Logfile of random's system information tool 1.09 (written by random/random)
Run by Administrator at 2011-08-31 20:07:21
Microsoft® Windows Vista™ Ultimate Service Pack 2
System drive C: has 6 GB (9%) free of 71 GB
Total RAM: 8190 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:40:31, on 30.8.2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\PROGRA~1\ASUS\AISUIT~1\AiGear3\CPUPOW~1.EXE
C:\PROGRA~2\DivX\DIVXUP~1\DIVXUP~1.EXE
C:\PROGRA~1\AVASTS~1\Avast\AvastUI.exe
C:\PROGRA~2\Intel\INTELM~1\IAAnotif.exe
C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe
C:\PROGRA~2\BITTOR~1\BITTOR~1.EXE
C:\PROGRA~2\DAEMON~1\DTLite.exe
C:\PROGRA~2\Hamachi\hamachi.exe
C:\PROGRA~2\ICQ7.5\ICQ.exe
C:\PROGRA~2\MOZILL~1\firefox.exe
C:\PROGRA~2\MOZILL~1\plugin-container.exe
C:\Users\ADMINI~1\AppData\Local\Temp\winpbebwb.exe
C:\Users\ADMINI~1\AppData\Local\Temp\winkjvvfb.exe
C:\PROGRA~1\TRENDM~1\ADMINI~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bigseekpro.com/pivotstickfig ... A6D93936BD}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files (x86)\Pivot Stickfigure Toolbar\tbhelper.dll
R3 - URLSearchHook: (no name) - {9a29aeac-5ebd-407c-b5e2-144157d51936} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {9a29aeac-5ebd-407c-b5e2-144157d51936} - (no file)
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\Pivot Stickfigure Toolbar\tbcore3.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
O3 - Toolbar: Pivot Stickfigure Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\Pivot Stickfigure Toolbar\tbcore3.dll
O3 - Toolbar: (no name) - {9a29aeac-5ebd-407c-b5e2-144157d51936} - (no file)
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\tbBS_P.dll
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [4StoryPrePatch] "D:\Program Files (x86)\Gameforge4D\4Story\PrePatch.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WeatherBugAlert] "C:\Program Files (x86)\AWS\WeatherBug Alert\WeatherBugAlert.exe" /st
O4 - HKCU\..\Run: [System Smart Security] "C:\ProgramData\b7c20c\SSb7c_2140.exe" /s /d
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [BitTorrent] "C:\PROGRA~2\BITTOR~1\BITTOR~1.EXE"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\PROGRA~2\DAEMON~1\DTLite.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files (x86)\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: hamachi.lnk = C:\Program Files (x86)\Hamachi\hamachi.exe
O4 - Global Startup: AutoClicker.lnk = C:\AutoClickExtreme\AutoClicker.exe
O4 - Global Startup: DynDNS Updater Tray Icon.lnk = C:\Program Files (x86)\DynDNS Updater\DynTray.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{17C5919F-1FA8-487F-90AF-5F9E31C2B18C}: NameServer = 216.146.35.35,216.146.36.36
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF7DD46C-4A79-4268-A3DE-EF61F58CF371}: NameServer = 216.146.35.35,216.146.36.36
O17 - HKLM\System\CS1\Services\Tcpip\..\{17C5919F-1FA8-487F-90AF-5F9E31C2B18C}: NameServer = 216.146.35.35,216.146.36.36
O17 - HKLM\System\CS7\Services\Tcpip\..\{17C5919F-1FA8-487F-90AF-5F9E31C2B18C}: NameServer = 216.146.35.35,216.146.36.36
O17 - HKLM\System\CS8\Services\Tcpip\..\{17C5919F-1FA8-487F-90AF-5F9E31C2B18C}: NameServer = 216.146.35.35,216.146.36.36
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Skype Recorder\Skype4COM.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Unknown owner - C:\Windows\system32\AEADISRV.EXE (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: DynDNS Updater - Dynamic Network Services, Inc. - C:\Program Files (x86)\DynDNS Updater\DynUpSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: mysql - Unknown owner - c:\xampp\mysql\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: wampapache - Unknown owner - D:\wamp\bin\apache\apache2.2.11\bin\httpd.exe (file missing)
O23 - Service: wampmysqld - Unknown owner - D:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11192 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {5AE5B89B-F654-4A22-8467-C92DB40D821E}
taskeng.exe {7A45413D-A1F4-4CEC-9EB1-F0DD349949FC}
C:\Users\ADMINI~1\AppData\Local\Temp\3582-490\aaCenter.exe
C:\PROGRA~1\WICC9F~1\sidebar.exe /autoRun
C:\PROGRA~2\DAEMON~1\DTLite.exe -autorun
C:\PROGRA~1\AVASTS~1\Avast\AvastUI.exe /nogui
C:\PROGRA~1\ASUS\AISUIT~1\AiGear3\CPUPOW~1.EXE
C:\PROGRA~2\LOGMEI~1\HAMACH~2.EXE --auto-start
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\PROGRA~2\Intel\INTELM~1\IAAnotif.exe
C:\Windows\system32\AEADISRV.EXE
"C:\xampp\apache\bin\httpd.exe" -k runservice
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe"
C:\xampp\apache\bin\httpd.exe -d C:/xampp/apache
C:\PROGRA~1\WICC9F~1\sidebar.exe /autoRun
"C:\Windows\Explorer.exe" /separate,/idlist,:49182:2096,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
c:\xampp\mysql\bin\mysqld.exe --defaults-file=c:\xampp\mysql\bin\my.ini mysql
