Win32/Adware
Napsal: 21 kvě 2010 19:36
Dobry den!
Mam problem , ze Eset Smart Security mi hlasi problem:
http://download.mybrowserbar.com/vkits/ ... oolbar.msi Win32/Adware.Toolbar.Dealio aplikácia prerušené spojenie - uložený do karantény Infiltrácia bola zachytená pri prístupe na web aplikáciou: C:\Users\Majo\AppData\Local\Temp\is-3R3IP.tmp\pdfforgeToolbar-stub-1.exe.
Takato tabulka sa vyhadzuje opakovane asi po 30ych sekundach....
Prikladam log:
Logfile of random's system information tool 1.07 (written by random/random)
Run by Majo at 2010-05-21 20:30:57
Microsoft Windows 7 Home Premium Service Pack 3
System drive C: has 386 GB (83%) free of 462 GB
Total RAM: 3950 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:31:04, on 21. 5. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\InterVideo\DVD5R\SchSvr.exe
C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe
C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Java\jre6\bin\jucheck.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10d.exe
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
C:\Users\Majo\AppData\Local\Temp\is-3R3IP.tmp\pdfforgeToolbar-stub-1.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Majo\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Majo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files (x86)\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files (x86)\InterVideo\DVD5R\SchSvr.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Intel(R) Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15173 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\Partner.dll [2010-02-17 433648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-16 278128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-05-16 814648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-02-17 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-16 278128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-11-21 284696]
"ISBMgr.exe"=C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2009-08-26 320880]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-01-14 98304]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-06-17 538472]
"PMBVolumeWatcher"=C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [2009-10-24 597792]
"MarketingTools"=C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [2010-02-17 26624]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2010-02-17 149280]
"FastTVSync"=C:\Program Files (x86)\Common Files\InterVideo\FastTVSync\FastTVSync.exe [2003-12-26 245760]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-17 39408]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-05-07 26211624]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
InterVideo Scheduler server.lnk - C:\Program Files (x86)\InterVideo\DVD5R\SchSvr.exe
InterVideo WinCinema Manager.lnk - C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
C:\Windows\system32\VESWinlogon.dll [2009-12-02 98304]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f5dca5d-5e9c-11df-b1d0-806e6f6e6963}]
shell\AutoRun\command - E:\winopen.exe index.html
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-05-21 20:26:54 ----D---- C:\rsit
2010-05-21 20:26:54 ----D---- C:\Program Files (x86)\trend micro
2010-05-21 19:22:58 ----A---- C:\Windows\SysWOW64\MSMPIDE.DLL
2010-05-21 19:22:57 ----D---- C:\Program Files (x86)\PDFCreator
2010-05-20 13:01:09 ----D---- C:\Program Files (x86)\IrfanView
2010-05-18 11:30:06 ----D---- C:\Program Files (x86)\YouTube Downloader
2010-05-17 14:56:05 ----D---- C:\Windows\Downloaded Installations
2010-05-16 13:22:03 ----D---- C:\Program Files (x86)\Common Files\Adobe
2010-05-16 13:22:03 ----D---- C:\Program Files (x86)\Adobe
2010-05-16 08:50:40 ----D---- C:\Users\Majo\AppData\Roaming\Win7codecs
2010-05-16 08:50:31 ----D---- C:\Program Files (x86)\Win7codecs
2010-05-16 08:49:44 ----D---- C:\ProgramData\Win7codecs
