Logfile of random's system information tool 1.08 (written by random/random)
Run by Pase at 2000-12-31 23:31:00
Microsoft Windows 7 Home Premium
System drive C: has 132 GB (45%) free of 291 GB
Total RAM: 4092 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:31:12, on 31.12.2000
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Pase\AppData\Roaming\QipGuard\QipGuard.exe
C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files\trend micro\Pase.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.acer.com/rdr.aspx?b=ACA ... 5t4862v722
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.acer.com/rdr.aspx?b=ACA ... 5t4862v722
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Pase\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Alawar.com Toolbar - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - C:\Program Files (x86)\Alawar.com\tbAlaw.dll
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Alawar.com Toolbar - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - C:\Program Files (x86)\Alawar.com\tbAlaw.dll
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Users\Pase\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll
O2 - BHO: Pomocník pro pøihlášení ke službì Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Pase\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Alawar.com Toolbar - {511131f1-4629-4254-a85f-ed7b6d75dd3c} - C:\Program Files (x86)\Alawar.com\tbAlaw.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files (x86)\free-downloads.net\tbfree.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpyEmergency] C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\Pase\AppData\Roaming\QipGuard\QipGuard.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_Plugin.exe -update plugin
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáøe Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Pøidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Pøidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files (x86)\QIP\qip.exe (HKCU)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13617 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Essentials\MsMpEng.exe"
winlogon.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe"
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe"
"C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe"
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Explorer.EXE
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe"
"C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\PLFSetI.exe"
"C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"C:\Users\Pase\AppData\Roaming\QipGuard\QipGuard.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
"C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
"C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Users\Pase\AppData\Local\Opera\Opera\temporary_downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\Norton Security Scan for Pase.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-07-25 371888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll [2010-09-17 317496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{511131f1-4629-4254-a85f-ed7b6d75dd3c}]
Alawar.com Toolbar - C:\Program Files (x86)\Alawar.com\tbAlaw.dll [2008-09-15 1784856]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\Pase\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-04-12 45568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro pøihlášení ke službì Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Pase\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-04-12 149968]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-25 278192]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-09-17 842296]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
free-downloads.net Toolbar - C:\Program Files (x86)\free-downloads.net\tbfree.dll [2009-12-31 2349080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2010-03-25 1548096]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2010-07-25 371888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-25 278192]
{511131f1-4629-4254-a85f-ed7b6d75dd3c} - Alawar.com Toolbar - C:\Program Files (x86)\Alawar.com\tbAlaw.dll [2008-09-15 1784856]
{ecdee021-0d17-467f-a1ff-c7a115230949} - free-downloads.net Toolbar - C:\Program Files (x86)\free-downloads.net\tbfree.dll [2009-12-31 2349080]
{D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-06 7940128]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2009-09-30 823840]
"mwlDaemon"=C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-09-10 349480]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-06-18 1808168]
"PLFSetI"=C:\Windows\PLFSetI.exe [2010-06-24 200704]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-06-01 1446504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-10-16 39408]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2010-09-25 328056]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"SpyEmergency"=C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe []
"AlcoholAutomount"=C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
"QIP Internet Guardian"=C:\Users\Pase\AppData\Roaming\QipGuard\QipGuard.exe [2010-04-12 181760]
"EA Core"=C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_Plugin.exe [2010-07-11 231888]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"EgisTecLiveUpdate"=C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04 199464]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
"BackupManagerTray"=C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-09-24 261888]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-08-05 98304]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-09-01 1157128]
"ArcadeDeluxeAgent"=C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [2009-10-29 419112]
"PlayMovie"=C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [2009-10-22 181480]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe []
"PWRISOVM.EXE"=C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [2010-04-12 180224]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Microsoft Office.lnk - C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-09-27 12:56:52 ----D---- C:\Program Files (x86)\PowerISO
2010-09-27 12:56:52 ----A---- C:\Windows\system32\drivers\scdemu.sys
2010-09-24 07:18:05 ----A---- C:\Windows\system32\MRT.exe
2010-09-23 15:51:21 ----D---- C:\ProgramData\NtiDvdCopy
2010-09-23 15:39:56 ----D---- C:\Users\Pase\AppData\Roaming\Nero
2010-09-23 15:38:53 ----D---- C:\ProgramData\Nero
2010-09-17 17:05:43 ----D---- C:\PFiles
2010-09-15 17:27:10 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2010-09-15 17:27:08 ----A---- C:\Windows\system32\iertutil.dll
2010-09-15 15:32:30 ----A---- C:\Windows\system32\spoolsv.exe
2010-09-05 17:55:54 ----SHD---- C:\Windows\ftpcache
2010-09-05 15:24:25 ----RHD---- C:\Users\Pase\AppData\Roaming\SecuROM
2010-09-05 15:22:32 ----D---- C:\Users\Pase\AppData\Roaming\Leadertech
2010-09-05 15:13:36 ----D---- C:\Program Files (x86)\EA Games
2010-09-05 15:13:33 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2010-09-05 15:13:33 ----A---- C:\Windows\system32\XAudio2_0.dll
2010-09-05 15:13:32 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2010-09-05 15:13:32 ----A---- C:\Windows\system32\xactengine3_0.dll
2010-09-05 15:13:31 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2010-09-05 15:13:31 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2010-09-05 15:13:30 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2010-09-05 15:13:30 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2010-09-05 15:13:30 ----A---- C:\Windows\system32\d3dx10_37.dll
2010-09-05 15:13:30 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2010-09-05 15:13:29 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2010-09-05 15:13:29 ----A---- C:\Windows\system32\D3DX9_37.dll
2010-09-05 15:13:27 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2010-09-05 15:13:27 ----A---- C:\Windows\system32\xactengine2_10.dll
2010-09-05 15:13:25 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2010-09-05 15:13:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2010-09-05 15:13:25 ----A---- C:\Windows\system32\d3dx10_36.dll
2010-09-05 15:13:25 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2010-09-05 15:13:24 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2010-09-05 15:13:24 ----A---- C:\Windows\system32\d3dx9_36.dll
2010-09-05 15:13:22 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2010-09-05 15:13:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2010-09-05 15:13:21 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2010-09-05 15:13:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2010-09-05 15:13:21 ----A---- C:\Windows\system32\d3dx10_35.dll
2010-09-05 15:13:21 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2010-09-05 15:13:19 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2010-09-05 15:13:19 ----A---- C:\Windows\system32\d3dx9_35.dll
2010-09-05 15:13:18 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2010-09-05 15:13:18 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2010-09-05 13:09:54 ----A---- C:\Windows\SYSWOW64\CmdLineExt_x64.dll
2010-08-26 18:12:11 ----D---- C:\Program Files (x86)\Microsoft Antimalware
2010-08-26 18:12:04 ----D---- C:\Program Files\Microsoft Security Essentials
2010-08-26 14:51:21 ----D---- C:\Users\Pase\AppData\Roaming\Microsoft Games
2010-08-26 14:51:21 ----D---- C:\ProgramData\Microsoft Games
2010-08-26 11:53:05 ----D---- C:\Program Files (x86)\sixteen tons entertainment
2010-08-25 09:52:56 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2010-08-25 09:52:56 ----A---- C:\Windows\system32\oleaut32.dll
2010-08-14 14:43:37 ----D---- C:\Program Files\DivX
2010-08-14 14:43:10 ----D---- C:\Program Files (x86)\DivX
2010-08-13 20:39:00 ----D---- C:\Users\Pase\AppData\Roaming\COWON
2010-08-13 20:38:08 ----D---- C:\Program Files (x86)\JetAudio
2010-08-13 20:37:36 ----D---- C:\Users\Pase\AppData\Roaming\InstallShield
