Virus Generic29.AJGE nejede smazat[+2 Posti, dlhy log]
Napsal: 05 kvě 2013 08:24
Dobry den,
Pri kazdom zapnuti AVG mi vykoukne okno s Detekciou virusu:
http://prntscr.com/13i1fx
Skousal sem ruzne navody jak ten virus smazat, no nic se mi nepodarilo.. Furt pise ze pristup zamitnuty... Skusal som ho vymazat aj cez nudzovi rezim ale nic nepomohlo... Zatim sem si zadne zmeni v PC nevsimnul, no internet furt pada atd... Takze to bude asi tym.....
RSIT:
Logfile of random's system information tool 1.09 (written by random/random)
Run by GAMELASTER at 2013-05-05 09:10:07
Microsoft Windows 8 Pro
System drive C: has 24 GB (31%) free of 76 GB
Total RAM: 3767 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:10:15, on 5.5.2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16384)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.4.0.50\LightShot.exe
C:\Program Files (x86)\Clownfish\Clownfish.exe
C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Program Files\trend micro\GAMELASTER.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - E:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [LightShot] C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
O4 - HKCU\..\Run: [Clownfish] "C:\Program Files (x86)\Clownfish\Clownfish.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: ZyXEL G-202 Wireless Adapter Utility.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
O23 - Service: AsusFanControlService - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.06\AsusFanControlService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @oem4.inf,%ViaKaraokeSrv.SvcDesc%;VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9698 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe /pipeName=64161437-e087-4957-8845-3c3ea6b8923c /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\a5294026-9ff8-4e24-81a0-960d6d831c1b-184-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2013\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2013" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe"
"C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.06\AsusFanControlService.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {232ff1d5-ec7f-4a3a-b422039e1b41c0e9}
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgemca.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\viakaraokesrv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c374631c-beb3-41da-952f-c920d9cf2987 -SystemEventPortName:HostProcess-2b0d0d8f-42b2-40bc-a9da-570755f4b25a -IoCancelEventPortName:HostProcess-5c2e682e-5589-4842-bf78-31e2cfffdeeb -NonStateChangingEventPortName:HostProcess-3581643f-c992-4558-84ad-559b28237fd0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:cb53d338-a760-43d0-a868-fb26f6d48146 -DeviceGroupId:WudfDefaultDevicePool
taskhostex.exe
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
"C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe" -onlytray
C:\Windows\Explorer.EXE
C:\Windows\system32\msiexec.exe /V
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.4.0.50\LightShot.exe" Flags: uninsdeletevalue
"C:\Program Files (x86)\Clownfish\Clownfish.exe"
"C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\WmiApSrv.exe
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
"C:\Program Files (x86)\Winamp\winamp.exe"
taskhost.exe $(Arg0)
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4112.5332800.397795908 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox" E7CF176E110C211B 4112 "\\.\pipe\gecko-crash-server-pipe.4112" plugin
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe" --proxy-stub-channel=Flash4228.6F511D90.30726 --host-broker-channel=Flash4228.6F511D90.15028 --host-pid=4228 --host-npapi-version=27 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_11_7_700_169.dll"