2010-05-15 22:21:10 ----D---- C:\ProgramData\InterVideo
2010-05-15 22:21:09 ----D---- C:\Users\Majo\AppData\Roaming\InterVideo
2010-05-15 22:20:13 ----D---- C:\Program Files (x86)\Common Files\InterVideo
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeW7.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizePX.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeP6.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeM6.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeA6.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresize.dll
2010-05-15 22:19:32 ----D---- C:\Program Files (x86)\InterVideo
2010-05-15 20:30:50 ----D---- C:\Users\Majo\AppData\Roaming\Vso
2010-05-15 20:30:50 ----A---- C:\Users\Majo\AppData\Roaming\inst.exe
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\vp7vfw.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\sipr3260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\drv43260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\drv33260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\drv23260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\cook3260.dll
2010-05-15 20:30:07 ----A---- C:\Windows\SysWOW64\wvc1dmod.dll
2010-05-15 20:29:58 ----D---- C:\Program Files (x86)\VSO
2010-05-15 07:59:02 ----D---- C:\Program Files (x86)\uTorrent
2010-05-15 07:58:49 ----D---- C:\Users\Majo\AppData\Roaming\uTorrent
2010-05-14 22:11:03 ----A---- C:\Windows\iun6002.exe
2010-05-14 22:11:00 ----D---- C:\Program Files (x86)\Codec Pack - All In 1
2010-05-14 22:10:28 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2010-05-14 21:57:49 ----D---- C:\Users\Majo\AppData\Roaming\skypePM
2010-05-14 21:56:50 ----D---- C:\Users\Majo\AppData\Roaming\Skype
2010-05-14 21:55:34 ----D---- C:\Program Files (x86)\Common Files\Skype
2010-05-14 21:55:32 ----RD---- C:\Program Files (x86)\Skype
2010-05-14 21:55:27 ----D---- C:\ProgramData\Skype
2010-05-14 21:31:22 ----D---- C:\Program Files (x86)\EA SPORTS
2010-05-14 20:19:49 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2010-05-14 20:19:49 ----D---- C:\Program Files (x86)\Common Files\DESIGNER
2010-05-14 20:19:32 ----D---- C:\Windows\PCHEALTH
2010-05-14 20:19:32 ----D---- C:\Program Files (x86)\Microsoft.NET
2010-05-14 20:17:48 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2010-05-14 20:16:44 ----RHD---- C:\MSOCache
2010-05-14 20:10:20 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2010-05-14 20:09:20 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2010-05-14 20:09:08 ----D---- C:\Users\Majo\AppData\Roaming\DAEMON Tools Lite
2010-05-14 20:09:03 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-05-14 20:07:26 ----D---- C:\install
2010-05-14 17:58:10 ----D---- C:\Users\Majo\AppData\Roaming\InstallShield
2010-05-14 17:35:17 ----D---- C:\Update
2010-05-14 15:18:32 ----D---- C:\ProgramData\Roxio
2010-05-14 15:18:31 ----D---- C:\Users\Majo\AppData\Roaming\Roxio
2010-05-14 15:17:34 ----D---- C:\Users\Majo\AppData\Roaming\WinRAR
2010-05-14 12:02:18 ----D---- C:\Program Files (x86)\MSXML 4.0
2010-05-14 11:48:19 ----D---- C:\Program Files (x86)\WinRAR
2010-05-14 11:24:42 ----A---- C:\Windows\SysWOW64\quartz.dll
2010-05-14 11:24:42 ----A---- C:\Windows\SysWOW64\mciavi32.dll
2010-05-14 11:24:41 ----A---- C:\Windows\SysWOW64\msvidc32.dll
2010-05-14 11:24:41 ----A---- C:\Windows\SysWOW64\iyuv_32.dll
2010-05-14 11:24:41 ----A---- C:\Windows\SysWOW64\avifil32.dll
2010-05-14 11:24:40 ----A---- C:\Windows\SysWOW64\tsbyuv.dll
2010-05-14 11:24:40 ----A---- C:\Windows\SysWOW64\msyuv.dll
2010-05-14 11:24:40 ----A---- C:\Windows\SysWOW64\msrle32.dll
2010-05-14 11:23:21 ----A---- C:\Windows\SysWOW64\setup16.exe
2010-05-14 11:23:20 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2010-05-14 11:23:19 ----A---- C:\Windows\SysWOW64\wow32.dll
2010-05-14 11:23:19 ----A---- C:\Windows\SysWOW64\user.exe
2010-05-14 11:23:19 ----A---- C:\Windows\SysWOW64\instnm.exe
