Ahoj, nalezen rootkit, prosím o pomoc...
Napsal: 28 čer 2012 12:21
Ahoj, mám nový netbook asi 3 dny a instaluji AVG, Terminator, Openoffice atd. a s něčím se mi dostal do počítače i rootkit. AVG ho najde,ale neodstraní. Koupil jsem dva stejné přístroje a instaluji stejné věci a oba mají stejný problém.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Datart at 2012-06-28 13:14:03
Microsoft Windows 7 Starter Service Pack 1
System drive C: has 257 GB (89%) free of 288 GB
Total RAM: 1012 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:14:52, on 28.6.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
C:\Program Files\EgisTec IPS\PmmUpdate.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Launch Manager\LMworker.exe
C:\Program Files\Acer\Android Manager\iSync.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Program Files\Acer\Updater\iUpdate.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Compcare\ikonka.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Datart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JVD6SL9A\RSIT.exe
C:\Program Files\trend micro\Datart.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [iSyncData] C:\Program Files\Acer\Android Manager\iSync.exe
O4 - HKLM\..\Run: [AndroidManager] C:\Program Files\Acer\Android Manager\AML.exe
O4 - HKLM\..\Run: [iPatchData] C:\Program Files\Acer\Updater\iUpdate.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O4 - Startup: Ikonka.lnk = C:\Program Files\Compcare\ikonka.exe
O4 - Global Startup: Acer VCM.lnk = ?
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: McAfee Application Installer Cleanup (0294881340569512) (0294881340569512mcinstcleanup) - Unknown owner - C:\Users\Datart\AppData\Local\Temp\029488~1.EXE (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files\Spyware Terminator\st_rsser.exe
O23 - Service: vToolbarUpdater11.1.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
--
End of file - 9821 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-16 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2011-11-11 1378144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-06-25 329480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll [2012-06-26 2068536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-06-25 59144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll [2012-06-26 2068536]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2011-02-11 10025576]
"SuiteTray"=C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [2011-04-02 340848]
"EgisTecPMMUpdate"=C:\Program Files\EgisTec IPS\PmmUpdate.exe [2011-03-29 408432]
"EgisUpdate"=C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29 202608]
"Norton Online Backup"=C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe [2010-06-02 966488]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-01-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-01-11 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-01-11 150552]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2011-07-01 1103440]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-10-08 1934632]
"Power Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2011-05-10 715368]
"iSyncData"=C:\Program Files\Acer\Android Manager\iSync.exe [2011-05-10 408128]
"AndroidManager"=C:\Program Files\Acer\Android Manager\AML.exe [2011-05-10 508992]
"iPatchData"=C:\Program Files\Acer\Updater\iUpdate.exe [2011-05-10 492096]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2012-01-24 2416480]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-06-26 1104440]
"SpywareTerminatorShield"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2012-06-21 2786512]
"SpywareTerminatorUpdater"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2012-06-21 3669712]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Users\Datart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Ikonka.lnk - C:\Program Files\Compcare\ikonka.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-10-24 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-06-28 13:14:05 ----D---- C:\Program Files\trend micro
2012-06-28 13:14:02 ----D---- C:\rsit