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe" --channel=1656.00BAF144.638617114 --proxy-stub-channel=Flash4228.6F511D90.30726 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_11_7_700_169.dll" --host-npapi-version=27 --type=renderer
"C:\Windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
"C:\Users\GAMELASTER\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\update-S-1-5-21-3732101377-2479867636-1582925402-1001.job
C:\Windows\tasks\update-sys.job
=========Mozilla firefox=========
ProfilePath - C:\Users\GAMELASTER\AppData\Roaming\Mozilla\Firefox\Profiles\l190mp8f.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-04-12 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{876d9f09-c6d6-4324-a2cc-04dd9a4de12f}]
Microsoft Web Test Recorder 10.0 Helper - E:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26 74888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-04-12 170912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-03-22 165872]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-03-22 407536]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-03-22 441840]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-02-28 18672232]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"LightShot"=C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe [2013-02-21 226152]
"Clownfish"=C:\Program Files (x86)\Clownfish\Clownfish.exe [2013-03-27 1262328]
"uTorrent"=C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe [2013-05-03 802136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2012-06-28 74752]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-07-12 5256336]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2013\avgui.exe [2013-03-13 4394032]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ZyXEL G-202 Wireless Adapter Utility.lnk - C:\Program Files (x86)\ZyXEL G-202\ZyXEL G-202.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-03-19 434176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"disablecad"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2013-05-05 09:10:07 ----D---- C:\rsit
2013-05-05 09:10:07 ----D---- C:\Program Files\trend micro
2013-05-04 10:31:36 ----A---- C:\Windows\ntbtlog.txt
2013-05-04 10:30:54 ----D---- C:\Windows\pss
2013-05-04 10:01:57 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Apple Computer
2013-05-03 19:07:32 ----D---- C:\Program Files (x86)\MagicISO
2013-05-03 18:43:55 ----D---- C:\Program Files (x86)\Resource Hacker
2013-05-03 16:56:20 ----D---- C:\ProgramData\Apple Computer
2013-05-03 16:56:20 ----D---- C:\Program Files (x86)\QuickTime
2013-05-03 16:55:12 ----D---- C:\ProgramData\Apple
2013-05-03 16:55:12 ----D---- C:\Program Files (x86)\Apple Software Update
2013-05-03 16:49:57 ----D---- C:\Users\GAMELASTER\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-05-03 16:48:45 ----D---- C:\Users\GAMELASTER\AppData\Roaming\PACE Anti-Piracy
2013-05-03 16:48:45 ----D---- C:\ProgramData\PACE Anti-Piracy
2013-05-02 18:30:45 ----A---- C:\Windows\system32\netcfg-669312.txt
2013-05-02 18:21:01 ----A---- C:\Windows\system32\netcfg-85140.txt
2013-05-02 18:20:44 ----A---- C:\Windows\system32\netcfg-68015.txt
2013-05-01 22:10:39 ----A---- C:\Windows\system32\netcfg-10079421.txt
2013-05-01 21:04:22 ----A---- C:\Windows\dxsdkuninst.exe
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XAudioD2_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XAPOFXD1_5.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XactEngineD3_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XactEngineA3_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\X3DAudioD1_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\D3DX9d_43.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\d3dx9d_33.dll
2013-05-01 20:15:22 ----A---- C:\Windows\system32\D3DX11d_43.dll
