Ahoj prosim kouknete mi na log dekuji
Napsal: 30 črc 2013 12:45
Logfile of random's system information tool 1.09 (written by random/random)
Run by Davidov at 2013-07-30 13:44:32
Microsoft Windows 7 Home Basic Service Pack 1
System drive C: has 14 GB (46%) free of 31 GB
Total RAM: 8189 MB (84% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-17 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AntiLogger"=C:\Program Files (x86)\AntiLogger\AntiLogger.exe [2013-07-22 17289640]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GAINWARD"=c:\program files (x86)\expertool\tbpanel.exe [2011-08-02 2273608]
"SandboxieControl"=C:\Program Files\Sandboxie\SbieCtrl.exe [2013-07-08 759384]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"WinPatrol"=C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [2013-07-15 436800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-07-30 13:44:33 ----D---- C:\Program Files (x86)\trend micro
2013-07-30 13:44:32 ----D---- C:\rsit
2013-07-25 21:07:33 ----SH---- C:\diskpt0.sys
2013-07-25 16:41:38 ----HDC---- C:\ProgramData\{33CC04A6-7C06-4D73-B22D-D63FE2603F84}
2013-07-23 20:31:10 ----D---- C:\ProgramData\HitmanPro
2013-07-19 20:37:19 ----D---- C:\Users\Davidov\AppData\Roaming\WinPatrol
2013-07-19 20:37:16 ----D---- C:\ProgramData\InstallMate
2013-07-19 20:37:16 ----D---- C:\Program Files (x86)\BillP Studios
2013-07-17 23:23:35 ----D---- C:\Users\Davidov\AppData\Roaming\VitySoft
2013-07-17 23:22:31 ----D---- C:\Program Files (x86)\Common Files\Java
2013-07-17 23:22:22 ----A---- C:\Windows\SysWOW64\javaws.exe
2013-07-17 23:22:18 ----A---- C:\Windows\SysWOW64\javaw.exe
2013-07-17 23:22:18 ----A---- C:\Windows\SysWOW64\java.exe
2013-07-17 23:22:10 ----D---- C:\Program Files (x86)\Java
2013-07-17 22:58:01 ----D---- C:\ProgramData\Sun
2013-07-17 20:24:31 ----D---- C:\ProgramData\APN
2013-07-17 20:24:08 ----D---- C:\Program Files (x86)\FreeTime
2013-07-17 20:18:36 ----D---- C:\IObit
2013-07-17 20:16:42 ----D---- C:\Users\Davidov\AppData\Roaming\IObit
2013-07-17 19:59:09 ----D---- C:\Program Files (x86)\Google
2013-07-16 18:48:36 ----SHD---- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-07-16 18:48:36 ----HD---- C:\ProgramData\Common Files
2013-07-14 23:41:20 ----D---- C:\Windows\SysWOW64\RTCOM
2013-07-14 23:39:59 ----A---- C:\Windows\SysWOW64\SFCOM.dll
2013-07-14 17:34:22 ----D---- C:\Program Files (x86)\Realtek
2013-07-14 17:31:52 ----HD---- C:\Program Files (x86)\Temp
2013-07-14 17:31:50 ----A---- C:\Windows\RtlExUpd.dll
2013-07-14 17:06:57 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-07-14 17:03:16 ----D---- C:\ProgramData\IObit
2013-07-14 17:03:15 ----D---- C:\Program Files (x86)\IObit
2013-07-14 16:28:03 ----A---- C:\Windows\SysWOW64\ieui.dll
2013-07-14 16:27:59 ----A---- C:\Windows\SysWOW64\iesetup.dll
2013-07-14 16:27:59 ----A---- C:\Windows\SysWOW64\iernonce.dll
2013-07-14 16:27:58 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-14 16:27:58 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2013-07-14 16:27:56 ----A---- C:\Windows\SysWOW64\iertutil.dll
2013-07-14 16:27:55 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2013-07-14 16:27:55 ----A---- C:\Windows\SysWOW64\jscript.dll
2013-07-14 16:27:54 ----A---- C:\Windows\SysWOW64\jscript9.dll
2013-07-14 16:27:53 ----A---- C:\Windows\SysWOW64\urlmon.dll
2013-07-14 16:27:52 ----A---- C:\Windows\SysWOW64\wininet.dll
2013-07-14 16:27:52 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2013-07-14 16:27:51 ----A---- C:\Windows\SysWOW64\ieframe.dll
2013-07-14 16:27:48 ----A---- C:\Windows\SysWOW64\mshtml.dll
2013-07-14 16:20:08 ----A---- C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-14 16:19:43 ----A---- C:\Windows\SysWOW64\qedit.dll
2013-07-14 16:18:38 ----A---- C:\Windows\SysWOW64\DWrite.dll
======List of files/folders modified in the last 1 month======
2013-07-30 13:44:33 ----RD---- C:\Program Files (x86)
2013-07-30 10:53:02 ----D---- C:\Windows\Temp
2013-07-30 10:43:13 ----D---- C:\Windows\Prefetch
2013-07-30 10:20:36 ----D---- C:\Windows\System32
2013-07-30 10:20:36 ----D---- C:\Windows\inf
2013-07-25 21:06:46 ----D---- C:\Windows\debug