"C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe" -service
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-18233850-0932-466c-8242-daabafefe1fc -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-54eee700-c80e-4443-9d25-f86340d58f67 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-7e7ad8be-88dd-4422-82ab-d0d6a3d1c324 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a6bf86ea-006c-413e-b5ea-183ea575c21b
"C:\Program Files (x86)\DynDNS Updater\DynUpSvc.exe"
"C:\Program Files\Windows Media Player\wmpnscfg.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=5932.aeb8a80.72894955 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" - -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 5932 "\\.\pipe\gecko-crash-server-pipe.5932" plugin
C:\Windows\TEMP\3582-490\MBAMSE~1.EXE
C:\Users\ADMINI~1\AppData\Local\Temp\winpcghyk.exe
C:\PROGRA~1\Sun\VIRTUA~1\VIRTUA~1.EXE
C:\PROGRA~1\Sun\VIRTUA~1\VBoxSVC.exe -Embedding
C:\Windows\TEMP\whtm.exe
C:\Users\ADMINI~1\AppData\Local\Temp\wincxpx.exe
C:\Windows\TEMP\winhfwtjo.exe
C:\xampp\XAMPP-~1.EXE
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe25_ Global\UsGthrCtrlFltPipeMssGthrPipe25 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 668 672 680 65536 676
C:\Users\ADMINI~1\AppData\Local\Temp\3582-490\RSITX6~1.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\ADMINI~1.EXE /silentautolog
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1052879530-2571350418-974908233-500Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1052879530-2571350418-974908233-500UA.job
C:\Windows\tasks\User_Feed_Synchronization-{B97A25D9-03BE-46A8-B934-C7C86E756055}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-05-10 977472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-07-16 49440]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}]
DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23 115072]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-05-10 819840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9a29aeac-5ebd-407c-b5e2-144157d51936}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
SMTTB2009 Class - C:\Program Files (x86)\Pivot Stickfigure Toolbar\tbcore3.dll [2010-02-16 2495488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll []
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-05-10 977472]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{9a29aeac-5ebd-407c-b5e2-144157d51936}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-05-10 819840]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\ICQToolBar.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2010-08-26 1875048]
"IAAnotif"=C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2011-08-30 248600]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1555968]
"DAEMON Tools Lite"=C:\PROGRA~2\DAEMON~1\DTLite.exe [2011-08-31 4980544]
"WMPNSCFG"=C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"CPU Power Monitor"=C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe [2007-09-06 707584]
"SoundMAXPnP"=C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [2011-08-30 1220096]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-05-10 3459712]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 785968]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2011-08-15 2024840]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AutoClicker.lnk - D:\C\AutoClickExtreme\AutoClicker.exe
DynDNS Updater Tray Icon.lnk - C:\Program Files (x86)\DynDNS Updater\DynTray.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
"DisableRegistryTools"=1
"DisableCMD"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=2
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"DisableTaskMgr"=0
"DisableCMD"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe"="C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\BitTorrent\BitTorrent.exe"="C:\Program Files (x86)\BitTorrent\BitTorrent.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\knobcj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\knobcj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\qdjcm.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\qdjcm.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winybsgqg.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winybsgqg.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winhdimu.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winhdimu.exe:*:Enabled:ipsec"
