prosim o kontrolu logu - zamrzlo PC
Napsal: 13 úno 2010 11:48
Mozete prosim niekto pozriet tento log? Zamrzlo mi PC pri praci a ked som ho po chvili necinnosti resetol (po na citani tej uvodnej ciernej obrazovky po starte - neviem ako sa tomu hovori) vypisalo ze kontroluje disky C a D ci nedoslo ku chybe a po asi 3minutach vypisalo ze 100% hotovo a spustil sa windows. Zatial ide vsetko dobre zda sa, no moze tam, byt daka skryta haved... tak chcem mat istotu, vdaka
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-02-13 11:42:44
Microsoft Windows 7 Professional Service Pack 2
System drive C: has 64 GB (64%) free of 100 GB
Total RAM: 2047 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:46, on 13. 2. 2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\admin\Desktop\cistenie PC registre, malware,\RSIT.exe
C:\Program Files\trend micro\admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
--
End of file - 4234 bytes
======Scheduled tasks folder======
C:\Windows\tasks\NeroLiveEpgUpdate-admin-PC_admin.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pre aplikáciu Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
"AdobeVersionCue"=C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe [2004-03-25 1732608]
"NWEReboot"= []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acrobat Assistant.lnk - C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-02-10 18:07:36 ----A---- C:\Windows\system32\kernel32.dll
2010-02-10 18:07:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\apphelp.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\avifil32.dll
2010-02-10 18:07:07 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-07 14:05:51 ----D---- C:\Windows\system32\QuickTime
2010-02-07 14:05:51 ----D---- C:\ProgramData\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files\Macromedia
2010-02-07 14:05:11 ----D---- C:\Windows\Downloaded Installations
2010-02-07 13:36:06 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2010-02-07 13:36:01 ----D---- C:\ProgramData\Malwarebytes
2010-02-07 13:36:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-07 13:24:11 ----D---- C:\Program Files\CCleaner
2010-02-06 11:36:41 ----D---- C:\Windows\system32\appmgmt
2010-02-06 11:05:49 ----D---- C:\Program Files\TrendMicro
2010-02-06 10:36:32 ----D---- C:\Program Files\trend micro
2010-02-06 10:36:31 ----D---- C:\rsit
2010-01-31 08:24:19 ----D---- C:\Users\admin\AppData\Roaming\Google
2010-01-30 18:25:44 ----D---- C:\Users\admin\AppData\Roaming\skypePM
2010-01-30 18:20:16 ----D---- C:\Program Files\Google
2010-01-30 18:19:05 ----D---- C:\ProgramData\Skype
2010-01-27 17:21:06 ----A---- C:\Windows\system32\winlogon.exe
2010-01-27 17:21:06 ----A---- C:\Windows\explorer.exe
2010-01-24 15:32:29 ----D---- C:\Program Files\MSXML 4.0
2010-01-23 19:48:58 ----D---- C:\Users\admin\AppData\Roaming\Nero
2010-01-23 19:34:44 ----A---- C:\Windows\Irremote.ini
2010-01-23 19:26:01 ----D---- C:\ProgramData\Nero
2010-01-23 19:26:00 ----D---- C:\Program Files\Common Files\Nero
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-23 17:59:36 ----A---- C:\Users\admin\AppData\Roaming\inst.exe
2010-01-23 17:59:35 ----D---- C:\Users\admin\AppData\Roaming\Vso
2010-01-23 17:59:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\vp7vfw.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\sipr3260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\Pncrt.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv43260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv33260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv23260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\cook3260.dll
2010-01-23 17:59:16 ----D---- C:\Program Files\VSO
2010-01-23 17:35:37 ----D---- C:\Users\admin\AppData\Roaming\Ahead