2010-05-14 11:23:08 ----A---- C:\Windows\SysWOW64\mshtml.dll
2010-05-14 11:23:05 ----A---- C:\Windows\SysWOW64\ieframe.dll
2010-05-14 11:23:04 ----A---- C:\Windows\SysWOW64\mstime.dll
2010-05-14 11:23:03 ----A---- C:\Windows\SysWOW64\urlmon.dll
2010-05-14 11:23:03 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2010-05-14 11:23:02 ----A---- C:\Windows\SysWOW64\wininet.dll
2010-05-14 11:23:02 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2010-05-14 11:22:32 ----A---- C:\Windows\SysWOW64\tzres.dll
2010-05-14 11:21:58 ----A---- C:\Windows\SysWOW64\vbscript.dll
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\secproc_isv.dll
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\secproc.dll
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\RMActivate_isv.exe
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\RMActivate.exe
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\secproc_ssp_isv.dll
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\secproc_ssp.dll
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\RMActivate_ssp.exe
2010-05-14 11:21:51 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2010-05-14 11:21:50 ----A---- C:\Windows\SysWOW64\explorer.exe
2010-05-14 11:21:50 ----A---- C:\Windows\explorer.exe
2010-05-14 11:19:46 ----A---- C:\Windows\SysWOW64\jscript.dll
2010-05-14 11:19:42 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2010-05-14 11:19:42 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2010-05-14 11:19:35 ----A---- C:\Windows\SysWOW64\shell32.dll
2010-05-14 11:19:34 ----A---- C:\Windows\SysWOW64\sspicli.dll
2010-05-14 11:19:34 ----A---- C:\Windows\SysWOW64\secur32.dll
2010-05-14 11:19:06 ----A---- C:\Windows\SysWOW64\CPFilters.dll
2010-05-14 11:19:05 ----A---- C:\Windows\SysWOW64\psisdecd.dll
2010-05-14 11:16:37 ----D---- C:\ProgramData\ArcSoft
2010-05-14 11:16:36 ----D---- C:\Users\Majo\AppData\Roaming\ArcSoft
2010-05-14 11:02:46 ----D---- C:\Users\Majo\AppData\Roaming\ESET
2010-05-14 11:02:19 ----D---- C:\ProgramData\ESET
2010-05-13 19:26:09 ----A---- C:\Windows\SysWOW64\wintrust.dll
2010-05-13 19:26:09 ----A---- C:\Windows\SysWOW64\cabview.dll
2010-05-13 16:46:45 ----D---- C:\Users\Majo\AppData\Roaming\Macromedia
2010-05-13 16:46:45 ----D---- C:\Users\Majo\AppData\Roaming\Adobe
2010-05-13 16:44:11 ----D---- C:\Users\Majo\AppData\Roaming\Google
2010-05-13 16:42:35 ----D---- C:\Users\Majo\AppData\Roaming\Intel Corporation
2010-05-13 16:42:29 ----D---- C:\Users\Majo\AppData\Roaming\ATI
2010-05-13 16:40:34 ----D---- C:\Users\Majo\AppData\Roaming\Identities
2010-05-13 16:40:05 ----HD---- C:\Windows\msdownld.tmp
2010-05-13 16:38:46 ----D---- C:\Users\Majo\AppData\Roaming\Sony Corporation
2010-05-13 16:38:41 ----SD---- C:\Users\Majo\AppData\Roaming\Microsoft
2010-05-13 16:38:41 ----D---- C:\Users\Majo\AppData\Roaming\Media Center Programs
2010-05-13 16:36:56 ----D---- C:\Windows\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2010-05-21 20:31:03 ----D---- C:\Windows\Temp
2010-05-21 20:28:26 ----D---- C:\Windows\Prefetch
2010-05-21 20:26:54 ----RD---- C:\Program Files (x86)
2010-05-21 19:23:00 ----D---- C:\Windows\SysWOW64
2010-05-21 19:23:00 ----D---- C:\Windows\System32
2010-05-21 15:09:51 ----SHD---- C:\System Volume Information
2010-05-21 15:07:09 ----A---- C:\Windows\SysWOW64\log.txt
2010-05-21 00:05:25 ----HD---- C:\SPLASH.000
2010-05-21 00:04:00 ----HD---- C:\SPLASH.SYS
2010-05-20 19:47:51 ----D---- C:\Windows\inf
2010-05-18 10:53:22 ----D---- C:\Windows\debug
2010-05-17 16:59:42 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-05-17 16:59:16 ----SHD---- C:\Windows\Installer
2010-05-17 16:58:44 ----RSD---- C:\Windows\assembly
2010-05-17 14:56:05 ----D---- C:\Windows
2010-05-16 13:22:05 ----D---- C:\ProgramData\Adobe
2010-05-16 13:22:03 ----D---- C:\Program Files (x86)\Common Files
2010-05-16 11:30:15 ----D---- C:\Windows\rescache
2010-05-16 09:48:37 ----D---- C:\Windows\winsxs