"C:\PROGRA~1\ASUS\AISUIT~1\AiGear3\CPUPOW~1.EXE"="C:\PROGRA~1\ASUS\AISUIT~1\AiGear3\CPUPOW~1.EXE:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winfvlw.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winfvlw.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\ykhids.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\ykhids.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winifbj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winifbj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wineiiljp.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wineiiljp.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe"="C:\Program Files (x86)\ASUS\AASP\1.00.40\aaCenter.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\isueh.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\isueh.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\dtyqv.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\dtyqv.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winrqeqe.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winrqeqe.exe:*:Enabled:ipsec"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"="C:\Program Files (x86)\Mozilla Firefox\firefox.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winhytyo.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winhytyo.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\drnn.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\drnn.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winmnxl.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winmnxl.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\vlqg.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\vlqg.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\txut.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\txut.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wqcu.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wqcu.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winklqn.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winklqn.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\cwnff.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\cwnff.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\xvewj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\xvewj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\yyyan.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\yyyan.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winpocjv.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winpocjv.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wincjit.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wincjit.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winfweo.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winfweo.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wincwqtdw.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wincwqtdw.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\pwfax.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\pwfax.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winrgnq.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winrgnq.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winleir.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winleir.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\windaaiky.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\windaaiky.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\kglx.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\kglx.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\iyaga.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\iyaga.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winjdmr.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winjdmr.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winjkppkv.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winjkppkv.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\ppid.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\ppid.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winoprcxx.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winoprcxx.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winwhkfo.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winwhkfo.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winbovc.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winbovc.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winoudr.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winoudr.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winrvcnbs.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winrvcnbs.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winbqkd.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winbqkd.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\dvujb.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\dvujb.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winutqck.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winutqck.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\orcawj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\orcawj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winvvjgjo.