2010-01-23 17:13:58 ----D---- C:\Program Files\Nero
2010-01-23 17:13:58 ----D---- C:\Program Files\Common Files\Ahead
2010-01-23 13:15:11 ----D---- C:\ProgramData\Adobe
2010-01-23 13:13:30 ----D---- C:\Windows\system32\Adobe
2010-01-23 13:13:30 ----A---- C:\Windows\system32\FileOps.exe
2010-01-23 13:07:05 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-23 13:05:37 ----HD---- C:\Program Files\Installshield Installation Information
2010-01-23 12:59:14 ----D---- C:\Program Files\YouTube Downloader
2010-01-23 12:54:42 ----D---- C:\Program Files\CamStudio
2010-01-23 12:43:01 ----D---- C:\Program Files\Adobe
2010-01-23 11:45:12 ----D---- C:\Program Files\7-Zip
2010-01-23 11:41:00 ----D---- C:\Program Files\Microsoft Works
2010-01-23 11:40:50 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-23 11:40:50 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-23 11:40:38 ----D---- C:\Windows\PCHEALTH
2010-01-23 11:40:38 ----D---- C:\Program Files\Microsoft.NET
2010-01-23 11:39:01 ----D---- C:\ProgramData\Microsoft Help
2010-01-23 11:39:01 ----D---- C:\Program Files\Microsoft Office
2010-01-23 11:34:35 ----D---- C:\Users\admin\AppData\Roaming\WinRAR
2010-01-23 11:34:02 ----D---- C:\Program Files\WinRAR
2010-01-23 10:48:19 ----D---- C:\Program Files\Common Files\Adobe
2010-01-22 20:32:23 ----D---- C:\NOD32 antivirus 4
2010-01-22 20:26:00 ----D---- C:\ProgramData\ESET
2010-01-22 20:26:00 ----D---- C:\Program Files\ESET
2010-01-22 20:23:18 ----SHD---- C:\Windows\Installer
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Macromedia
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Adobe
2010-01-22 20:07:51 ----D---- C:\Windows\system32\Macromed
2010-01-22 19:36:10 ----A---- C:\Windows\system32\msv1_0.dll
2010-01-22 19:35:46 ----HD---- C:\ProgramData\CanonBJ
2010-01-22 19:34:51 ----A---- C:\Windows\system32\MRT.exe
2010-01-22 19:34:12 ----A---- C:\Windows\system32\tzres.dll
2010-01-22 19:33:58 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-22 19:33:42 ----A---- C:\Windows\system32\wmp.dll
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winresume.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winload.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\CertEnroll.dll
2010-01-22 19:33:40 ----A---- C:\Windows\system32\wmploc.DLL
2010-01-22 19:33:39 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 19:33:39 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\t2embed.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\fontsub.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\atmfd.dll
2010-01-22 19:33:28 ----A---- C:\Windows\system32\msasn1.dll
2010-01-22 19:32:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-22 19:30:34 ----D---- C:\Users\admin\AppData\Roaming\Identities
2010-01-22 19:30:24 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2010-01-22 19:30:24 ----D---- C:\Users\admin\AppData\Roaming\Media Center Programs
2010-01-22 19:20:46 ----D---- C:\Windows\SoftwareDistribution
2010-01-22 19:18:04 ----D---- C:\Windows\Prefetch
2010-01-22 19:16:50 ----D---- C:\Windows\Panther
2010-01-22 19:11:33 ----D---- C:\Windows.old
======List of files/folders modified in the last 1 months======
2010-02-13 11:42:46 ----D---- C:\Windows\Temp
2010-02-13 11:40:45 ----D---- C:\Windows\System32
2010-02-13 11:40:44 ----D---- C:\Windows\inf
2010-02-13 10:22:25 ----D---- C:\Windows\system32\config
2010-02-12 18:56:50 ----RD---- C:\Program Files
2010-02-12 18:56:19 ----SHD---- C:\System Volume Information
2010-02-10 18:11:44 ----D---- C:\Windows\winsxs
2010-02-10 18:10:48 ----D---- C:\Windows\system32\catroot2
2010-02-10 18:10:41 ----D---- C:\Windows\system32\drivers
2010-02-10 18:07:01 ----D---- C:\Windows\system32\catroot
2010-02-09 18:23:41 ----RSD---- C:\Windows\Fonts
2010-02-07 14:05:51 ----HD---- C:\ProgramData