2012-06-28 09:34:34 ----D---- C:\Users\Datart\AppData\Roaming\vlc
2012-06-28 09:30:43 ----D---- C:\Program Files\VideoLAN
2012-06-25 20:13:15 ----D---- C:\Program Files\Common Files\DESIGNER
2012-06-25 20:13:07 ----D---- C:\Program Files\Microsoft Application Virtualization Client
2012-06-25 20:12:32 ----D---- C:\Users\Datart\AppData\Roaming\TP
2012-06-25 16:49:50 ----D---- C:\Program Files\Common Files\Java
2012-06-25 16:47:52 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-06-25 16:47:52 ----A---- C:\Windows\system32\javaws.exe
2012-06-25 16:47:51 ----A---- C:\Windows\system32\javaw.exe
2012-06-25 16:47:51 ----A---- C:\Windows\system32\java.exe
2012-06-25 16:47:08 ----D---- C:\Program Files\Java
2012-06-25 16:34:25 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-06-24 23:50:25 ----A---- C:\Windows\system32\mshtmled.dll
2012-06-24 23:50:24 ----A---- C:\Windows\system32\iertutil.dll
2012-06-24 23:50:21 ----A---- C:\Windows\system32\ieui.dll
2012-06-24 23:50:20 ----A---- C:\Windows\system32\ieUnatt.exe
2012-06-24 23:50:16 ----A---- C:\Windows\system32\jsproxy.dll
2012-06-24 23:50:15 ----A---- C:\Windows\system32\wininet.dll
2012-06-24 23:50:13 ----A---- C:\Windows\system32\jscript.dll
2012-06-24 23:50:10 ----A---- C:\Windows\system32\jscript9.dll
2012-06-24 23:50:09 ----A---- C:\Windows\system32\url.dll
2012-06-24 23:50:05 ----A---- C:\Windows\system32\urlmon.dll
2012-06-24 23:49:58 ----A---- C:\Windows\system32\mshtml.dll
2012-06-24 23:49:56 ----A---- C:\Windows\system32\ieframe.dll
2012-06-24 23:34:27 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-06-24 23:34:25 ----A---- C:\Windows\system32\wmi.dll
2012-06-24 23:34:25 ----A---- C:\Windows\system32\wintrust.dll
2012-06-24 23:34:24 ----A---- C:\Windows\system32\imagehlp.dll
2012-06-24 23:02:53 ----D---- C:\ProgramData\CyberLink
2012-06-24 23:02:52 ----D---- C:\Users\Datart\AppData\Roaming\CyberLink
2012-06-24 22:45:50 ----D---- C:\Users\Datart\AppData\Roaming\AVG
2012-06-24 22:42:18 ----N---- C:\Windows\system32\MpSigStub.exe
2012-06-24 21:58:38 ----D---- C:\Users\Datart\AppData\Roaming\ICQ
2012-06-24 21:57:30 ----D---- C:\Program Files\ICQ7M
2012-06-24 21:46:55 ----A---- C:\Windows\system32\drivers\sp_rsdrv2.sys
2012-06-24 21:46:51 ----D---- C:\Users\Datart\AppData\Roaming\Spyware Terminator
2012-06-24 21:46:51 ----D---- C:\ProgramData\Spyware Terminator
2012-06-24 21:43:45 ----D---- C:\Program Files\Spyware Terminator
2012-06-24 21:25:38 ----D---- C:\Users\Datart\AppData\Roaming\AVG2012
2012-06-24 21:22:34 ----D---- C:\ProgramData\AVG Secure Search
2012-06-24 21:22:29 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-06-24 21:22:26 ----D---- C:\Program Files\AVG Secure Search
2012-06-24 21:20:55 ----D---- C:\Windows\system32\drivers\AVG
2012-06-24 21:20:55 ----D---- C:\ProgramData\AVG2012
2012-06-24 21:19:40 ----D---- C:\Program Files\AVG
2012-06-24 21:15:36 ----HD---- C:\ProgramData\Common Files
2012-06-24 21:15:07 ----D---- C:\ProgramData\MFAData
2012-06-24 21:07:19 ----D---- C:\Users\Datart\AppData\Roaming\OpenOffice.org
2012-06-24 21:03:19 ----D---- C:\Program Files\OpenOffice.org 3
2012-06-24 19:53:00 ----D---- C:\Users\Datart\AppData\Roaming\WildTangent
2012-06-24 19:27:57 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-24 19:27:47 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-06-24 19:27:21 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-06-24 19:27:20 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-24 19:27:01 ----A---- C:\Windows\system32\msi.dll
2012-06-24 19:26:57 ----A---- C:\Windows\system32\win32k.sys
2012-06-24 19:26:53 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-24 19:26:52 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-24 19:26:52 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-24 19:26:46 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-06-24 19:26:42 ----A---- C:\Windows\system32\profsvc.dll
2012-06-24 19:26:38 ----A---- C:\Windows\system32\DWrite.dll
2012-06-24 19:26:27 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-24 19:26:27 ----A---- C:\Windows\system32\crypt32.dll