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winvvjgjo.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winbpuf.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winbpuf.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winvnkw.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winvnkw.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winmmiolj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winmmiolj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\pfki.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\pfki.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wintatxk.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wintatxk.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winitdw.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winitdw.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\qvkmd.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\qvkmd.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\qdrj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\qdrj.exe:*:Enabled:ipsec"
"c:\xampp\apache\bin\httpd.exe"="C:\xampp\apache\bin\httpd.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winmann.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winmann.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winevtu.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winevtu.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winluqacc.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winluqacc.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wincekk.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wincekk.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\tlxid.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\tlxid.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winykdgvq.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winykdgvq.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\irbjpr.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\irbjpr.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\giodkc.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\giodkc.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\ldlbbp.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\ldlbbp.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wodiyb.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wodiyb.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\kylabp.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\kylabp.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\lrpfwe.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\lrpfwe.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\ourx.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\ourx.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winobwxk.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winobwxk.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\cgle.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\cgle.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winonws.exe"="C:\Windows\TEMP\winonws.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winiobt.exe"="C:\Windows\TEMP\winiobt.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\cpwp.exe"="C:\Windows\TEMP\cpwp.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winkjpbu.exe"="C:\Windows\TEMP\winkjpbu.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winhkcrb.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winhkcrb.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winifsj.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winifsj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winxbarjb.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winxbarjb.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winvokib.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winvokib.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\tqqt.exe"="C:\Windows\TEMP\tqqt.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winxjfrrl.exe"="C:\Windows\TEMP\winxjfrrl.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winqwrj.exe"="C:\Windows\TEMP\winqwrj.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wvtpt.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wvtpt.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\doapo.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\doapo.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winyknv.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winyknv.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winsumptj.exe"="C:\Windows\TEMP\winsumptj.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\wintrxofp.exe"="C:\Windows\TEMP\wintrxofp.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\fbxjt.exe"="C:\Windows\TEMP\fbxjt.exe:*:Enabled:ipsec"