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files
2010-02-07 14:05:11 ----D---- C:\Windows
2010-02-06 11:37:33 ----D---- C:\Windows\system32\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\system32\wfp
2010-02-05 19:09:22 ----D---- C:\Windows\system32\DriverStore
2010-02-05 19:09:22 ----D---- C:\Windows\rescache
2010-02-05 19:09:22 ----D---- C:\Program Files\Internet Explorer
2010-02-05 19:09:20 ----D---- C:\Windows\system32\wbem
2010-02-05 19:09:20 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-05 19:09:18 ----D---- C:\Windows\AppCompat
2010-02-05 19:09:09 ----D---- C:\Windows\registration
2010-02-05 19:06:49 ----D---- C:\Windows\system32\LogFiles
2010-02-04 18:53:19 ----D---- C:\Windows\system32\NDF
2010-01-31 09:27:11 ----D---- C:\Windows\system32\wdi
2010-01-30 18:15:41 ----D---- C:\Windows\Logs
2010-01-24 10:41:25 ----SD---- C:\ProgramData\Microsoft
2010-01-23 19:25:42 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-23 17:52:05 ----RSD---- C:\Windows\assembly
2010-01-23 16:40:37 ----D---- C:\Program Files\Common Files\System
2010-01-23 16:40:37 ----A---- C:\Windows\win.ini
2010-01-23 11:39:35 ----D---- C:\Windows\ShellNew
2010-01-22 20:07:52 ----D---- C:\Windows\Downloaded Program Files
2010-01-22 19:48:41 ----D---- C:\Windows\Microsoft.NET
2010-01-22 19:36:40 ----D---- C:\Windows\system32\Boot
2010-01-22 19:36:40 ----D---- C:\Windows\ehome
2010-01-22 19:36:40 ----D---- C:\Windows\AppPatch
2010-01-22 19:36:40 ----D---- C:\Program Files\Windows Media Player
2010-01-22 19:34:52 ----D---- C:\Windows\debug
2010-01-22 19:34:19 ----D---- C:\Windows\system32\sk-SK
2010-01-22 19:31:11 ----D---- C:\Windows\system32\restore
2010-01-22 19:30:32 ----SHD---- C:\$Recycle.Bin
2010-01-22 19:30:21 ----RD---- C:\Users
2010-01-22 19:30:11 ----SHD---- C:\Recovery
2010-01-22 19:30:11 ----D---- C:\Windows\system32\Recovery
2010-01-22 19:21:22 ----D---- C:\Windows\system32\sysprep
2010-01-22 19:18:37 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-01-23 47360]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 drmkaud;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 AdobeVersionCue;AdobeVersionCue; C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe [2004-03-25 61440]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by admin at 2010-02-13 11:42:44
Microsoft Windows 7 Professional Service Pack 2
System drive C: has 64 GB (64%) free of 100 GB
Total RAM: 2047 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:46, on 13. 2. 2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\admin\Desktop\cistenie PC registre, malware,\RSIT.exe
C:\Program Files\trend micro\admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Podpora odkazu pre aplikáciu Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
--
End of file - 4234 bytes
======Scheduled tasks folder======
C:\Windows\tasks\NeroLiveEpgUpdate-admin-PC_admin.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pre aplikáciu Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2008-06-11 61816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
"AdobeVersionCue"=C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe [2004-03-25 1732608]
"NWEReboot"= []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acrobat Assistant.lnk - C:\Program Files\Adobe\Adobe Acrobat 6.0 CE\Distillr\acrotray.exe
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-02-10 18:07:36 ----A---- C:\Windows\system32\kernel32.dll
2010-02-10 18:07:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-10 18:07:34 ----A---- C:\Windows\system32\apphelp.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\quartz.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-10 18:07:30 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msyuv.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\msrle32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-10 18:07:29 ----A---- C:\Windows\system32\avifil32.dll