2013-07-25 21:06:46 ----D---- C:\Windows
2013-07-25 21:06:44 ----SHD---- C:\Boot
2013-07-25 20:37:34 ----D---- C:\Windows\SoftwareDistribution
2013-07-25 19:31:06 ----D---- C:\Windows\SysWOW64
2013-07-25 19:30:43 ----A---- C:\Windows\SysWOW64\PnkBstrB.exe
2013-07-25 16:43:33 ----HD---- C:\ProgramData
2013-07-25 16:41:38 ----SHD---- C:\Windows\Installer
2013-07-25 16:41:37 ----D---- C:\Program Files (x86)\AntiLogger
2013-07-25 16:34:19 ----A---- C:\Windows\Sandboxie.ini
2013-07-20 01:35:03 ----D---- C:\Users\Davidov\AppData\Roaming\TS3Client
2013-07-18 10:22:39 ----D---- C:\Windows\Tasks
2013-07-18 10:21:16 ----SHD---- C:\System Volume Information
2013-07-17 23:22:31 ----D---- C:\Program Files (x86)\Common Files
2013-07-17 23:22:13 ----A---- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-17 23:22:11 ----A---- C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-17 23:22:11 ----A---- C:\Windows\SysWOW64\deployJava1.dll
2013-07-17 19:58:00 ----RD---- C:\Program Files
2013-07-17 19:54:14 ----D---- C:\Users\Davidov\AppData\Roaming\Identities
2013-07-17 19:23:33 ----RSD---- C:\Windows\assembly
2013-07-15 10:58:11 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-07-15 01:07:07 ----D---- C:\Windows\Microsoft.NET
2013-07-15 00:11:23 ----RSD---- C:\Windows\Fonts
2013-07-14 17:50:31 ----D---- C:\Windows\SysWOW64\config
2013-07-14 17:50:30 ----D---- C:\Windows\Panther
2013-07-14 17:31:44 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2013-07-14 17:25:32 ----D---- C:\ProgramData\NVIDIA Corporation
2013-07-14 16:51:41 ----D---- C:\Windows\winsxs
2013-07-14 16:51:15 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-07-14 16:50:25 ----D---- C:\Program Files (x86)\Windows Defender
2013-07-14 16:50:25 ----D---- C:\Program Files (x86)\Internet Explorer
2013-07-05 10:48:45 ----D---- C:\Users\Davidov\AppData\Roaming\vlc
2013-07-04 15:24:02 ----A---- C:\Windows\SysWOW64\PnkBstrA.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 diskpt;diskpt; C:\Windows\SYSTEM32\drivers\diskpt.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 AntiLog32;AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R2 bdfsfltr;bdfsfltr; \??\C:\Windows\system32\Drivers\bdfsfltr.sys []
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys []
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys []
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2013-07-08 199384]
R3 skfiltv;skfiltv; C:\Windows\system32\drivers\skfiltv.sys []
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\PhenomMsrTweaker\WinRing0x64.sys [2010-06-03 14544]
S3 efavdrv;efavdrv; C:\Windows\SysWOW64\drivers\efavdrv.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 TBPanel;TBPanel; C:\Windows\SysWOW64\drivers\TBPanel.sys []
S3 Trufos;Trufos; C:\Windows\system32\DRIVERS\TRUFOS.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys []
S4 IObitUnlocker;IObitUnlocker; \??\C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [2013-04-03 36920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2013-07-08 623936]
R2 PhenomMsrTweaker;PhenomMsrTweaker service; C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe [2010-06-03 188416]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2013-07-04 76888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2013-07-08 183896]
R2 Windows7FirewallService;Windows7FirewallService; C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe [2013-04-16 778752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17 116648]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-01-28 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-10-28 357456]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-06-26 117144]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-07 543656]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S3 WiseBootAssistant;Wise Boot Assistant; G:\Programy atd cod\cisteni PC\Wise Care 365\BootTime.exe [2013-07-18 580232]
S4 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2010-01-27 286720]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Davidov at 2013-07-30 13:44:32
Microsoft Windows 7 Home Basic Service Pack 1