"D:\OTM.exe"="D:\OTM.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winpcghyk.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winpcghyk.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winlnays.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winlnays.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\winopxwad.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\winopxwad.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\whtm.exe"="C:\Windows\TEMP\whtm.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\windlhdt.exe"="C:\Windows\TEMP\windlhdt.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winmqtfgh.exe"="C:\Windows\TEMP\winmqtfgh.exe:*:Enabled:ipsec"
"C:\Users\ADMINI~1\AppData\Local\Temp\wincxpx.exe"="C:\Users\ADMINI~1\AppData\Local\Temp\wincxpx.exe:*:Enabled:ipsec"
"C:\Windows\TEMP\winhfwtjo.exe"="C:\Windows\TEMP\winhfwtjo.exe:*:Enabled:ipsec"
"C:\PROGRA~2\WinSCP\WinSCP.exe"="C:\PROGRA~2\WinSCP\WinSCP.exe:*:Enabled:ipsec"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"midi1"=wdmaud.drv
======File associations======
.exe - open - C:\Windows\svchost.com "%1" %*
.txt - open - %SystemRoot%\SysWow64\NOTEPAD.EXE %1
======List of files/folders created in the last 1 month======
2011-08-31 20:07:21 ----D---- C:\rsit
2011-08-31 19:31:43 ----D---- C:\games
2011-08-31 17:53:33 ----D---- C:\_OTM
2011-08-31 16:12:49 ----A---- C:\Windows\isRS-000.tmp
2011-08-31 08:00:07 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2011-08-31 01:00:23 ----A---- C:\Windows\SYSWOW64\debug.txt
2011-08-30 21:36:10 ----A---- C:\Windows\SYSWOW64\exehelperlog.txt
2011-08-30 21:21:51 ----A---- C:\Windows\svchost.com
2011-08-30 19:25:51 ----D---- C:\Users\Administrator\AppData\Roaming\Malwarebytes
2011-08-30 19:25:46 ----D---- C:\ProgramData\Malwarebytes
2011-08-30 19:25:46 ----A---- C:\Windows\SYSWOW64\drivers\mbamswissarmy.sys
2011-08-30 19:25:43 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-30 19:25:43 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-08-30 18:54:18 ----SHD---- C:\$RECYCLE.BIN
2011-08-30 16:58:31 ----A---- C:\Windows\directx.sys
2011-08-30 16:55:22 ----D---- C:\Windows\temp
2011-08-30 15:17:59 ----D---- C:\Qoobox
2011-08-30 14:40:25 ----D---- C:\Program Files\trend micro
2011-08-30 10:04:38 ----D---- C:\Windows\Microsoft_app
2011-08-29 00:36:56 ----D---- C:\FR
2011-08-28 12:06:09 ----D---- C:\Nová složka (2)
2011-08-28 11:48:12 ----D---- C:\Nová složka
2011-08-28 11:43:38 ----D---- C:\tutorial
2011-08-28 11:39:07 ----A---- C:\m2.exe
2011-08-28 11:39:07 ----A---- C:\Extraction Helper .exe
2011-08-28 11:39:07 ----A---- C:\Archiver Helper.exe
2011-08-28 11:39:06 ----RD---- C:\system
2011-08-28 11:29:03 ----D---- C:\extract
2011-08-28 11:27:30 ----D---- C:\Source
2011-08-28 11:25:28 ----A---- C:\Easy File Extract0r by Eddy² 4 epvp.exe
2011-08-27 12:33:00 ----D---- C:\ProgramData\DynDNS
2011-08-24 12:13:49 ----D---- C:\Users\Administrator\AppData\Roaming\SynthMaker
2011-08-24 11:50:25 ----D---- C:\Users\Administrator\AppData\Roaming\.minecraft
2011-08-24 11:23:28 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-08-24 11:23:28 ----A---- C:\Windows\system32\tzres.dll
2011-08-24 01:31:02 ----D---- C:\Program Files\Yamaha
2011-08-24 01:26:14 ----D---- C:\Program Files (x86)\YAMAHA
2011-08-21 16:13:32 ----D---- C:\Eddy2
2011-08-20 13:39:26 ----A---- C:\Game-Tool.exe
2011-08-20 11:45:01 ----A---- C:\MT2ExpMod_1.1.0.0(1).exe
2011-08-19 22:08:15 ----D---- C:\Program Files (x86)\ConTEXT
2011-08-19 14:49:00 ----A---- C:\MT2ExpMod_1.2.0.0(1).exe
2011-08-19 13:33:05 ----A---- C:\EXP Edit.exe
2011-08-19 13:32:35 ----D---- C:\Users\Administrator\AppData\Roaming\expedit
2011-08-19 13:32:27 ----RD---- C:\EXP Edit
2011-08-19 13:32:27 ----D---- C:\Free_UPX
2011-08-18 22:57:26 ----D---- C:\Users\Administrator\AppData\Roaming\EditPlus 3
2011-08-18 22:57:26 ----D---- C:\Program Files (x86)\EditPlus 3
2011-08-18 22:31:54 ----A---- C:\MT2ExpMod_1.2.0.0.exe
2011-08-18 22:12:06 ----A---- C:\EXP_Edit_v1.5_by_Eddy².exe
2011-08-18 00:08:44 ----D---- C:\Program Files (x86)\DynDNS Updater
2011-08-16 21:28:15 ----D---- C:\Program Files (x86)\Conduit
2011-08-16 21:28:14 ----D---- C:\Program Files (x86)\BS_Player
2011-08-16 21:28:10 ----D---- C:\Users\Administrator\AppData\Roaming\BSplayer Pro
2011-08-16 21:28:10 ----D---- C:\Users\Administrator\AppData\Roaming\BSplayer
2011-08-16 21:28:10 ----D---- C:\Program Files (x86)\Webteh
2011-08-16 17:54:10 ----D---- C:\hl2
2011-08-16 12:17:27 ----D---- C:\Program Files (x86)\GIMP-2.0
2011-08-15 17:45:02 ----D---- C:\Program Files\Peter