2010-02-10 18:07:07 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\secproc.dll
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-10 18:07:06 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-10 18:07:05 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-07 14:05:51 ----D---- C:\Windows\system32\QuickTime
2010-02-07 14:05:51 ----D---- C:\ProgramData\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Macromedia
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files\Macromedia
2010-02-07 14:05:11 ----D---- C:\Windows\Downloaded Installations
2010-02-07 13:36:06 ----D---- C:\Users\admin\AppData\Roaming\Malwarebytes
2010-02-07 13:36:01 ----D---- C:\ProgramData\Malwarebytes
2010-02-07 13:36:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-07 13:24:11 ----D---- C:\Program Files\CCleaner
2010-02-06 11:36:41 ----D---- C:\Windows\system32\appmgmt
2010-02-06 11:05:49 ----D---- C:\Program Files\TrendMicro
2010-02-06 10:36:32 ----D---- C:\Program Files\trend micro
2010-02-06 10:36:31 ----D---- C:\rsit
2010-01-31 08:24:19 ----D---- C:\Users\admin\AppData\Roaming\Google
2010-01-30 18:25:44 ----D---- C:\Users\admin\AppData\Roaming\skypePM
2010-01-30 18:20:16 ----D---- C:\Program Files\Google
2010-01-30 18:19:05 ----D---- C:\ProgramData\Skype
2010-01-27 17:21:06 ----A---- C:\Windows\system32\winlogon.exe
2010-01-27 17:21:06 ----A---- C:\Windows\explorer.exe
2010-01-24 15:32:29 ----D---- C:\Program Files\MSXML 4.0
2010-01-23 19:48:58 ----D---- C:\Users\admin\AppData\Roaming\Nero
2010-01-23 19:34:44 ----A---- C:\Windows\Irremote.ini
2010-01-23 19:26:01 ----D---- C:\ProgramData\Nero
2010-01-23 19:26:00 ----D---- C:\Program Files\Common Files\Nero
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_30.dll
2010-01-23 18:15:52 ----A---- C:\Windows\system32\d3dx9_28.dll
2010-01-23 17:59:36 ----A---- C:\Users\admin\AppData\Roaming\inst.exe
2010-01-23 17:59:35 ----D---- C:\Users\admin\AppData\Roaming\Vso
2010-01-23 17:59:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\vp7vfw.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\sipr3260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\Pncrt.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv43260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv33260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\drv23260.dll
2010-01-23 17:59:19 ----A---- C:\Windows\system32\cook3260.dll
2010-01-23 17:59:16 ----D---- C:\Program Files\VSO
2010-01-23 17:35:37 ----D---- C:\Users\admin\AppData\Roaming\Ahead
2010-01-23 17:13:58 ----D---- C:\Program Files\Nero
2010-01-23 17:13:58 ----D---- C:\Program Files\Common Files\Ahead
2010-01-23 13:15:11 ----D---- C:\ProgramData\Adobe
2010-01-23 13:13:30 ----D---- C:\Windows\system32\Adobe
2010-01-23 13:13:30 ----A---- C:\Windows\system32\FileOps.exe
2010-01-23 13:07:05 ----D---- C:\Program Files\Common Files\InstallShield
2010-01-23 13:05:37 ----HD---- C:\Program Files\Installshield Installation Information
2010-01-23 12:59:14 ----D---- C:\Program Files\YouTube Downloader
2010-01-23 12:54:42 ----D---- C:\Program Files\CamStudio
2010-01-23 12:43:01 ----D---- C:\Program Files\Adobe
2010-01-23 11:45:12 ----D---- C:\Program Files\7-Zip
2010-01-23 11:41:00 ----D---- C:\Program Files\Microsoft Works
2010-01-23 11:40:50 ----D---- C:\Program Files\Microsoft Visual Studio
2010-01-23 11:40:50 ----D---- C:\Program Files\Common Files\DESIGNER
2010-01-23 11:40:38 ----D---- C:\Windows\PCHEALTH
2010-01-23 11:40:38 ----D---- C:\Program Files\Microsoft.NET
2010-01-23 11:39:01 ----D---- C:\ProgramData\Microsoft Help
2010-01-23 11:39:01 ----D---- C:\Program Files\Microsoft Office