2013-05-01 20:15:22 ----A---- C:\Windows\system32\D3DX10d_43.dll
2013-05-01 20:15:22 ----A---- C:\Windows\system32\D3DCSXd_43.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XAudioD2_7.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XAPOFXD1_5.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XactEngineD3_7.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XactEngineA3_7.dll
2013-05-01 20:15:20 ----A---- C:\Windows\SYSWOW64\X3DAudioD1_7.dll
2013-05-01 20:15:20 ----A---- C:\Windows\SYSWOW64\D3dx9d_43.dll
2013-05-01 20:15:20 ----A---- C:\Windows\SYSWOW64\d3dx9d_33.dll
2013-05-01 20:15:18 ----A---- C:\Windows\SYSWOW64\D3DX11d_43.dll
2013-05-01 20:15:17 ----A---- C:\Windows\SYSWOW64\D3DX10d_43.dll
2013-05-01 20:15:17 ----A---- C:\Windows\SYSWOW64\D3DCSXd_43.dll
2013-05-01 08:46:14 ----A---- C:\Windows\system32\netcfg-50758140.txt
2013-05-01 07:56:53 ----A---- C:\Windows\system32\netcfg-47796750.txt
2013-04-30 22:39:26 ----A---- C:\Windows\system32\netcfg-14356265.txt
2013-04-30 18:43:35 ----A---- C:\Windows\system32\netcfg-204656.txt
2013-04-30 18:43:21 ----A---- C:\Windows\system32\netcfg-191078.txt
2013-04-29 22:07:55 ----A---- C:\Windows\system32\netcfg-22218156.txt
2013-04-29 22:07:05 ----A---- C:\Windows\system32\netcfg-22168296.txt
2013-04-29 22:07:04 ----A---- C:\Windows\system32\netcfg-22166921.txt
2013-04-28 22:30:33 ----A---- C:\Windows\system32\netcfg-18728609.txt
2013-04-28 17:19:47 ----A---- C:\Windows\system32\netcfg-82625.txt
2013-04-28 17:18:10 ----A---- C:\Windows\system32\netcfg-18060828.txt
2013-04-28 16:17:05 ----D---- C:\Program Files\Application Verifier
2013-04-28 16:17:05 ----D---- C:\Program Files (x86)\Application Verifier
2013-04-28 16:17:01 ----D---- C:\ProgramData\Windows App Certification Kit
2013-04-28 16:14:20 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2013-04-28 16:14:12 ----D---- C:\Program Files\Microsoft
2013-04-28 16:13:56 ----D---- C:\Program Files\IIS Express
2013-04-28 16:13:56 ----D---- C:\Program Files (x86)\IIS Express
2013-04-28 16:12:49 ----D---- C:\Program Files (x86)\NuGet
2013-04-28 16:12:42 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2013-04-28 16:11:32 ----D---- C:\Program Files (x86)\Windows Kits
2013-04-28 16:07:48 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2013-04-28 16:02:27 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2013-04-28 16:00:00 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2013-04-28 15:58:46 ----D---- C:\Windows\system32\appmgmt
2013-04-28 14:02:07 ----D---- C:\ProgramData\ALM
2013-04-28 13:49:04 ----D---- C:\Program Files (x86)\Adobe Media Player
2013-04-28 13:48:51 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2013-04-28 13:48:51 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2013-04-28 13:48:51 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2013-04-28 13:48:51 ----D---- C:\Program Files (x86)\My Company Name
2013-04-28 13:47:15 ----D---- C:\Program Files\Common Files\Adobe
2013-04-28 13:47:15 ----D---- C:\Program Files\Adobe
2013-04-28 13:46:28 ----D---- C:\Program Files (x86)\Adobe
2013-04-28 13:45:09 ----D---- C:\ProgramData\Adobe
2013-04-28 12:24:57 ----A---- C:\Windows\system32\netcfg-467640.txt
2013-04-28 12:24:55 ----A---- C:\Windows\system32\netcfg-466296.txt
2013-04-28 12:11:40 ----A---- C:\Windows\system32\netcfg-11300859.txt
2013-04-28 09:48:56 ----D---- C:\Users\GAMELASTER\AppData\Roaming\stetic
2013-04-28 09:48:19 ----D---- C:\Users\GAMELASTER\AppData\Roaming\MonoDevelop-Unity-2.8
2013-04-28 09:23:32 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Unity
2013-04-28 09:23:21 ----D---- C:\ProgramData\Unity
2013-04-27 21:12:17 ----D---- C:\Users\GAMELASTER\AppData\Roaming\uTorrent
2013-04-27 20:35:28 ----A---- C:\Windows\system32\netcfg-2394031.txt