2010-05-16 08:49:44 ----HD---- C:\ProgramData
2010-05-16 00:08:09 ----D---- C:\Program Files (x86)\Windows Sidebar
2010-05-16 00:08:09 ----D---- C:\Program Files (x86)\Windows Mail
2010-05-16 00:08:07 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2010-05-16 00:08:07 ----D---- C:\Program Files (x86)\Windows Media Player
2010-05-16 00:08:07 ----D---- C:\Program Files (x86)\Internet Explorer
2010-05-16 00:08:06 ----D---- C:\Program Files (x86)\Windows Defender
2010-05-16 00:08:06 ----D---- C:\Program Files (x86)\Common Files\System
2010-05-16 00:08:03 ----D---- C:\Windows\servicing
2010-05-16 00:07:58 ----D---- C:\Windows\SysWOW64\winrm
2010-05-16 00:07:58 ----D---- C:\Windows\SysWOW64\tr-TR
2010-05-16 00:07:58 ----D---- C:\Windows\SysWOW64\migwiz
2010-05-16 00:07:58 ----D---- C:\Windows\ehome
2010-05-16 00:07:39 ----D---- C:\Windows\SysWOW64\slmgr
2010-05-16 00:07:39 ----D---- C:\Windows\SysWOW64\migration
2010-05-16 00:07:39 ----D---- C:\Windows\SysWOW64\drivers
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\WCN
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\wbem
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\Printing_Admin_Scripts
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\MUI
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\DriverStore
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\Dism
2010-05-16 00:07:37 ----D---- C:\Windows\SysWOW64\com
2010-05-16 00:07:37 ----D---- C:\Windows\IME
2010-05-16 00:07:03 ----D---- C:\Windows\PolicyDefinitions
2010-05-16 00:07:03 ----D---- C:\Windows\AppPatch
2010-05-16 00:06:28 ----D---- C:\Windows\SysWOW64\sv-SE
2010-05-16 00:04:56 ----D---- C:\Windows\SysWOW64\ro-RO
2010-05-16 00:04:44 ----D---- C:\Windows\SysWOW64\en-US
2010-05-16 00:03:51 ----D---- C:\Windows\SysWOW64\pt-PT
2010-05-16 00:02:08 ----D---- C:\Windows\SysWOW64\pl-PL
2010-05-16 00:00:23 ----D---- C:\Windows\SysWOW64\hu-HU
2010-05-15 23:58:36 ----D---- C:\Windows\SysWOW64\el-GR
2010-05-15 23:56:58 ----D---- C:\Windows\SysWOW64\fi-FI
2010-05-15 23:55:06 ----D---- C:\Windows\SysWOW64\da-DK
2010-05-15 23:53:27 ----D---- C:\Windows\SysWOW64\cs-CZ
2010-05-15 23:51:55 ----D---- C:\Windows\SysWOW64\bg-BG
2010-05-15 23:50:29 ----D---- C:\Windows\en-US
2010-05-15 23:50:08 ----D---- C:\Windows\Speech
2010-05-15 13:12:31 ----RD---- C:\Program Files
2010-05-15 08:52:43 ----D---- C:\Windows\Logs
2010-05-14 21:44:23 ----D---- C:\ProgramData\Sony Corporation
2010-05-14 20:20:47 ----D---- C:\ProgramData\Microsoft Help
2010-05-14 20:20:00 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2010-05-14 20:19:58 ----D---- C:\Program Files (x86)\MSBuild
2010-05-14 20:19:52 ----D---- C:\Program Files (x86)\Microsoft Office
2010-05-14 20:19:47 ----D---- C:\Windows\ShellNew
2010-05-14 20:19:36 ----RSD---- C:\Windows\Fonts
2010-05-14 20:19:32 ----SD---- C:\ProgramData\Microsoft
2010-05-14 20:17:33 ----A---- C:\Windows\win.ini
2010-05-14 17:57:22 ----D---- C:\Program Files (x86)\SONY
2010-05-14 17:57:22 ----D---- C:\Program Files (x86)\Common Files\Sony Shared
2010-05-14 15:18:13 ----D---- C:\ProgramData\Sonic
2010-05-14 14:47:29 ----D---- C:\Windows\Microsoft.NET
2010-05-14 14:35:30 ----D---- C:\Windows\SysWOW64\sk-SK
2010-05-14 10:54:34 ----D---- C:\ProgramData\McAfee
2010-05-14 10:53:17 ----D---- C:\Windows\Tasks
2010-05-13 16:40:31 ----SHD---- C:\$Recycle.Bin
2010-05-13 16:40:10 ----D---- C:\Program Files (x86)\Intel
2010-05-13 16:38:41 ----RD---- C:\Users
2010-05-13 16:37:11 ----D---- C:\Windows\Panther
Mam problem , ze Eset Smart Security mi hlasi problem:
http://download.mybrowserbar.com/vkits/ ... oolbar.msi Win32/Adware.Toolbar.Dealio aplikácia prerušené spojenie - uložený do karantény Infiltrácia bola zachytená pri prístupe na web aplikáciou: C:\Users\Majo\AppData\Local\Temp\is-3R3IP.tmp\pdfforgeToolbar-stub-1.exe.
Takato tabulka sa vyhadzuje opakovane asi po 30ych sekundach....