2012-06-24 19:26:26 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-24 19:19:03 ----D---- C:\Users\Datart\AppData\Roaming\Media Player Classic
2012-06-24 19:11:11 ----A---- C:\Windows\system32\wups2.dll
2012-06-24 19:11:11 ----A---- C:\Windows\system32\wucltux.dll
2012-06-24 19:11:11 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-24 19:11:10 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-24 19:10:50 ----A---- C:\Windows\system32\wups.dll
2012-06-24 19:10:50 ----A---- C:\Windows\system32\wudriver.dll
2012-06-24 19:10:50 ----A---- C:\Windows\system32\wuapi.dll
2012-06-24 19:10:36 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-24 19:10:36 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2012-06-28 13:14:54 ----D---- C:\Windows\Temp
2012-06-28 13:14:05 ----RD---- C:\Program Files
2012-06-28 13:05:09 ----D---- C:\Windows\system32\config
2012-06-28 12:25:12 ----D---- C:\Windows\System32
2012-06-28 12:25:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-06-28 12:25:11 ----D---- C:\Windows\inf
2012-06-26 20:59:18 ----SHD---- C:\Windows\Installer
2012-06-26 07:19:38 ----D---- C:\Windows\system32\wdi
2012-06-26 07:19:37 ----D---- C:\Windows\Prefetch
2012-06-25 20:14:02 ----D---- C:\Windows\system32\Tasks
2012-06-25 20:14:02 ----D---- C:\Windows\system32\drivers
2012-06-25 20:13:19 ----D---- C:\Program Files\Common Files\microsoft shared
2012-06-25 20:13:15 ----D---- C:\Program Files\Common Files
2012-06-25 20:13:09 ----SD---- C:\ProgramData\Microsoft
2012-06-25 20:13:07 ----D---- C:\Program Files\Microsoft Office
2012-06-25 19:55:40 ----D---- C:\Windows\Microsoft.NET
2012-06-25 19:47:36 ----RSD---- C:\Windows\assembly
2012-06-25 18:14:18 ----D---- C:\Windows\system32\catroot2
2012-06-25 18:14:18 ----D---- C:\Windows\system32\catroot
2012-06-25 18:14:16 ----D---- C:\Windows\system32\DriverStore
2012-06-25 17:00:30 ----D---- C:\Windows\winsxs
2012-06-25 16:47:15 ----A---- C:\Windows\system32\deployJava1.dll
2012-06-25 16:43:45 ----SHD---- C:\System Volume Information
2012-06-25 16:38:42 ----D---- C:\Windows\rescache
2012-06-25 16:34:36 ----D---- C:\Windows\Tasks
2012-06-25 16:28:48 ----D---- C:\Program Files\Common Files\mcafee
2012-06-25 03:06:57 ----D---- C:\Windows\system32\cs-CZ
2012-06-25 03:06:53 ----D---- C:\Windows\system32\migration
2012-06-25 03:06:51 ----D---- C:\Program Files\Internet Explorer
2012-06-25 03:06:40 ----D---- C:\Program Files\Windows Sidebar
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Photo Viewer
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Media Player
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Mail
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Defender
2012-06-25 03:06:38 ----D---- C:\Program Files\DVD Maker
2012-06-25 03:06:38 ----D---- C:\Program Files\Common Files\System
2012-06-25 03:06:37 ----D---- C:\Windows\servicing
2012-06-25 03:06:37 ----D---- C:\Windows
2012-06-25 03:06:36 ----D---- C:\Windows\en-US
2012-06-25 03:06:35 ----D---- C:\Windows\system32\winrm
2012-06-25 03:06:34 ----D---- C:\Windows\system32\oobe
2012-06-25 03:06:34 ----D---- C:\Windows\system32\migwiz
2012-06-25 03:06:34 ----D---- C:\Windows\system32\en
2012-06-25 03:06:33 ----D---- C:\Windows\system32\sysprep
2012-06-25 03:06:33 ----D---- C:\Windows\system32\slmgr
2012-06-25 03:06:33 ----D---- C:\Windows\system32\Boot
2012-06-25 03:06:32 ----D---- C:\Windows\system32\sk-SK
2012-06-25 03:06:23 ----D---- C:\Windows\system32\drivers\en-US
2012-06-25 03:06:22 ----D---- C:\Windows\system32\en-US
2012-06-25 03:06:12 ----D---- C:\Windows\system32\WCN
2012-06-25 03:06:12 ----D---- C:\Windows\system32\Dism
2012-06-25 03:06:07 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2012-06-25 03:06:05 ----D---- C:\Windows\system32\wbem
2012-06-25 03:05:35 ----D---- C:\Windows\Speech
2012-06-25 02:52:09 ----AD---- C:\ProgramData\Temp
2012-06-24 23:20:54 ----SD---- C:\Users\Datart\AppData\Roaming\Microsoft
2012-06-24 23:12:35 ----D---- C:\ProgramData\Skype
2012-06-24 23:02:53 ----HD---- C:\ProgramData
2012-06-24 22:47:07 ----D---- C:\Windows\Downloaded Program Files
2012-06-24 22:00:04 ----HD---- C:\Program Files\InstallShield Installation Information