2010-01-23 11:34:35 ----D---- C:\Users\admin\AppData\Roaming\WinRAR
2010-01-23 11:34:02 ----D---- C:\Program Files\WinRAR
2010-01-23 10:48:19 ----D---- C:\Program Files\Common Files\Adobe
2010-01-22 20:32:23 ----D---- C:\NOD32 antivirus 4
2010-01-22 20:26:00 ----D---- C:\ProgramData\ESET
2010-01-22 20:26:00 ----D---- C:\Program Files\ESET
2010-01-22 20:23:18 ----SHD---- C:\Windows\Installer
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Macromedia
2010-01-22 20:07:52 ----D---- C:\Users\admin\AppData\Roaming\Adobe
2010-01-22 20:07:51 ----D---- C:\Windows\system32\Macromed
2010-01-22 19:36:10 ----A---- C:\Windows\system32\msv1_0.dll
2010-01-22 19:35:46 ----HD---- C:\ProgramData\CanonBJ
2010-01-22 19:34:51 ----A---- C:\Windows\system32\MRT.exe
2010-01-22 19:34:12 ----A---- C:\Windows\system32\tzres.dll
2010-01-22 19:33:58 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-22 19:33:42 ----A---- C:\Windows\system32\wmp.dll
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winresume.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\winload.exe
2010-01-22 19:33:41 ----A---- C:\Windows\system32\CertEnroll.dll
2010-01-22 19:33:40 ----A---- C:\Windows\system32\wmploc.DLL
2010-01-22 19:33:39 ----A---- C:\Windows\system32\mshtml.dll
2010-01-22 19:33:39 ----A---- C:\Windows\system32\ieframe.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\wininet.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\urlmon.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-22 19:33:38 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\t2embed.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\fontsub.dll
2010-01-22 19:33:37 ----A---- C:\Windows\system32\atmfd.dll
2010-01-22 19:33:28 ----A---- C:\Windows\system32\msasn1.dll
2010-01-22 19:32:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-22 19:30:34 ----D---- C:\Users\admin\AppData\Roaming\Identities
2010-01-22 19:30:24 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2010-01-22 19:30:24 ----D---- C:\Users\admin\AppData\Roaming\Media Center Programs
2010-01-22 19:20:46 ----D---- C:\Windows\SoftwareDistribution
2010-01-22 19:18:04 ----D---- C:\Windows\Prefetch
2010-01-22 19:16:50 ----D---- C:\Windows\Panther
2010-01-22 19:11:33 ----D---- C:\Windows.old
======List of files/folders modified in the last 1 months======
2010-02-13 11:42:46 ----D---- C:\Windows\Temp
2010-02-13 11:40:45 ----D---- C:\Windows\System32
2010-02-13 11:40:44 ----D---- C:\Windows\inf
2010-02-13 10:22:25 ----D---- C:\Windows\system32\config
2010-02-12 18:56:50 ----RD---- C:\Program Files
2010-02-12 18:56:19 ----SHD---- C:\System Volume Information
2010-02-10 18:11:44 ----D---- C:\Windows\winsxs
2010-02-10 18:10:48 ----D---- C:\Windows\system32\catroot2
2010-02-10 18:10:41 ----D---- C:\Windows\system32\drivers
2010-02-10 18:07:01 ----D---- C:\Windows\system32\catroot
2010-02-09 18:23:41 ----RSD---- C:\Windows\Fonts
2010-02-07 14:05:51 ----HD---- C:\ProgramData
2010-02-07 14:05:45 ----D---- C:\Program Files\Common Files
2010-02-07 14:05:11 ----D---- C:\Windows
2010-02-06 11:37:33 ----D---- C:\Windows\system32\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\Tasks
2010-02-05 19:09:22 ----D---- C:\Windows\system32\wfp
2010-02-05 19:09:22 ----D---- C:\Windows\system32\DriverStore
2010-02-05 19:09:22 ----D---- C:\Windows\rescache
2010-02-05 19:09:22 ----D---- C:\Program Files\Internet Explorer
2010-02-05 19:09:20 ----D---- C:\Windows\system32\wbem
2010-02-05 19:09:20 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-05 19:09:18 ----D---- C:\Windows\AppCompat
2010-02-05 19:09:09 ----D---- C:\Windows\registration
2010-02-05 19:06:49 ----D---- C:\Windows\system32\LogFiles
2010-02-04 18:53:19 ----D---- C:\Windows\system32\NDF
2010-01-31 09:27:11 ----D---- C:\Windows\system32\wdi