2013-04-27 20:35:15 ----A---- C:\Windows\system32\netcfg-2380812.txt
2013-04-27 20:34:41 ----A---- C:\Windows\system32\netcfg-2347265.txt
2013-04-27 20:33:22 ----A---- C:\Windows\system32\netcfg-2268250.txt
2013-04-27 20:23:09 ----A---- C:\Windows\system32\netcfg-1655250.txt
2013-04-27 20:21:25 ----A---- C:\Windows\system32\netcfg-1551281.txt
2013-04-27 20:19:41 ----A---- C:\Windows\system32\netcfg-1447171.txt
2013-04-27 20:19:41 ----A---- C:\Windows\system32\netcfg-1447125.txt
2013-04-27 20:19:35 ----A---- C:\Windows\system32\netcfg-1440750.txt
2013-04-27 20:19:25 ----A---- C:\Windows\system32\netcfg-1431015.txt
2013-04-27 20:18:48 ----A---- C:\Windows\system32\netcfg-1393937.txt
2013-04-27 19:52:51 ----A---- C:\Windows\system32\netcfg-272353593.txt
2013-04-27 15:54:07 ----D---- C:\Program Files (x86)\sounds
2013-04-27 15:54:06 ----D---- C:\Program Files (x86)\Uninstall
2013-04-27 15:54:06 ----A---- C:\Program Files (x86)\uninstall.exe
2013-04-27 15:54:06 ----A---- C:\Program Files (x86)\lua5.1.dll
2013-04-27 13:54:40 ----A---- C:\Windows\system32\netcfg-250862703.txt
2013-04-27 13:30:49 ----A---- C:\Windows\system32\netcfg-249431468.txt
2013-04-27 12:01:38 ----A---- C:\Windows\system32\netcfg-244080296.txt
2013-04-26 22:28:13 ----A---- C:\Windows\system32\netcfg-195281484.txt
2013-04-26 19:10:42 ----D---- C:\Program Files (x86)\OpenAL
2013-04-26 19:10:42 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2013-04-26 19:10:42 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2013-04-26 19:10:42 ----A---- C:\Windows\system32\wrap_oal.dll
2013-04-26 19:10:42 ----A---- C:\Windows\system32\OpenAL32.dll
2013-04-26 19:07:25 ----D---- C:\Program Files (x86)\MonoGame
2013-04-26 19:01:59 ----D---- C:\Windows\SYSWOW64\xlive
2013-04-26 19:01:58 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-04-26 18:18:26 ----A---- C:\Windows\system32\netcfg-180294812.txt
2013-04-26 14:45:28 ----A---- C:\Windows\system32\netcfg-167522890.txt
2013-04-26 14:32:21 ----A---- C:\Windows\system32\netcfg-166736515.txt
2013-04-25 21:54:54 ----A---- C:\Windows\system32\netcfg-106894687.txt
2013-04-25 20:00:32 ----D---- C:\Users\GAMELASTER\AppData\Roaming\TeamViewer
2013-04-25 19:40:19 ----D---- C:\Program Files (x86)\Microsoft XNA
2013-04-25 17:26:28 ----D---- C:\Program Files (x86)\Game_Maker8
2013-04-25 17:01:37 ----A---- C:\Windows\system32\netcfg-89298281.txt
2013-04-24 22:07:02 ----A---- C:\Windows\system32\netcfg-21228937.txt
2013-04-24 17:09:06 ----A---- C:\Windows\system32\netcfg-3353171.txt
2013-04-24 17:09:00 ----A---- C:\Windows\system32\netcfg-3347140.txt
2013-04-23 22:12:31 ----A---- C:\Windows\system32\netcfg-15051953.txt
2013-04-23 22:12:15 ----A---- C:\Windows\system32\netcfg-15036093.txt
2013-04-23 22:10:19 ----A---- C:\Windows\system32\netcfg-14920078.txt
2013-04-23 22:10:15 ----A---- C:\Windows\system32\netcfg-14916078.txt
2013-04-23 18:26:10 ----A---- C:\Windows\system32\netcfg-1470734.txt
2013-04-23 18:25:45 ----A---- C:\Windows\system32\netcfg-1446578.txt
2013-04-23 18:25:21 ----A---- C:\Windows\system32\netcfg-1421906.txt
2013-04-23 18:25:21 ----A---- C:\Windows\system32\netcfg-1421843.txt
2013-04-23 18:22:04 ----A---- C:\Windows\system32\netcfg-1224640.txt
2013-04-23 18:20:50 ----A---- C:\Windows\system32\netcfg-1151234.txt
2013-04-23 18:05:01 ----A---- C:\Windows\system32\netcfg-202640.txt
2013-04-23 18:04:59 ----A---- C:\Windows\system32\netcfg-200250.txt
2013-04-23 18:04:56 ----A---- C:\Windows\system32\netcfg-197234.txt
2013-04-23 18:04:53 ----A---- C:\Windows\system32\netcfg-194218.txt
2013-04-23 18:03:48 ----A---- C:\Windows\system32\netcfg-129234.txt
2013-04-23 18:00:23 ----A---- C:\Windows\system32\netcfg-869812.txt
2013-04-23 17:54:47 ----A---- C:\Windows\system32\netcfg-534156.txt
2013-04-23 17:54:44 ----A---- C:\Windows\system32\netcfg-531109.txt