Prikladam log:
Logfile of random's system information tool 1.07 (written by random/random)
Run by Majo at 2010-05-21 20:30:57
Microsoft Windows 7 Home Premium Service Pack 3
System drive C: has 386 GB (83%) free of 462 GB
Total RAM: 3950 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:31:04, on 21. 5. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\InterVideo\DVD5R\SchSvr.exe
C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe
C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe
C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Sony\VAIO Care\listener.exe
C:\Program Files (x86)\Java\jre6\bin\jucheck.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10d.exe
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
C:\Users\Majo\AppData\Local\Temp\is-3R3IP.tmp\pdfforgeToolbar-stub-1.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Majo\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Majo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
O4 - HKLM\..\Run: [MarketingTools] C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files (x86)\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files (x86)\InterVideo\DVD5R\SchSvr.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Intel(R) Sample Collector (SampleCollector) - Intel Corporation - C:\Program Files\Sony\VAIO Care\collsvc.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata Intelligent Network Service Manager (VcmINSMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15173 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\Partner.dll [2010-02-17 433648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-16 278128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-05-16 814648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-02-17 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-05-16 278128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2009-11-21 284696]
"ISBMgr.exe"=C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2009-08-26 320880]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-01-14 98304]
"NortonOnlineBackupReminder"=C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-06-17 538472]
"PMBVolumeWatcher"=C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [2009-10-24 597792]
"MarketingTools"=C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe [2010-02-17 26624]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre6\bin\jusched.exe [2010-02-17 149280]
"FastTVSync"=C:\Program Files (x86)\Common Files\InterVideo\FastTVSync\FastTVSync.exe [2003-12-26 245760]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-17 39408]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2010-05-07 26211624]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
InterVideo Scheduler server.lnk - C:\Program Files (x86)\InterVideo\DVD5R\SchSvr.exe
InterVideo WinCinema Manager.lnk - C:\Program Files (x86)\InterVideo\Common\Bin\WinCinemaMgr.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\VESWinlogon]
C:\Windows\system32\VESWinlogon.dll [2009-12-02 98304]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f5dca5d-5e9c-11df-b1d0-806e6f6e6963}]
shell\AutoRun\command - E:\winopen.exe index.html
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-05-21 20:26:54 ----D---- C:\rsit
2010-05-21 20:26:54 ----D---- C:\Program Files (x86)\trend micro
2010-05-21 19:22:58 ----A---- C:\Windows\SysWOW64\MSMPIDE.DLL
2010-05-21 19:22:57 ----D---- C:\Program Files (x86)\PDFCreator
2010-05-20 13:01:09 ----D---- C:\Program Files (x86)\IrfanView
2010-05-18 11:30:06 ----D---- C:\Program Files (x86)\YouTube Downloader
2010-05-17 14:56:05 ----D---- C:\Windows\Downloaded Installations
2010-05-16 13:22:03 ----D---- C:\Program Files (x86)\Common Files\Adobe
2010-05-16 13:22:03 ----D---- C:\Program Files (x86)\Adobe
2010-05-16 08:50:40 ----D---- C:\Users\Majo\AppData\Roaming\Win7codecs