2010-08-12 19:10:02 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-08-12 19:10:02 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-12 19:10:02 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-12 19:10:01 ----A---- C:\Windows\SYSWOW64\schannel.dll
2010-08-12 19:10:01 ----A---- C:\Windows\system32\schannel.dll
2010-08-12 19:09:54 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-12 19:09:53 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-12 19:09:52 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2010-08-12 19:09:52 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2010-08-12 19:09:50 ----A---- C:\Windows\system32\mshtml.dll
2010-08-12 19:09:48 ----A---- C:\Windows\system32\ieframe.dll
2010-08-12 19:09:47 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2010-08-12 19:09:46 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2010-08-12 19:09:45 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2010-08-12 19:09:45 ----A---- C:\Windows\system32\wininet.dll
2010-08-12 19:09:45 ----A---- C:\Windows\system32\urlmon.dll
2010-08-12 19:09:44 ----A---- C:\Windows\SYSWOW64\wininet.dll
2010-08-12 19:09:44 ----A---- C:\Windows\SYSWOW64\mstime.dll
2010-08-12 19:09:44 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2010-08-12 19:09:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2010-08-12 19:09:44 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2010-08-12 19:09:44 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2010-08-12 19:09:44 ----A---- C:\Windows\system32\mstime.dll
2010-08-12 19:09:44 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-08-12 19:09:44 ----A---- C:\Windows\system32\ieui.dll
2010-08-12 19:09:44 ----A---- C:\Windows\system32\iepeers.dll
2010-08-12 19:09:44 ----A---- C:\Windows\system32\iedkcs32.dll
2010-08-12 19:09:43 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2010-08-12 19:09:43 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2010-08-12 19:09:43 ----A---- C:\Windows\system32\msfeedssync.exe
2010-08-12 19:09:43 ----A---- C:\Windows\system32\jsproxy.dll
2010-08-12 19:09:39 ----A---- C:\Windows\SYSWOW64\rtutils.dll
2010-08-12 19:09:39 ----A---- C:\Windows\SYSWOW64\iccvid.dll
2010-08-12 19:09:39 ----A---- C:\Windows\system32\rtutils.dll
2010-08-12 19:09:36 ----A---- C:\Windows\system32\win32k.sys
2010-08-12 19:09:35 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2010-08-12 19:09:35 ----A---- C:\Windows\system32\msxml3.dll
2010-08-10 10:02:20 ----D---- C:\Users\Pase\AppData\Roaming\QipGuard
2010-08-10 10:02:16 ----D---- C:\Program Files (x86)\QIP
2010-08-08 19:49:59 ----D---- C:\Users\Pase\AppData\Roaming\skypePM
2010-08-08 19:45:01 ----D---- C:\Users\Pase\AppData\Roaming\Skype
2010-08-08 19:44:38 ----RD---- C:\Program Files (x86)\Skype
2010-08-08 19:44:31 ----D---- C:\ProgramData\Skype
2010-08-06 15:51:33 ----D---- C:\usr
2010-08-06 15:36:00 ----D---- C:\Program Files (x86)\free-downloads.net
2010-08-06 15:35:46 ----D---- C:\Program Files (x86)\Alcohol Soft
2010-08-03 09:04:48 ----A---- C:\Windows\system32\shell32.dll
2010-08-03 09:04:46 ----A---- C:\Windows\SYSWOW64\shell32.dll
2010-08-01 13:49:23 ----D---- C:\Users\Pase\AppData\Roaming\FarmingSimulator2008
2010-08-01 13:43:30 ----A---- C:\Windows\SYSWOW64\dxtmeta2.dll
2010-07-31 11:39:32 ----D---- C:\ProgramData\FarmFrenzy3
2010-07-29 20:32:01 ----D---- C:\Program Files (x86)\Conduit
2010-07-29 20:32:00 ----D---- C:\Program Files (x86)\Alawar.com
2010-07-29 20:31:55 ----D---- C:\ProgramData\AlawarGameBox
2010-07-29 20:29:08 ----D---- C:\ProgramData\AlawarWrapper
2010-07-29 20:28:32 ----D---- C:\Program Files (x86)\Alawar
2010-07-22 07:48:51 ----D---- C:\ProgramData\FarmFrenzy2
2010-07-21 19:55:41 ----D---- C:\ProgramData\Arcade Lab
2010-07-14 15:16:47 ----N---- C:\Windows\system32\MpSigStub.exe
2010-07-14 11:33:00 ----A---- C:\Windows\system32\cdd.dll
2010-07-13 16:18:21 ----D---- C:\Program Files (x86)\Cultures
2010-07-13 16:18:16 ----A---- C:\Windows\IsUninst.exe
2010-07-13 16:12:52 ----A---- C:\Windows\level.ini
2010-07-12 23:24:42 ----D---- C:\ProgramData\Electronic Arts
2010-07-12 23:23:10 ----D---- C:\Program Files (x86)\Microsoft WSE
2010-07-11 19:11:14 ----D---- C:\Windows\system32\drivers\NSSx64
2010-07-11 19:11:14 ----D---- C:\ProgramData\Norton
2010-07-11 19:11:14 ----D---- C:\Program Files (x86)\Norton Security Scan
2010-07-11 19:11:10 ----D---- C:\ProgramData\NortonInstaller
2010-07-11 19:11:10 ----D---- C:\Program Files (x86)\NortonInstaller
2010-07-11 15:36:21 ----D---- C:\Program Files (x86)\Snapshot Viewer
2010-07-11 15:29:52 ----A---- C:\Windows\ODBC.INI
2010-07-11 15:27:46 ----D---- C:\Windows\Msagent
2010-07-11 15:25:41 ----D---- C:\Users\Pase\AppData\Roaming\Microsoft Web Folders
2010-07-11 15:16:04 ----D---- C:\Windows\SYSWOW64\Adobe
2010-07-04 23:01:35 ----D---- C:\Program Files (x86)\Electronic Arts
2010-07-04 09:38:08 ----D---- C:\Program Files (x86)\Acclaim
2010-07-04 09:14:12 ----D---- C:\Users\Pase\AppData\Roaming\Zoner