System drive C: has 14 GB (46%) free of 31 GB
Total RAM: 8189 MB (84% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-07-17 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AntiLogger"=C:\Program Files (x86)\AntiLogger\AntiLogger.exe [2013-07-22 17289640]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GAINWARD"=c:\program files (x86)\expertool\tbpanel.exe [2011-08-02 2273608]
"SandboxieControl"=C:\Program Files\Sandboxie\SbieCtrl.exe [2013-07-08 759384]
"Advanced SystemCare Ultimate"=C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ASCTray.exe [2012-11-07 512384]
"WinPatrol"=C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [2013-07-15 436800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-07-30 13:44:33 ----D---- C:\Program Files (x86)\trend micro
2013-07-30 13:44:32 ----D---- C:\rsit
2013-07-25 21:07:33 ----SH---- C:\diskpt0.sys
2013-07-25 16:41:38 ----HDC---- C:\ProgramData\{33CC04A6-7C06-4D73-B22D-D63FE2603F84}
2013-07-23 20:31:10 ----D---- C:\ProgramData\HitmanPro
2013-07-19 20:37:19 ----D---- C:\Users\Davidov\AppData\Roaming\WinPatrol
2013-07-19 20:37:16 ----D---- C:\ProgramData\InstallMate
2013-07-19 20:37:16 ----D---- C:\Program Files (x86)\BillP Studios
2013-07-17 23:23:35 ----D---- C:\Users\Davidov\AppData\Roaming\VitySoft
2013-07-17 23:22:31 ----D---- C:\Program Files (x86)\Common Files\Java
2013-07-17 23:22:22 ----A---- C:\Windows\SysWOW64\javaws.exe
2013-07-17 23:22:18 ----A---- C:\Windows\SysWOW64\javaw.exe
2013-07-17 23:22:18 ----A---- C:\Windows\SysWOW64\java.exe
2013-07-17 23:22:10 ----D---- C:\Program Files (x86)\Java
2013-07-17 22:58:01 ----D---- C:\ProgramData\Sun
2013-07-17 20:24:31 ----D---- C:\ProgramData\APN
2013-07-17 20:24:08 ----D---- C:\Program Files (x86)\FreeTime
2013-07-17 20:18:36 ----D---- C:\IObit
2013-07-17 20:16:42 ----D---- C:\Users\Davidov\AppData\Roaming\IObit
2013-07-17 19:59:09 ----D---- C:\Program Files (x86)\Google
2013-07-16 18:48:36 ----SHD---- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-07-16 18:48:36 ----HD---- C:\ProgramData\Common Files
2013-07-14 23:41:20 ----D---- C:\Windows\SysWOW64\RTCOM
2013-07-14 23:39:59 ----A---- C:\Windows\SysWOW64\SFCOM.dll
2013-07-14 17:34:22 ----D---- C:\Program Files (x86)\Realtek
2013-07-14 17:31:52 ----HD---- C:\Program Files (x86)\Temp
2013-07-14 17:31:50 ----A---- C:\Windows\RtlExUpd.dll
2013-07-14 17:06:57 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-07-14 17:03:16 ----D---- C:\ProgramData\IObit
2013-07-14 17:03:15 ----D---- C:\Program Files (x86)\IObit
2013-07-14 16:28:03 ----A---- C:\Windows\SysWOW64\ieui.dll
2013-07-14 16:27:59 ----A---- C:\Windows\SysWOW64\iesetup.dll
2013-07-14 16:27:59 ----A---- C:\Windows\SysWOW64\iernonce.dll
2013-07-14 16:27:58 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-14 16:27:58 ----A---- C:\Windows\SysWOW64\iesysprep.dll
2013-07-14 16:27:56 ----A---- C:\Windows\SysWOW64\iertutil.dll
2013-07-14 16:27:55 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2013-07-14 16:27:55 ----A---- C:\Windows\SysWOW64\jscript.dll
2013-07-14 16:27:54 ----A---- C:\Windows\SysWOW64\jscript9.dll
2013-07-14 16:27:53 ----A---- C:\Windows\SysWOW64\urlmon.dll
2013-07-14 16:27:52 ----A---- C:\Windows\SysWOW64\wininet.dll
2013-07-14 16:27:52 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2013-07-14 16:27:51 ----A---- C:\Windows\SysWOW64\ieframe.dll
2013-07-14 16:27:48 ----A---- C:\Windows\SysWOW64\mshtml.dll
2013-07-14 16:20:08 ----A---- C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-14 16:19:43 ----A---- C:\Windows\SysWOW64\qedit.dll
2013-07-14 16:18:38 ----A---- C:\Windows\SysWOW64\DWrite.dll
======List of files/folders modified in the last 1 month======
2013-07-30 13:44:33 ----RD---- C:\Program Files (x86)
2013-07-30 10:53:02 ----D---- C:\Windows\Temp
2013-07-30 10:43:13 ----D---- C:\Windows\Prefetch
2013-07-30 10:20:36 ----D---- C:\Windows\System32
2013-07-30 10:20:36 ----D---- C:\Windows\inf
2013-07-25 21:06:46 ----D---- C:\Windows\debug
2013-07-25 21:06:46 ----D---- C:\Windows
2013-07-25 21:06:44 ----SHD---- C:\Boot
2013-07-25 20:37:34 ----D---- C:\Windows\SoftwareDistribution
