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-01-09 19:49:34 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-01-09 19:49:34 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\wow64win.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\wow64cpu.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\wow64.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\winsrv.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\ntvdm64.dll
2013-01-09 19:49:34 ----A---- C:\Windows\system32\conhost.exe
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 19:49:33 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 19:49:33 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-01-09 19:49:33 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-01-09 19:49:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 19:49:32 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 19:49:32 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 19:49:32 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 19:49:32 ----A---- C:\Windows\SYSWOW64\user.exe
2013-01-09 19:47:52 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-01-09 19:47:52 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-01-09 19:47:52 ----A---- C:\Windows\system32\msxml6.dll
2013-01-09 19:47:52 ----A---- C:\Windows\system32\msxml3.dll
2013-01-09 19:47:49 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-01-09 19:47:49 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2013-01-09 19:47:49 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 19:47:49 ----A---- C:\Windows\system32\dpnet.dll
2013-01-09 19:47:47 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-01-09 19:47:47 ----A---- C:\Windows\system32\usp10.dll
2013-01-09 19:47:16 ----A---- C:\Windows\system32\win32k.sys
2013-01-09 19:47:16 ----A---- C:\Windows\system32\taskhost.exe
2013-01-09 19:46:02 ----D---- C:\ProgramData\{D76294E6-03B8-4971-AF2E-3F846161A690}
======List of files/folders modified in the last 1 months======
2013-01-26 20:30:19 ----RD---- C:\Program Files
2013-01-26 18:31:24 ----D---- C:\Windows\system32\config
2013-01-26 18:19:28 ----D---- C:\Windows\Temp
2013-01-26 18:19:28 ----D---- C:\Windows\System32
2013-01-26 18:19:28 ----D---- C:\Windows\inf
2013-01-26 18:19:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-23 20:28:57 ----D---- C:\Windows\system32\catroot2
2013-01-23 20:27:48 ----D---- C:\Windows
2013-01-23 20:27:47 ----D---- C:\Windows\debug
2013-01-23 08:59:50 ----D---- C:\Windows\SoftwareDistribution
2013-01-23 08:57:12 ----A---- C:\Windows\Sandboxie.ini
2013-01-22 13:36:16 ----D---- C:\Windows\SYSWOW64\drivers
2013-01-22 13:36:15 ----RD---- C:\Program Files (x86)
2013-01-22 12:22:32 ----D---- C:\Windows\system32\LogFiles
2013-01-22 12:20:27 ----D---- C:\Windows\winsxs
2013-01-22 12:11:30 ----SHD---- C:\Windows\Installer
2013-01-22 12:11:30 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-01-22 12:09:50 ----SHD---- C:\Boot
2013-01-22 12:03:04 ----D---- C:\Program Files\Java
2013-01-22 12:03:04 ----A---- C:\Windows\system32\npDeployJava1.dll
2013-01-22 12:03:04 ----A---- C:\Windows\system32\deployJava1.dll
2013-01-22 12:02:35 ----D---- C:\Windows\SysWOW64
2013-01-22 12:02:14 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2013-01-22 12:02:14 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2013-01-22 12:02:11 ----D---- C:\Program Files (x86)\Java
2013-01-22 11:59:50 ----D---- C:\Users\Dada\AppData\Roaming\TS3Client
2013-01-22 11:55:29 ----D---- C:\Windows\system32\drivers
2013-01-22 11:55:29 ----D---- C:\Windows\system32\catroot
2013-01-22 11:55:28 ----D---- C:\Windows\system32\DriverStore
2013-01-10 14:04:04 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2013-01-10 14:03:37 ----SHD---- C:\System Volume Information
2013-01-10 14:02:46 ----D---- C:\Users\Dada\AppData\Roaming\DAEMON Tools Lite
2013-01-09 22:39:49 ----RSD---- C:\Windows\assembly
2013-01-09 22:39:49 ----D---- C:\Windows\Microsoft.NET
2013-01-09 22:20:45 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2013-01-09 22:19:47 ----D---- C:\Users\Dada\AppData\Roaming\HLSW
2013-01-09 21:11:55 ----D---- C:\Windows\system32\Tasks
2013-01-09 20:51:50 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-01-09 20:44:58 ----HD---- C:\ProgramData
2013-01-09 20:01:44 ----D---- C:\Windows\SYSWOW64\en-US
2013-01-09 20:01:44 ----D---- C:\Windows\system32\en-US
2013-01-09 19:58:09 ----D---- C:\Windows\SYSWOW64\migration
2013-01-09 19:58:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-01-09 19:58:09 ----D---- C:\Windows\system32\migration
2013-01-09 19:58:09 ----D---- C:\Windows\system32\cs-CZ
2013-01-09 19:58:09 ----D---- C:\Program Files (x86)\Internet Explorer
2013-01-09 19:58:08 ----D---- C:\Program Files\Internet Explorer
2013-01-09 19:58:07 ----D---- C:\Windows\AppPatch
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 diskpt;diskpt; C:\Windows\SYSTEM32\drivers\diskpt.sys [2012-10-24 258376]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-01-22 283200]
R2 bdfsfltr;bdfsfltr; \??\C:\Windows\system32\Drivers\bdfsfltr.sys [2011-03-24 431176]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-09-02 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-09-02 60696]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2011-09-02 42776]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2012-12-16 202632]
R3 skfiltv;skfiltv; C:\Windows\system32\drivers\skfiltv.sys [2008-08-14 24064]
R3 Trufos;Trufos; C:\Windows\system32\DRIVERS\TRUFOS.sys [2011-11-21 329800]
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\PhenomMsrTweaker\WinRing0x64.sys [2010-06-03 14544]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-11 19456]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2012-11-04 15712]
S3 TBPanel;TBPanel; C:\Windows\system32\drivers\TBPanel.sys []
S3 tizeqdrv;tizeqdrv; \??\C:\Users\Dada\AppData\Roaming\TZAC2\tizeq64.sys [2012-09-10 171704]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-11-11 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-11-11 30208]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-11-27 1050496]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2012-11-13 625536]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-05-15 889664]
R2 PhenomMsrTweaker;PhenomMsrTweaker service; C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe [2010-06-03 188416]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-08-29 76888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2012-12-16 123664]
R2 Windows7FirewallService;Windows7FirewallService; C:\Program Files (x86)\Windows7FirewallControl\Windows7FirewallService.exe [2012-09-21 491520]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2012-09-03 529744]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-07-28 1255736]
S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-07-28 79360]
S4 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2010-01-27 286720]
S4 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2011-09-27 359192]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------