2013-04-23 17:52:09 ----A---- C:\Windows\system32\netcfg-376140.txt
2013-04-23 17:52:06 ----A---- C:\Windows\system32\netcfg-372984.txt
2013-04-23 17:52:03 ----A---- C:\Windows\system32\netcfg-370281.txt
2013-04-23 17:48:48 ----A---- C:\Windows\system32\netcfg-174921.txt
2013-04-23 17:48:37 ----A---- C:\Windows\system32\netcfg-164500.txt
2013-04-23 17:47:25 ----A---- C:\Windows\system32\netcfg-92062.txt
2013-04-23 17:46:48 ----A---- C:\Windows\system32\netcfg-54890.txt
2013-04-23 17:45:19 ----D---- C:\Program Files (x86)\ZyXEL G-202
2013-04-23 17:45:19 ----A---- C:\Windows\system32\drivers\WlanGZG.sys
2013-04-23 17:41:33 ----A---- C:\Windows\system32\netcfg-442125.txt
2013-04-23 17:41:33 ----A---- C:\Windows\system32\netcfg-442046.txt
2013-04-23 17:41:33 ----A---- C:\Windows\system32\netcfg-441906.txt
2013-04-23 17:41:27 ----A---- C:\Windows\system32\netcfg-435875.txt
2013-04-23 17:40:46 ----A---- C:\Windows\system32\netcfg-395593.txt
2013-04-23 17:40:32 ----A---- C:\Windows\system32\netcfg-381578.txt
2013-04-23 17:39:24 ----A---- C:\Windows\system32\netcfg-312796.txt
2013-04-23 17:39:22 ----A---- C:\Windows\system32\netcfg-310734.txt
2013-04-23 17:38:21 ----A---- C:\Windows\system32\netcfg-250062.txt
2013-04-23 17:37:58 ----A---- C:\Windows\system32\netcfg-227468.txt
2013-04-23 17:36:45 ----A---- C:\Windows\system32\netcfg-153843.txt
2013-04-23 17:31:59 ----A---- C:\Windows\system32\netcfg-8512718.txt
2013-04-23 17:25:57 ----A---- C:\Windows\system32\netcfg-8151015.txt
2013-04-23 17:25:45 ----A---- C:\Windows\system32\netcfg-8139531.txt
2013-04-23 17:24:58 ----A---- C:\Windows\system32\netcfg-8091765.txt
2013-04-23 17:24:48 ----A---- C:\Windows\system32\netcfg-8082562.txt
2013-04-23 17:19:58 ----A---- C:\Windows\system32\netcfg-7791765.txt
2013-04-23 17:19:57 ----A---- C:\Windows\system32\netcfg-7791234.txt
2013-04-23 17:18:54 ----A---- C:\Windows\system32\netcfg-7727718.txt
2013-04-23 15:55:15 ----A---- C:\Windows\system32\netcfg-2708968.txt
2013-04-23 15:54:47 ----A---- C:\Windows\system32\netcfg-2680953.txt
2013-04-23 15:54:42 ----A---- C:\Windows\system32\netcfg-2676062.txt
2013-04-22 22:27:07 ----A---- C:\Windows\system32\netcfg-439078.txt
2013-04-22 22:22:14 ----A---- C:\Windows\system32\netcfg-145703.txt
2013-04-22 22:22:14 ----A---- C:\Windows\system32\netcfg-145656.txt
2013-04-22 22:22:09 ----A---- C:\Windows\system32\netcfg-140859.txt
2013-04-22 22:20:37 ----A---- C:\Windows\system32\netcfg-49062.txt
2013-04-22 22:19:32 ----A---- C:\Windows\system32\netcfg-1348015.txt
2013-04-22 22:19:26 ----A---- C:\Windows\system32\netcfg-1342578.txt
2013-04-22 22:19:23 ----A---- C:\Windows\system32\netcfg-1339437.txt
2013-04-22 22:18:38 ----D---- C:\Program Files\ASUS
2013-04-22 22:18:37 ----A---- C:\Windows\SYSWOW64\drivers\ASUSFILTER.sys
2013-04-22 22:17:51 ----A---- C:\Windows\system32\drivers\ndisrd.sys
2013-04-22 22:16:58 ----A---- C:\Windows\system32\netcfg-1194296.txt
2013-04-22 21:59:38 ----A---- C:\Windows\system32\netcfg-154125.txt
2013-04-22 21:58:23 ----A---- C:\Windows\system32\netcfg-79437.txt
2013-04-22 21:57:58 ----A---- C:\Windows\system32\netcfg-54484.txt
2013-04-22 17:48:03 ----A---- C:\Windows\PE_Rom.dll
2013-04-22 17:46:59 ----A---- C:\Windows\system32\netcfg-183062.txt
2013-04-22 17:46:45 ----A---- C:\Windows\system32\netcfg-168875.txt
2013-04-22 16:49:11 ----A---- C:\Windows\system32\netcfg-55796.txt
2013-04-21 19:55:57 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Microsoft Corporation
2013-04-21 18:44:06 ----A---- C:\Windows\system32\netcfg-66937.txt
2013-04-21 18:43:52 ----A---- C:\Windows\system32\netcfg-53515.txt
2013-04-21 09:32:12 ----A---- C:\Windows\system32\netcfg-45937.txt
2013-04-21 09:27:27 ----A---- C:\Windows\system32\netcfg-593421.txt