2012-06-24 21:03:35 ----RSD---- C:\Windows\Fonts
2012-06-24 20:20:45 ----D---- C:\Windows\Logs
2012-06-24 19:53:00 ----D---- C:\ProgramData\WildTangent
2012-06-03 23:35:34 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2010-11-06 354840]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2011-08-08 40016]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2011-07-26 21600]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2011-07-26 16936]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2011-07-26 62240]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2011-06-21 32768]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-10-24 4807168]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2011-02-11 3396136]
R3 NETwNs32;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\Windows\system32\DRIVERS\NETwNs32.sys [2011-01-04 7435264]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-03-07 252520]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-12-28 327784]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 550760]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 195944]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 21864]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 19304]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-10-08 1314736]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
R2 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-05-13 249648]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files\Launch Manager\dsiwmis.exe [2011-07-01 353360]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-05-10 739944]
R2 GREGService;GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [2011-05-26 29696]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336]
R2 IconMan_R;IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 1755136]
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
R2 NOBU;Norton Online Backup; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2010-06-02 2057560]
R2 RS_Service;Raw Socket Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640]
R2 sftlist;Application Virtualization Client; C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files\Spyware Terminator\st_rsser.exe [2012-06-21 483024]
R2 vToolbarUpdater11.1.0;vToolbarUpdater11.1.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe [2012-06-26 935480]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 0294881340569512mcinstcleanup;McAfee Application Installer Cleanup (0294881340569512); C:\Users\Datart\AppData\Local\Temp\029488~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-25 257224]
S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [2011-04-02 173424]
S3 GamesAppService;GamesAppService; C:\Program Files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-11-19 4640000]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Datart at 2012-06-28 13:14:03
Microsoft Windows 7 Starter Service Pack 1
System drive C: has 257 GB (89%) free of 288 GB
Total RAM: 1012 MB (24% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:14:52, on 28.6.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
C:\Program Files\EgisTec IPS\PmmUpdate.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Launch Manager\LMworker.exe
C:\Program Files\Acer\Android Manager\iSync.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Program Files\Acer\Updater\iUpdate.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Compcare\ikonka.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Datart\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JVD6SL9A\RSIT.exe
C:\Program Files\trend micro\Datart.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [iSyncData] C:\Program Files\Acer\Android Manager\iSync.exe
O4 - HKLM\..\Run: [AndroidManager] C:\Program Files\Acer\Android Manager\AML.exe
O4 - HKLM\..\Run: [iPatchData] C:\Program Files\Acer\Updater\iUpdate.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [IsMyWinLockerReboot] msiexec.exe /qn /x{voidguid} (User 'Default user')
O4 - Startup: Ikonka.lnk = C:\Program Files\Compcare\ikonka.exe
O4 - Global Startup: Acer VCM.lnk = ?