2010-01-30 18:15:41 ----D---- C:\Windows\Logs
2010-01-24 10:41:25 ----SD---- C:\ProgramData\Microsoft
2010-01-23 19:25:42 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-23 17:52:05 ----RSD---- C:\Windows\assembly
2010-01-23 16:40:37 ----D---- C:\Program Files\Common Files\System
2010-01-23 16:40:37 ----A---- C:\Windows\win.ini
2010-01-23 11:39:35 ----D---- C:\Windows\ShellNew
2010-01-22 20:07:52 ----D---- C:\Windows\Downloaded Program Files
2010-01-22 19:48:41 ----D---- C:\Windows\Microsoft.NET
2010-01-22 19:36:40 ----D---- C:\Windows\system32\Boot
2010-01-22 19:36:40 ----D---- C:\Windows\ehome
2010-01-22 19:36:40 ----D---- C:\Windows\AppPatch
2010-01-22 19:36:40 ----D---- C:\Program Files\Windows Media Player
2010-01-22 19:34:52 ----D---- C:\Windows\debug
2010-01-22 19:34:19 ----D---- C:\Windows\system32\sk-SK
2010-01-22 19:31:11 ----D---- C:\Windows\system32\restore
2010-01-22 19:30:32 ----SHD---- C:\$Recycle.Bin
2010-01-22 19:30:21 ----RD---- C:\Users
2010-01-22 19:30:11 ----SHD---- C:\Recovery
2010-01-22 19:30:11 ----D---- C:\Windows\system32\Recovery
2010-01-22 19:21:22 ----D---- C:\Windows\system32\sysprep
2010-01-22 19:18:37 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 discache;@%systemroot%\system32\drivers\discache.sys,-102; C:\Windows\System32\drivers\discache.sys [2009-07-14 32256]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 RDPREFMP;@%systemroot%\system32\drivers\RdpRefMp.sys,-101; C:\Windows\system32\drivers\rdprefmp.sys [2009-07-14 7168]
R1 WfpLwf;WFP Lightweight Filter; C:\Windows\system32\DRIVERS\wfplwf.sys [2009-07-14 9728]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R3 1394ohci;1394 OHCI Compliant Host Controller; C:\Windows\system32\DRIVERS\1394ohci.sys [2009-07-14 163328]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller; C:\Windows\system32\DRIVERS\l160x86.sys [2009-07-13 47104]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-08-18 4994560]
R3 CompositeBus;Composite Bus Enumerator Driver; C:\Windows\system32\DRIVERS\CompositeBus.sys [2009-07-14 31232]
R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2009-07-14 304128]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-01-23 47360]
R3 RasAgileVpn;WAN Miniport (IKEv2); C:\Windows\system32\DRIVERS\AgileVpn.sys [2009-07-14 49152]
R3 rdpbus;Remote Desktop Device Redirector Bus Driver; C:\Windows\system32\DRIVERS\rdpbus.sys [2009-07-14 18944]
R3 WudfPf;User Mode Driver Frameworks Platform Driver; C:\Windows\system32\drivers\WudfPf.sys [2009-07-14 92672]
S3 AcpiPmi;ACPI Power Meter Driver; C:\Windows\system32\DRIVERS\acpipmi.sys [2009-07-14 9728]
S3 AmdPPM;AMD Processor Driver; C:\Windows\system32\DRIVERS\amdppm.sys [2009-07-14 52736]
S3 amdsata;amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [2009-07-14 79952]
S3 amdsbs;amdsbs; C:\Windows\system32\DRIVERS\amdsbs.sys [2009-07-14 159312]
S3 AppID;@%systemroot%\system32\appidsvc.dll,-102; C:\Windows\system32\drivers\appid.sys [2009-07-14 50176]
S3 b06bdrv;Broadcom NetXtreme II VBD; C:\Windows\system32\DRIVERS\bxvbdx.sys [2009-07-13 430080]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2009-07-14 14080]
S3 drmkaud;Microsoft Trusted Audio Drivers; C:\Windows\system32\drivers\drmkaud.sys [2009-07-14 5120]
S3 ebdrv;Broadcom NetXtreme II 10 GigE VBD; C:\Windows\system32\DRIVERS\evbdx.sys [2009-07-13 3100160]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\DRIVERS\errdev.sys [2009-07-14 7168]
S3 FsDepends;@%SystemRoot%\system32\drivers\fsdepends.sys,-10001; C:\Windows\System32\drivers\FsDepends.sys [2009-07-14 46160]
S3 hcw85cir;Hauppauge Consumer Infrared Receiver; C:\Windows\system32\drivers\hcw85cir.sys [2009-07-13 26624]
S3 HidBatt;HID UPS Battery Driver; C:\Windows\system32\DRIVERS\HidBatt.sys [2009-07-14 21504]