2010-05-16 08:50:31 ----D---- C:\Program Files (x86)\Win7codecs
2010-05-16 08:49:44 ----D---- C:\ProgramData\Win7codecs
2010-05-15 22:21:10 ----D---- C:\ProgramData\InterVideo
2010-05-15 22:21:09 ----D---- C:\Users\Majo\AppData\Roaming\InterVideo
2010-05-15 22:20:13 ----D---- C:\Program Files (x86)\Common Files\InterVideo
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeW7.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizePX.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeP6.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeM6.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresizeA6.dll
2010-05-15 22:19:35 ----A---- C:\Windows\SysWOW64\IVIresize.dll
2010-05-15 22:19:32 ----D---- C:\Program Files (x86)\InterVideo
2010-05-15 20:30:50 ----D---- C:\Users\Majo\AppData\Roaming\Vso
2010-05-15 20:30:50 ----A---- C:\Users\Majo\AppData\Roaming\inst.exe
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\vp7vfw.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\sipr3260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\drv43260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\drv33260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\drv23260.dll
2010-05-15 20:30:08 ----A---- C:\Windows\SysWOW64\cook3260.dll
2010-05-15 20:30:07 ----A---- C:\Windows\SysWOW64\wvc1dmod.dll
2010-05-15 20:29:58 ----D---- C:\Program Files (x86)\VSO
2010-05-15 07:59:02 ----D---- C:\Program Files (x86)\uTorrent
2010-05-15 07:58:49 ----D---- C:\Users\Majo\AppData\Roaming\uTorrent
2010-05-14 22:11:03 ----A---- C:\Windows\iun6002.exe
2010-05-14 22:11:00 ----D---- C:\Program Files (x86)\Codec Pack - All In 1
2010-05-14 22:10:28 ----A---- C:\Windows\Codec Pack - All In 1 Setup Log.txt
2010-05-14 21:57:49 ----D---- C:\Users\Majo\AppData\Roaming\skypePM
2010-05-14 21:56:50 ----D---- C:\Users\Majo\AppData\Roaming\Skype
2010-05-14 21:55:34 ----D---- C:\Program Files (x86)\Common Files\Skype
2010-05-14 21:55:32 ----RD---- C:\Program Files (x86)\Skype
2010-05-14 21:55:27 ----D---- C:\ProgramData\Skype
2010-05-14 21:31:22 ----D---- C:\Program Files (x86)\EA SPORTS
2010-05-14 20:19:49 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2010-05-14 20:19:49 ----D---- C:\Program Files (x86)\Common Files\DESIGNER
2010-05-14 20:19:32 ----D---- C:\Windows\PCHEALTH
2010-05-14 20:19:32 ----D---- C:\Program Files (x86)\Microsoft.NET
2010-05-14 20:17:48 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2010-05-14 20:16:44 ----RHD---- C:\MSOCache
2010-05-14 20:10:20 ----D---- C:\Program Files (x86)\DAEMON Tools Toolbar
2010-05-14 20:09:20 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2010-05-14 20:09:08 ----D---- C:\Users\Majo\AppData\Roaming\DAEMON Tools Lite
2010-05-14 20:09:03 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-05-14 20:07:26 ----D---- C:\install
2010-05-14 17:58:10 ----D---- C:\Users\Majo\AppData\Roaming\InstallShield
2010-05-14 17:35:17 ----D---- C:\Update
2010-05-14 15:18:32 ----D---- C:\ProgramData\Roxio
2010-05-14 15:18:31 ----D---- C:\Users\Majo\AppData\Roaming\Roxio
2010-05-14 15:17:34 ----D---- C:\Users\Majo\AppData\Roaming\WinRAR
2010-05-14 12:02:18 ----D---- C:\Program Files (x86)\MSXML 4.0
2010-05-14 11:48:19 ----D---- C:\Program Files (x86)\WinRAR
2010-05-14 11:24:42 ----A---- C:\Windows\SysWOW64\quartz.dll
2010-05-14 11:24:42 ----A---- C:\Windows\SysWOW64\mciavi32.dll
2010-05-14 11:24:41 ----A---- C:\Windows\SysWOW64\msvidc32.dll
2010-05-14 11:24:41 ----A---- C:\Windows\SysWOW64\iyuv_32.dll
2010-05-14 11:24:41 ----A---- C:\Windows\SysWOW64\avifil32.dll
2010-05-14 11:24:40 ----A---- C:\Windows\SysWOW64\tsbyuv.dll
2010-05-14 11:24:40 ----A---- C:\Windows\SysWOW64\msyuv.dll
2010-05-14 11:24:40 ----A---- C:\Windows\SysWOW64\msrle32.dll
2010-05-14 11:23:21 ----A---- C:\Windows\SysWOW64\setup16.exe