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files\ICQ7M\ICQ.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: McAfee Application Installer Cleanup (0294881340569512) (0294881340569512mcinstcleanup) - Unknown owner - C:\Users\Datart\AppData\Local\Temp\029488~1.EXE (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files\Spyware Terminator\st_rsser.exe
O23 - Service: vToolbarUpdater11.1.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
--
End of file - 9821 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-16 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2011-11-11 1378144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2012-06-25 329480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll [2012-06-26 2068536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-06-25 59144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files\Microsoft\BingBar\BingExt.dll [2011-06-07 1152264]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll [2012-06-26 2068536]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2011-02-11 10025576]
"SuiteTray"=C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [2011-04-02 340848]
"EgisTecPMMUpdate"=C:\Program Files\EgisTec IPS\PmmUpdate.exe [2011-03-29 408432]
"EgisUpdate"=C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-29 202608]
"Norton Online Backup"=C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe [2010-06-02 966488]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-01-11 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-01-11 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-01-11 150552]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2011-07-01 1103440]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-10-08 1934632]
"Power Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2011-05-10 715368]
"iSyncData"=C:\Program Files\Acer\Android Manager\iSync.exe [2011-05-10 408128]
"AndroidManager"=C:\Program Files\Acer\Android Manager\AML.exe [2011-05-10 508992]
"iPatchData"=C:\Program Files\Acer\Updater\iUpdate.exe [2011-05-10 492096]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2012-01-24 2416480]
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe [2012-06-26 1104440]
"SpywareTerminatorShield"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2012-06-21 2786512]
"SpywareTerminatorUpdater"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2012-06-21 3669712]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-01-18 254696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Users\Datart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Ikonka.lnk - C:\Program Files\Compcare\ikonka.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-10-24 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-06-28 13:14:05 ----D---- C:\Program Files\trend micro
2012-06-28 13:14:02 ----D---- C:\rsit
2012-06-28 09:34:34 ----D---- C:\Users\Datart\AppData\Roaming\vlc
2012-06-28 09:30:43 ----D---- C:\Program Files\VideoLAN
2012-06-25 20:13:15 ----D---- C:\Program Files\Common Files\DESIGNER
2012-06-25 20:13:07 ----D---- C:\Program Files\Microsoft Application Virtualization Client
2012-06-25 20:12:32 ----D---- C:\Users\Datart\AppData\Roaming\TP
2012-06-25 16:49:50 ----D---- C:\Program Files\Common Files\Java
2012-06-25 16:47:52 ----A---- C:\Windows\system32\npdeployJava1.dll
2012-06-25 16:47:52 ----A---- C:\Windows\system32\javaws.exe
2012-06-25 16:47:51 ----A---- C:\Windows\system32\javaw.exe
2012-06-25 16:47:51 ----A---- C:\Windows\system32\java.exe
2012-06-25 16:47:08 ----D---- C:\Program Files\Java
2012-06-25 16:34:25 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2012-06-24 23:50:25 ----A---- C:\Windows\system32\mshtmled.dll