S3 HpSAMD;HpSAMD; C:\Windows\system32\DRIVERS\HpSAMD.sys [2009-07-14 67152]
S3 LSI_SAS2;LSI_SAS2; C:\Windows\system32\DRIVERS\lsi_sas2.sys [2009-07-14 54864]
S3 MegaSR;MegaSR; C:\Windows\system32\DRIVERS\MegaSR.sys [2009-07-14 235584]
S3 mshidkmdf;@%SystemRoot%\system32\drivers\mshidkmdf.sys,-100; C:\Windows\System32\drivers\mshidkmdf.sys [2009-07-14 4096]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2009-07-14 8320]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2009-07-14 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2009-07-14 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2009-07-14 6144]
S3 MTConfig;Microsoft Input Configuration Driver; C:\Windows\system32\DRIVERS\MTConfig.sys [2009-07-14 12288]
S3 NdisCap;NDIS Capture LightWeight Filter; C:\Windows\system32\DRIVERS\ndiscap.sys [2009-07-14 27136]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 scfilter;@%SystemRoot%\System32\drivers\scfilter.sys,-11; C:\Windows\System32\DRIVERS\scfilter.sys [2009-07-14 26624]
S3 stexstor;stexstor; C:\Windows\system32\DRIVERS\stexstor.sys [2009-07-14 21072]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 UmPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2009-07-14 8192]
S3 vhdmp;vhdmp; C:\Windows\system32\DRIVERS\vhdmp.sys [2009-07-14 159824]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 vwifibus;@%SystemRoot%\System32\drivers\vwifibus.sys,-257; C:\Windows\System32\drivers\vwifibus.sys [2009-07-14 19968]
S3 WIMMount;WIMMount; C:\Windows\system32\drivers\wimmount.sys [2009-07-14 19008]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]
S3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2009-07-14 11264]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2009-07-14 132224]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-08-18 176128]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 Power;@%SystemRoot%\system32\umpo.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 RpcEptMapper;@%windir%\system32\RpcEpMap.dll,-1001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 sppsvc;@%SystemRoot%\system32\sppsvc.exe,-101; C:\Windows\system32\sppsvc.exe [2009-07-14 3179520]
R3 HomeGroupListener;@%SystemRoot%\System32\ListSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R3 HomeGroupProvider;@%SystemRoot%\System32\provsvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 AdobeVersionCue;AdobeVersionCue; C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe [2004-03-25 61440]
S3 AppIDSvc;@%systemroot%\system32\appidsvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 AxInstSV;@%SystemRoot%\system32\AxInstSV.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BDESVC;@%SystemRoot%\system32\bdesvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 bthserv;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 defragsvc;@%SystemRoot%\system32\defragsvc.dll,-101; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 EFS;@%SystemRoot%\system32\efssvc.dll,-100; C:\Windows\System32\lsass.exe [2009-07-14 22528]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2009-07-14 522752]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 SensrSvc;@%SystemRoot%\System32\sensrsvc.dll,-1000; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 sppuinotify;@%SystemRoot%\system32\sppuinotify.dll,-103; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 VaultSvc;@%SystemRoot%\system32\vaultsvc.dll,-1003; C:\Windows\system32\lsass.exe [2009-07-14 22528]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2009-07-14 1202688]
S3 WbioSrvc;@%systemroot%\system32\wbiosrvc.dll,-100; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 WwanSvc;@%SystemRoot%\System32\wwansvc.dll,-257; C:\Windows\system32\svchost.exe [2009-07-14 20992]
-----------------EOF-----------------