2010-05-14 11:23:20 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2010-05-14 11:23:19 ----A---- C:\Windows\SysWOW64\wow32.dll
2010-05-14 11:23:19 ----A---- C:\Windows\SysWOW64\user.exe
2010-05-14 11:23:19 ----A---- C:\Windows\SysWOW64\instnm.exe
2010-05-14 11:23:08 ----A---- C:\Windows\SysWOW64\mshtml.dll
2010-05-14 11:23:05 ----A---- C:\Windows\SysWOW64\ieframe.dll
2010-05-14 11:23:04 ----A---- C:\Windows\SysWOW64\mstime.dll
2010-05-14 11:23:03 ----A---- C:\Windows\SysWOW64\urlmon.dll
2010-05-14 11:23:03 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2010-05-14 11:23:02 ----A---- C:\Windows\SysWOW64\wininet.dll
2010-05-14 11:23:02 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2010-05-14 11:22:32 ----A---- C:\Windows\SysWOW64\tzres.dll
2010-05-14 11:21:58 ----A---- C:\Windows\SysWOW64\vbscript.dll
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\secproc_isv.dll
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\secproc.dll
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\RMActivate_isv.exe
2010-05-14 11:21:55 ----A---- C:\Windows\SysWOW64\RMActivate.exe
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\secproc_ssp_isv.dll
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\secproc_ssp.dll
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2010-05-14 11:21:54 ----A---- C:\Windows\SysWOW64\RMActivate_ssp.exe
2010-05-14 11:21:51 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2010-05-14 11:21:50 ----A---- C:\Windows\SysWOW64\explorer.exe
2010-05-14 11:21:50 ----A---- C:\Windows\explorer.exe
2010-05-14 11:19:46 ----A---- C:\Windows\SysWOW64\jscript.dll
2010-05-14 11:19:42 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2010-05-14 11:19:42 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2010-05-14 11:19:35 ----A---- C:\Windows\SysWOW64\shell32.dll
2010-05-14 11:19:34 ----A---- C:\Windows\SysWOW64\sspicli.dll
2010-05-14 11:19:34 ----A---- C:\Windows\SysWOW64\secur32.dll
2010-05-14 11:19:06 ----A---- C:\Windows\SysWOW64\CPFilters.dll
2010-05-14 11:19:05 ----A---- C:\Windows\SysWOW64\psisdecd.dll
2010-05-14 11:16:37 ----D---- C:\ProgramData\ArcSoft
2010-05-14 11:16:36 ----D---- C:\Users\Majo\AppData\Roaming\ArcSoft
2010-05-14 11:02:46 ----D---- C:\Users\Majo\AppData\Roaming\ESET
2010-05-14 11:02:19 ----D---- C:\ProgramData\ESET
2010-05-13 19:26:09 ----A---- C:\Windows\SysWOW64\wintrust.dll
2010-05-13 19:26:09 ----A---- C:\Windows\SysWOW64\cabview.dll
2010-05-13 16:46:45 ----D---- C:\Users\Majo\AppData\Roaming\Macromedia
2010-05-13 16:46:45 ----D---- C:\Users\Majo\AppData\Roaming\Adobe
2010-05-13 16:44:11 ----D---- C:\Users\Majo\AppData\Roaming\Google
2010-05-13 16:42:35 ----D---- C:\Users\Majo\AppData\Roaming\Intel Corporation
2010-05-13 16:42:29 ----D---- C:\Users\Majo\AppData\Roaming\ATI
2010-05-13 16:40:34 ----D---- C:\Users\Majo\AppData\Roaming\Identities
2010-05-13 16:40:05 ----HD---- C:\Windows\msdownld.tmp
2010-05-13 16:38:46 ----D---- C:\Users\Majo\AppData\Roaming\Sony Corporation
2010-05-13 16:38:41 ----SD---- C:\Users\Majo\AppData\Roaming\Microsoft
2010-05-13 16:38:41 ----D---- C:\Users\Majo\AppData\Roaming\Media Center Programs
2010-05-13 16:36:56 ----D---- C:\Windows\SoftwareDistribution
======List of files/folders modified in the last 1 months======
2010-05-21 20:31:03 ----D---- C:\Windows\Temp
2010-05-21 20:28:26 ----D---- C:\Windows\Prefetch
2010-05-21 20:26:54 ----RD---- C:\Program Files (x86)
2010-05-21 19:23:00 ----D---- C:\Windows\SysWOW64
2010-05-21 19:23:00 ----D---- C:\Windows\System32
2010-05-21 15:09:51 ----SHD---- C:\System Volume Information
2010-05-21 15:07:09 ----A---- C:\Windows\SysWOW64\log.txt
2010-05-21 00:05:25 ----HD---- C:\SPLASH.000
2010-05-21 00:04:00 ----HD---- C:\SPLASH.SYS
2010-05-20 19:47:51 ----D---- C:\Windows\inf
2010-05-18 10:53:22 ----D---- C:\Windows\debug
2010-05-17 16:59:42 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2010-05-17 16:59:16 ----SHD---- C:\Windows\Installer