2012-06-24 23:50:24 ----A---- C:\Windows\system32\iertutil.dll
2012-06-24 23:50:21 ----A---- C:\Windows\system32\ieui.dll
2012-06-24 23:50:20 ----A---- C:\Windows\system32\ieUnatt.exe
2012-06-24 23:50:16 ----A---- C:\Windows\system32\jsproxy.dll
2012-06-24 23:50:15 ----A---- C:\Windows\system32\wininet.dll
2012-06-24 23:50:13 ----A---- C:\Windows\system32\jscript.dll
2012-06-24 23:50:10 ----A---- C:\Windows\system32\jscript9.dll
2012-06-24 23:50:09 ----A---- C:\Windows\system32\url.dll
2012-06-24 23:50:05 ----A---- C:\Windows\system32\urlmon.dll
2012-06-24 23:49:58 ----A---- C:\Windows\system32\mshtml.dll
2012-06-24 23:49:56 ----A---- C:\Windows\system32\ieframe.dll
2012-06-24 23:34:27 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-06-24 23:34:25 ----A---- C:\Windows\system32\wmi.dll
2012-06-24 23:34:25 ----A---- C:\Windows\system32\wintrust.dll
2012-06-24 23:34:24 ----A---- C:\Windows\system32\imagehlp.dll
2012-06-24 23:02:53 ----D---- C:\ProgramData\CyberLink
2012-06-24 23:02:52 ----D---- C:\Users\Datart\AppData\Roaming\CyberLink
2012-06-24 22:45:50 ----D---- C:\Users\Datart\AppData\Roaming\AVG
2012-06-24 22:42:18 ----N---- C:\Windows\system32\MpSigStub.exe
2012-06-24 21:58:38 ----D---- C:\Users\Datart\AppData\Roaming\ICQ
2012-06-24 21:57:30 ----D---- C:\Program Files\ICQ7M
2012-06-24 21:46:55 ----A---- C:\Windows\system32\drivers\sp_rsdrv2.sys
2012-06-24 21:46:51 ----D---- C:\Users\Datart\AppData\Roaming\Spyware Terminator
2012-06-24 21:46:51 ----D---- C:\ProgramData\Spyware Terminator
2012-06-24 21:43:45 ----D---- C:\Program Files\Spyware Terminator
2012-06-24 21:25:38 ----D---- C:\Users\Datart\AppData\Roaming\AVG2012
2012-06-24 21:22:34 ----D---- C:\ProgramData\AVG Secure Search
2012-06-24 21:22:29 ----D---- C:\Program Files\Common Files\AVG Secure Search
2012-06-24 21:22:26 ----D---- C:\Program Files\AVG Secure Search
2012-06-24 21:20:55 ----D---- C:\Windows\system32\drivers\AVG
2012-06-24 21:20:55 ----D---- C:\ProgramData\AVG2012
2012-06-24 21:19:40 ----D---- C:\Program Files\AVG
2012-06-24 21:15:36 ----HD---- C:\ProgramData\Common Files
2012-06-24 21:15:07 ----D---- C:\ProgramData\MFAData
2012-06-24 21:07:19 ----D---- C:\Users\Datart\AppData\Roaming\OpenOffice.org
2012-06-24 21:03:19 ----D---- C:\Program Files\OpenOffice.org 3
2012-06-24 19:53:00 ----D---- C:\Users\Datart\AppData\Roaming\WildTangent
2012-06-24 19:27:57 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2012-06-24 19:27:47 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-06-24 19:27:21 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-06-24 19:27:20 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-06-24 19:27:01 ----A---- C:\Windows\system32\msi.dll
2012-06-24 19:26:57 ----A---- C:\Windows\system32\win32k.sys
2012-06-24 19:26:53 ----A---- C:\Windows\system32\rdpcorekmts.dll
2012-06-24 19:26:52 ----A---- C:\Windows\system32\rdrmemptylst.exe
2012-06-24 19:26:52 ----A---- C:\Windows\system32\rdpwsx.dll
2012-06-24 19:26:46 ----A---- C:\Windows\system32\drivers\partmgr.sys
2012-06-24 19:26:42 ----A---- C:\Windows\system32\profsvc.dll
2012-06-24 19:26:38 ----A---- C:\Windows\system32\DWrite.dll
2012-06-24 19:26:27 ----A---- C:\Windows\system32\cryptsvc.dll
2012-06-24 19:26:27 ----A---- C:\Windows\system32\crypt32.dll
2012-06-24 19:26:26 ----A---- C:\Windows\system32\cryptnet.dll
2012-06-24 19:19:03 ----D---- C:\Users\Datart\AppData\Roaming\Media Player Classic
2012-06-24 19:11:11 ----A---- C:\Windows\system32\wups2.dll
2012-06-24 19:11:11 ----A---- C:\Windows\system32\wucltux.dll
2012-06-24 19:11:11 ----A---- C:\Windows\system32\wuauclt.exe