2011-08-13 12:05:05 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2011-08-10 10:37:38 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-10 10:37:38 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 10:37:38 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 10:37:38 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 10:37:37 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-10 10:37:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-10 10:37:16 ----A---- C:\Windows\system32\wininet.dll
2011-08-10 10:37:16 ----A---- C:\Windows\system32\mshtml.dll
2011-08-10 10:37:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-10 10:37:15 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-10 10:37:15 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-10 10:37:15 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-10 10:37:15 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-10 10:37:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-10 10:37:15 ----A---- C:\Windows\system32\urlmon.dll
2011-08-10 10:37:15 ----A---- C:\Windows\system32\url.dll
2011-08-10 10:37:15 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-10 10:37:15 ----A---- C:\Windows\system32\iertutil.dll
2011-08-10 10:37:15 ----A---- C:\Windows\system32\ieframe.dll
2011-08-10 10:37:14 ----A---- C:\Windows\SYSWOW64\mstime.dll
2011-08-10 10:37:14 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-08-10 10:37:14 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-08-10 10:37:14 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-10 10:37:14 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-08-10 10:37:14 ----A---- C:\Windows\system32\mstime.dll
2011-08-10 10:37:14 ----A---- C:\Windows\system32\msfeeds.dll
2011-08-10 10:37:14 ----A---- C:\Windows\system32\iepeers.dll
2011-08-10 10:37:14 ----A---- C:\Windows\system32\ieapfltr.dll
2011-08-07 14:33:15 ----D---- C:\Program Files (x86)\RTF Viewer
2011-08-05 19:22:19 ----D---- C:\Program Files\Tracker Software
2011-08-05 12:19:06 ----D---- C:\ProgramData\ICQ
2011-08-05 12:18:34 ----D---- C:\Users\Administrator\AppData\Roaming\ICQ
2011-08-05 12:18:30 ----D---- C:\Program Files (x86)\ICQ7.5
2011-08-04 18:46:54 ----D---- C:\Program Files\Valve
2011-08-04 18:42:05 ----ASH---- C:\pagefile.sys
======List of files/folders modified in the last 1 month======
2011-08-31 19:32:00 ----D---- C:\Windows
2011-08-31 18:05:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-08-31 18:05:04 ----D---- C:\Windows\System32
2011-08-31 18:05:04 ----D---- C:\Windows\inf
2011-08-31 18:05:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-31 17:58:56 ----D---- C:\ProgramData\NVIDIA
2011-08-31 17:57:44 ----D---- C:\Program Files (x86)\WinSCP
2011-08-31 17:55:48 ----SHD---- C:\System Volume Information
2011-08-31 17:34:14 ----D---- C:\Users\Administrator\AppData\Roaming\Skype
2011-08-31 11:17:49 ----D---- C:\Windows\Prefetch
2011-08-31 09:06:35 ----D---- C:\xampp
2011-08-31 08:00:34 ----SHD---- C:\Windows\Installer
2011-08-31 08:00:10 ----D---- C:\Windows\system32\drivers
2011-08-31 08:00:07 ----RD---- C:\Program Files (x86)
2011-08-31 01:00:23 ----D---- C:\Windows\SysWOW64
2011-08-30 22:29:31 ----RSD---- C:\Windows\Fonts
2011-08-30 20:58:12 ----D---- C:\Users\Administrator\AppData\Roaming\Hamachi
2011-08-30 19:30:34 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-30 19:25:46 ----D---- C:\ProgramData
2011-08-30 19:23:37 ----D---- C:\Windows\Minidump
2011-08-30 16:57:28 ----A---- C:\Windows\system.ini
2011-08-30 16:57:20 ----D---- C:\Windows\system32\drivers\etc
2011-08-30 16:55:45 ----D---- C:\Windows\system32\config
2011-08-30 16:54:51 ----D---- C:\Program Files (x86)\ConduitEngine
2011-08-30 16:52:00 ----D---- C:\Windows\AppPatch
2011-08-30 16:51:58 ----D---- C:\Program Files\Common Files
2011-08-30 16:51:58 ----D---- C:\Program Files (x86)\Common Files
2011-08-30 16:24:33 ----D---- C:\Users\Administrator\AppData\Roaming\BitTorrent
2011-08-30 15:24:14 ----D---- C:\Program Files (x86)\Pivot Stickfigure Toolbar
2011-08-30 15:15:22 ----D---- C:\Windows\system32\WDI
2011-08-30 14:40:25 ----RD---- C:\Program Files
2011-08-30 13:33:55 ----RAS---- C:\BOOTSECT.BAK
2011-08-30 13:33:45 ----D---- C:\Boot
2011-08-30 13:24:16 ----D---- C:\AutoClickExtreme
2011-08-29 15:20:11 ----D---- C:\Users\Administrator\AppData\Roaming\FileZilla
2011-08-28 01:07:31 ----D---- C:\Users\Administrator\AppData\Roaming\uTorrent
2011-08-27 13:27:05 ----D---- C:\Windows\Tasks
2011-08-27 13:27:05 ----D---- C:\Windows\system32\Tasks
2011-08-26 23:36:20 ----D---- C:\Windows\system32\NDF
2011-08-25 11:59:24 ----D---- C:\Windows\rescache
2011-08-25 01:45:43 ----D---- C:\Windows\winsxs
2011-08-25 01:45:40 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-08-25 01:45:40 ----D---- C:\Windows\system32\cs-CZ
2011-08-24 11:22:32 ----D---- C:\Windows\system32\catroot2
2011-08-24 11:22:32 ----D---- C:\Windows\system32\catroot