2010-05-17 16:58:44 ----RSD---- C:\Windows\assembly
2010-05-17 14:56:05 ----D---- C:\Windows
2010-05-16 13:22:05 ----D---- C:\ProgramData\Adobe
2010-05-16 13:22:03 ----D---- C:\Program Files (x86)\Common Files
2010-05-16 11:30:15 ----D---- C:\Windows\rescache
2010-05-16 09:48:37 ----D---- C:\Windows\winsxs
2010-05-16 08:49:44 ----HD---- C:\ProgramData
2010-05-16 00:08:09 ----D---- C:\Program Files (x86)\Windows Sidebar
2010-05-16 00:08:09 ----D---- C:\Program Files (x86)\Windows Mail
2010-05-16 00:08:07 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2010-05-16 00:08:07 ----D---- C:\Program Files (x86)\Windows Media Player
2010-05-16 00:08:07 ----D---- C:\Program Files (x86)\Internet Explorer
2010-05-16 00:08:06 ----D---- C:\Program Files (x86)\Windows Defender
2010-05-16 00:08:06 ----D---- C:\Program Files (x86)\Common Files\System
2010-05-16 00:08:03 ----D---- C:\Windows\servicing
2010-05-16 00:07:58 ----D---- C:\Windows\SysWOW64\winrm
2010-05-16 00:07:58 ----D---- C:\Windows\SysWOW64\tr-TR
2010-05-16 00:07:58 ----D---- C:\Windows\SysWOW64\migwiz
2010-05-16 00:07:58 ----D---- C:\Windows\ehome
2010-05-16 00:07:39 ----D---- C:\Windows\SysWOW64\slmgr
2010-05-16 00:07:39 ----D---- C:\Windows\SysWOW64\migration
2010-05-16 00:07:39 ----D---- C:\Windows\SysWOW64\drivers
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\WCN
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\wbem
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\Printing_Admin_Scripts
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\MUI
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\DriverStore
2010-05-16 00:07:38 ----D---- C:\Windows\SysWOW64\Dism
2010-05-16 00:07:37 ----D---- C:\Windows\SysWOW64\com
2010-05-16 00:07:37 ----D---- C:\Windows\IME
2010-05-16 00:07:03 ----D---- C:\Windows\PolicyDefinitions
2010-05-16 00:07:03 ----D---- C:\Windows\AppPatch
2010-05-16 00:06:28 ----D---- C:\Windows\SysWOW64\sv-SE
2010-05-16 00:04:56 ----D---- C:\Windows\SysWOW64\ro-RO
2010-05-16 00:04:44 ----D---- C:\Windows\SysWOW64\en-US
2010-05-16 00:03:51 ----D---- C:\Windows\SysWOW64\pt-PT
2010-05-16 00:02:08 ----D---- C:\Windows\SysWOW64\pl-PL
2010-05-16 00:00:23 ----D---- C:\Windows\SysWOW64\hu-HU
2010-05-15 23:58:36 ----D---- C:\Windows\SysWOW64\el-GR
2010-05-15 23:56:58 ----D---- C:\Windows\SysWOW64\fi-FI
2010-05-15 23:55:06 ----D---- C:\Windows\SysWOW64\da-DK
2010-05-15 23:53:27 ----D---- C:\Windows\SysWOW64\cs-CZ
2010-05-15 23:51:55 ----D---- C:\Windows\SysWOW64\bg-BG
2010-05-15 23:50:29 ----D---- C:\Windows\en-US
2010-05-15 23:50:08 ----D---- C:\Windows\Speech
2010-05-15 13:12:31 ----RD---- C:\Program Files
2010-05-15 08:52:43 ----D---- C:\Windows\Logs
2010-05-14 21:44:23 ----D---- C:\ProgramData\Sony Corporation
2010-05-14 20:20:47 ----D---- C:\ProgramData\Microsoft Help
2010-05-14 20:20:00 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2010-05-14 20:19:58 ----D---- C:\Program Files (x86)\MSBuild
2010-05-14 20:19:52 ----D---- C:\Program Files (x86)\Microsoft Office
2010-05-14 20:19:47 ----D---- C:\Windows\ShellNew
2010-05-14 20:19:36 ----RSD---- C:\Windows\Fonts
2010-05-14 20:19:32 ----SD---- C:\ProgramData\Microsoft
2010-05-14 20:17:33 ----A---- C:\Windows\win.ini
2010-05-14 17:57:22 ----D---- C:\Program Files (x86)\SONY
2010-05-14 17:57:22 ----D---- C:\Program Files (x86)\Common Files\Sony Shared
2010-05-14 15:18:13 ----D---- C:\ProgramData\Sonic
2010-05-14 14:47:29 ----D---- C:\Windows\Microsoft.NET
2010-05-14 14:35:30 ----D---- C:\Windows\SysWOW64\sk-SK
2010-05-14 10:54:34 ----D---- C:\ProgramData\McAfee
2010-05-14 10:53:17 ----D---- C:\Windows\Tasks
2010-05-13 16:40:31 ----SHD---- C:\$Recycle.Bin
2010-05-13 16:40:10 ----D---- C:\Program Files (x86)\Intel
2010-05-13 16:38:41 ----RD---- C:\Users
2010-05-13 16:37:11 ----D---- C:\Windows\Panther