2012-06-24 19:11:10 ----A---- C:\Windows\system32\wuaueng.dll
2012-06-24 19:10:50 ----A---- C:\Windows\system32\wups.dll
2012-06-24 19:10:50 ----A---- C:\Windows\system32\wudriver.dll
2012-06-24 19:10:50 ----A---- C:\Windows\system32\wuapi.dll
2012-06-24 19:10:36 ----A---- C:\Windows\system32\wuwebv.dll
2012-06-24 19:10:36 ----A---- C:\Windows\system32\wuapp.exe
======List of files/folders modified in the last 1 month======
2012-06-28 13:14:54 ----D---- C:\Windows\Temp
2012-06-28 13:14:05 ----RD---- C:\Program Files
2012-06-28 13:05:09 ----D---- C:\Windows\system32\config
2012-06-28 12:25:12 ----D---- C:\Windows\System32
2012-06-28 12:25:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-06-28 12:25:11 ----D---- C:\Windows\inf
2012-06-26 20:59:18 ----SHD---- C:\Windows\Installer
2012-06-26 07:19:38 ----D---- C:\Windows\system32\wdi
2012-06-26 07:19:37 ----D---- C:\Windows\Prefetch
2012-06-25 20:14:02 ----D---- C:\Windows\system32\Tasks
2012-06-25 20:14:02 ----D---- C:\Windows\system32\drivers
2012-06-25 20:13:19 ----D---- C:\Program Files\Common Files\microsoft shared
2012-06-25 20:13:15 ----D---- C:\Program Files\Common Files
2012-06-25 20:13:09 ----SD---- C:\ProgramData\Microsoft
2012-06-25 20:13:07 ----D---- C:\Program Files\Microsoft Office
2012-06-25 19:55:40 ----D---- C:\Windows\Microsoft.NET
2012-06-25 19:47:36 ----RSD---- C:\Windows\assembly
2012-06-25 18:14:18 ----D---- C:\Windows\system32\catroot2
2012-06-25 18:14:18 ----D---- C:\Windows\system32\catroot
2012-06-25 18:14:16 ----D---- C:\Windows\system32\DriverStore
2012-06-25 17:00:30 ----D---- C:\Windows\winsxs
2012-06-25 16:47:15 ----A---- C:\Windows\system32\deployJava1.dll
2012-06-25 16:43:45 ----SHD---- C:\System Volume Information
2012-06-25 16:38:42 ----D---- C:\Windows\rescache
2012-06-25 16:34:36 ----D---- C:\Windows\Tasks
2012-06-25 16:28:48 ----D---- C:\Program Files\Common Files\mcafee
2012-06-25 03:06:57 ----D---- C:\Windows\system32\cs-CZ
2012-06-25 03:06:53 ----D---- C:\Windows\system32\migration
2012-06-25 03:06:51 ----D---- C:\Program Files\Internet Explorer
2012-06-25 03:06:40 ----D---- C:\Program Files\Windows Sidebar
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Photo Viewer
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Media Player
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Mail
2012-06-25 03:06:38 ----D---- C:\Program Files\Windows Defender
2012-06-25 03:06:38 ----D---- C:\Program Files\DVD Maker
2012-06-25 03:06:38 ----D---- C:\Program Files\Common Files\System
2012-06-25 03:06:37 ----D---- C:\Windows\servicing
2012-06-25 03:06:37 ----D---- C:\Windows
2012-06-25 03:06:36 ----D---- C:\Windows\en-US
2012-06-25 03:06:35 ----D---- C:\Windows\system32\winrm
2012-06-25 03:06:34 ----D---- C:\Windows\system32\oobe
2012-06-25 03:06:34 ----D---- C:\Windows\system32\migwiz
2012-06-25 03:06:34 ----D---- C:\Windows\system32\en
2012-06-25 03:06:33 ----D---- C:\Windows\system32\sysprep
2012-06-25 03:06:33 ----D---- C:\Windows\system32\slmgr
2012-06-25 03:06:33 ----D---- C:\Windows\system32\Boot
2012-06-25 03:06:32 ----D---- C:\Windows\system32\sk-SK
2012-06-25 03:06:23 ----D---- C:\Windows\system32\drivers\en-US
2012-06-25 03:06:22 ----D---- C:\Windows\system32\en-US
2012-06-25 03:06:12 ----D---- C:\Windows\system32\WCN
2012-06-25 03:06:12 ----D---- C:\Windows\system32\Dism
2012-06-25 03:06:07 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2012-06-25 03:06:05 ----D---- C:\Windows\system32\wbem
2012-06-25 03:05:35 ----D---- C:\Windows\Speech
2012-06-25 02:52:09 ----AD---- C:\ProgramData\Temp
2012-06-24 23:20:54 ----SD---- C:\Users\Datart\AppData\Roaming\Microsoft