2013-07-25 19:31:06 ----D---- C:\Windows\SysWOW64
2013-07-25 19:30:43 ----A---- C:\Windows\SysWOW64\PnkBstrB.exe
2013-07-25 16:43:33 ----HD---- C:\ProgramData
2013-07-25 16:41:38 ----SHD---- C:\Windows\Installer
2013-07-25 16:41:37 ----D---- C:\Program Files (x86)\AntiLogger
2013-07-25 16:34:19 ----A---- C:\Windows\Sandboxie.ini
2013-07-20 01:35:03 ----D---- C:\Users\Davidov\AppData\Roaming\TS3Client
2013-07-18 10:22:39 ----D---- C:\Windows\Tasks
2013-07-18 10:21:16 ----SHD---- C:\System Volume Information
2013-07-17 23:22:31 ----D---- C:\Program Files (x86)\Common Files
2013-07-17 23:22:13 ----A---- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-17 23:22:11 ----A---- C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-17 23:22:11 ----A---- C:\Windows\SysWOW64\deployJava1.dll
2013-07-17 19:58:00 ----RD---- C:\Program Files
2013-07-17 19:54:14 ----D---- C:\Users\Davidov\AppData\Roaming\Identities
2013-07-17 19:23:33 ----RSD---- C:\Windows\assembly
2013-07-15 10:58:11 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-07-15 01:07:07 ----D---- C:\Windows\Microsoft.NET
2013-07-15 00:11:23 ----RSD---- C:\Windows\Fonts
2013-07-14 17:50:31 ----D---- C:\Windows\SysWOW64\config
2013-07-14 17:50:30 ----D---- C:\Windows\Panther
2013-07-14 17:31:44 ----D---- C:\Program Files (x86)\Common Files\InstallShield
2013-07-14 17:25:32 ----D---- C:\ProgramData\NVIDIA Corporation
2013-07-14 16:51:41 ----D---- C:\Windows\winsxs
2013-07-14 16:51:15 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-07-14 16:50:25 ----D---- C:\Program Files (x86)\Windows Defender
2013-07-14 16:50:25 ----D---- C:\Program Files (x86)\Internet Explorer
2013-07-05 10:48:45 ----D---- C:\Users\Davidov\AppData\Roaming\vlc
2013-07-04 15:24:02 ----A---- C:\Windows\SysWOW64\PnkBstrA.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 diskpt;diskpt; C:\Windows\SYSTEM32\drivers\diskpt.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 AntiLog32;AntiLog32; \??\C:\Windows\system32\drivers\AntiLog64.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R2 bdfsfltr;bdfsfltr; \??\C:\Windows\system32\Drivers\bdfsfltr.sys []
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys []
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys []
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [2013-07-08 199384]
R3 skfiltv;skfiltv; C:\Windows\system32\drivers\skfiltv.sys []
R3 WinRing0_1_2_0;WinRing0_1_2_0; \??\C:\Program Files\PhenomMsrTweaker\WinRing0x64.sys [2010-06-03 14544]
S3 efavdrv;efavdrv; C:\Windows\SysWOW64\drivers\efavdrv.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 TBPanel;TBPanel; C:\Windows\SysWOW64\drivers\TBPanel.sys []
S3 Trufos;Trufos; C:\Windows\system32\DRIVERS\TRUFOS.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys []
S4 IObitUnlocker;IObitUnlocker; \??\C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [2013-04-03 36920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascsvc.exe [2012-12-13 1051088]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate\ascavsvc.exe [2013-07-08 623936]
R2 PhenomMsrTweaker;PhenomMsrTweaker service; C:\Program Files\PhenomMsrTweaker\PhenomMsrTweakerService.exe [2010-06-03 188416]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2013-07-04 76888]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2013-07-08 183896]
R2 Windows7FirewallService;Windows7FirewallService; C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe [2013-04-16 778752]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17 116648]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2013-01-28 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-17 116648]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-10-28 357456]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-06-26 117144]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-06-07 543656]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S3 WiseBootAssistant;Wise Boot Assistant; G:\Programy atd cod\cisteni PC\Wise Care 365\BootTime.exe [2013-07-18 580232]
S4 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2010-01-27 286720]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------