2011-08-24 01:26:14 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-08-16 21:28:15 ----RD---- C:\Users
2011-08-13 12:10:22 ----D---- C:\Program Files (x86)\PhotoFiltre Studio X
2011-08-13 12:05:05 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2011-08-13 12:00:32 ----RSD---- C:\Windows\assembly
2011-08-11 13:42:47 ----D---- C:\ProgramData\Electronic Arts
2011-08-10 21:18:50 ----D---- C:\Windows\Microsoft.NET
2011-08-10 20:30:41 ----D---- C:\Program Files\Windows Mail
2011-08-10 20:30:41 ----D---- C:\Program Files (x86)\Windows Mail
2011-08-10 20:10:40 ----A---- C:\Windows\system32\MRT.INI
2011-08-10 20:08:36 ----A---- C:\Windows\system32\mrt.exe
2011-08-05 18:07:05 ----SD---- C:\Windows\Downloaded Program Files
2011-08-05 09:59:58 ----A---- C:\Windows\win.ini
2011-08-04 21:51:06 ----D---- C:\Program Files\Zrychleni Pocitace
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 fvevol;BitLocker Drive Encryption Filter Driver; C:\Windows\System32\DRIVERS\fvevol.sys [2009-04-11 160744]
R0 iaStor;Intel RAID Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2007-03-21 381720]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-08-13 526392]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2006-10-18 13632]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-05-10 31064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-05-10 600920]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-05-10 287576]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-05-10 53592]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys [2009-12-17 193232]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows\system32\DRIVERS\VBoxUSBMon.sys [2009-12-17 53264]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-05-10 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-05-10 64344]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\ADIHdAud.sys [2007-07-18 432640]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2011-08-13 270912]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-07-06 25912]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-31 15680]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2010-09-02 12500840]
R3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2009-11-09 35112]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\Windows\system32\DRIVERS\VBoxNetFlt.sys [2009-12-17 165200]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\Windows\system32\DRIVERS\vcsvad.sys [2008-12-10 21504]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 108544]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x64.sys [2007-05-24 335872]
S3 ab5watl9;ab5watl9; C:\Windows\system32\drivers\ab5watl9.sys []
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2006-11-02 6144]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 273920]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 11008]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2006-11-02 7040]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2006-11-02 6656]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 7936]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows\system32\DRIVERS\VBoxNetAdp.sys [2009-12-17 145360]
S3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM); C:\Windows\system32\drivers\ymidusbx64.sys [2011-01-31 49256]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AEADIFilters;Andrea ADI Filters Service; C:\Windows\system32\AEADISRV.EXE [2007-06-07 89088]
R2 Apache2.2;Apache2.2; C:\xampp\apache\bin\httpd.exe [2010-10-18 90181]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-05-10 42184]
R2 DynDNS Updater;DynDNS Updater; C:\Program Files (x86)\DynDNS Updater\DynUpSvc.exe [2011-04-15 93048]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 27648]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-03-21 355096]
R2 mysql;mysql; c:\xampp\mysql\bin\mysqld.exe [2010-12-03 8133120]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service; C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [2008-12-11 4297728]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-09-01 159336]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-09-01 235624]
R2 TeamViewer5;TeamViewer 5; C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe [2009-12-17 185640]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 490032]
S2 wampapache;wampapache; D:\wamp\bin\apache\apache2.2.11\bin\httpd.exe -k runservice []
S3 FileZilla Server;FileZilla Server FTP server; c:\xampp\FileZillaFTP\FileZillaServer.exe [2011-08-31 784384]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe []
S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-18 19968]
S3 wampmysqld;wampmysqld; D:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe wampmysqld []
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
-----------------EOF-----------------