2012-06-24 23:12:35 ----D---- C:\ProgramData\Skype
2012-06-24 23:02:53 ----HD---- C:\ProgramData
2012-06-24 22:47:07 ----D---- C:\Windows\Downloaded Program Files
2012-06-24 22:00:04 ----HD---- C:\Program Files\InstallShield Installation Information
2012-06-24 21:03:35 ----RSD---- C:\Windows\Fonts
2012-06-24 20:20:45 ----D---- C:\Windows\Logs
2012-06-24 19:53:00 ----D---- C:\ProgramData\WildTangent
2012-06-03 23:35:34 ----A---- C:\Windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSEH;AVGIDSEH; C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2010-11-06 354840]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2011-08-08 40016]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2011-07-26 21600]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2011-07-26 16936]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2011-07-26 62240]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver; \??\C:\Windows\system32\drivers\sp_rsdrv2.sys [2011-06-21 32768]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]
R3 AVGIDSFilter;AVGIDSFilter; C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-10-24 4807168]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2011-02-11 3396136]
R3 NETwNs32;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\Windows\system32\DRIVERS\NETwNs32.sys [2011-01-04 7435264]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-03-07 252520]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2010-12-28 327784]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 550760]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 195944]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 21864]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 19304]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-10-08 1314736]
S2 Parvdm;Parvdm; C:\Windows\system32\drivers\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\drivers\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\drivers\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
R2 BBUpdate;BBUpdate; C:\Program Files\Microsoft\BingBar\SeaPort.EXE [2011-05-13 249648]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files\Launch Manager\dsiwmis.exe [2011-07-01 353360]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-05-10 739944]
R2 GREGService;GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [2011-05-26 29696]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336]
R2 IconMan_R;IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 1755136]
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]
R2 NOBU;Norton Online Backup; C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [2010-06-02 2057560]
R2 RS_Service;Raw Socket Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640]
R2 sftlist;Application Virtualization Client; C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service; C:\Program Files\Spyware Terminator\st_rsser.exe [2012-06-21 483024]
R2 vToolbarUpdater11.1.0;vToolbarUpdater11.1.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe [2012-06-26 935480]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
S2 0294881340569512mcinstcleanup;McAfee Application Installer Cleanup (0294881340569512); C:\Users\Datart\AppData\Local\Temp\029488~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-25 257224]
S3 BBSvc;Bing Bar Update Service; C:\Program Files\Microsoft\BingBar\BBSvc.EXE [2011-06-07 191752]
S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [2011-04-02 173424]
S3 GamesAppService;GamesAppService; C:\Program Files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-11-19 4640000]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 51040]
-----------------EOF-----------------