2013-04-21 09:18:20 ----A---- C:\Windows\system32\netcfg-46546.txt
2013-04-21 09:17:06 ----A---- C:\Windows\system32\netcfg-657234.txt
2013-04-20 22:57:35 ----A---- C:\Windows\system32\netcfg-9955828.txt
2013-04-20 15:04:45 ----D---- C:\Program Files\Paint.NET
2013-04-20 12:12:49 ----A---- C:\Windows\system32\netcfg-12240921.txt
2013-04-20 10:23:20 ----A---- C:\Windows\system32\netcfg-5677125.txt
2013-04-19 22:20:51 ----A---- C:\Windows\system32\netcfg-7120890.txt
2013-04-19 20:23:39 ----A---- C:\Windows\system32\netcfg-89500.txt
2013-04-19 20:23:19 ----A---- C:\Windows\system32\netcfg-69609.txt
2013-04-19 20:21:39 ----A---- C:\Windows\SYSWOW64\ZDCN50.dll
2013-04-19 20:21:28 ----A---- C:\Windows\system32\netcfg-328500.txt
2013-04-19 20:21:28 ----A---- C:\Windows\system32\netcfg-327875.txt
2013-04-19 20:15:25 ----A---- C:\Windows\system32\netcfg-61843.txt
2013-04-19 20:13:48 ----A---- C:\Windows\system32\ZDCN50.dll
2013-04-19 20:13:22 ----A---- C:\Windows\system32\drivers\WlanGZ64.sys
2013-04-19 20:12:53 ----A---- C:\Windows\system32\netcfg-773171.txt
2013-04-19 20:12:53 ----A---- C:\Windows\system32\netcfg-773093.txt
2013-04-19 20:12:47 ----A---- C:\Windows\system32\netcfg-766828.txt
2013-04-19 20:07:26 ----A---- C:\Windows\system32\netcfg-445875.txt
2013-04-19 20:07:17 ----A---- C:\Windows\system32\netcfg-436937.txt
2013-04-19 20:03:14 ----A---- C:\Windows\system32\netcfg-194531.txt
2013-04-19 20:03:12 ----A---- C:\Windows\system32\netcfg-192343.txt
2013-04-19 20:02:45 ----A---- C:\Windows\system32\netcfg-165093.txt
2013-04-19 16:00:33 ----A---- C:\Windows\system32\netcfg-8932875.txt
2013-04-19 13:36:05 ----A---- C:\Windows\system32\netcfg-264656.txt
2013-04-19 13:35:59 ----A---- C:\Windows\system32\netcfg-259406.txt
2013-04-19 13:35:32 ----A---- C:\Windows\system32\netcfg-232171.txt
Pri kazdom zapnuti AVG mi vykoukne okno s Detekciou virusu:
http://prntscr.com/13i1fx
Skousal sem ruzne navody jak ten virus smazat, no nic se mi nepodarilo.. Furt pise ze pristup zamitnuty... Skusal som ho vymazat aj cez nudzovi rezim ale nic nepomohlo... Zatim sem si zadne zmeni v PC nevsimnul, no internet furt pada atd... Takze to bude asi tym.....
RSIT:
Logfile of random's system information tool 1.09 (written by random/random)
Run by GAMELASTER at 2013-05-05 09:10:07
Microsoft Windows 8 Pro
System drive C: has 24 GB (31%) free of 76 GB
Total RAM: 3767 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:10:15, on 5.5.2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16384)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.4.0.50\LightShot.exe
C:\Program Files (x86)\Clownfish\Clownfish.exe
C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe
C:\Program Files\trend micro\GAMELASTER.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - E:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [LightShot] C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue
O4 - HKCU\..\Run: [Clownfish] "C:\Program Files (x86)\Clownfish\Clownfish.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - Global Startup: ZyXEL G-202 Wireless Adapter Utility.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
O23 - Service: AsusFanControlService - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.06\AsusFanControlService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @oem4.inf,%ViaKaraokeSrv.SvcDesc%;VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9698 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe /pipeName=64161437-e087-4957-8845-3c3ea6b8923c /coreSdkOptions=4382 /logConfFile="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\a5294026-9ff8-4e24-81a0-960d6d831c1b-184-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG2013\" /registryPath="SYSTEM\CurrentControlSet\Services\Avg\Avg2013" /tempPath="C:\Windows\system32\config\systemprofile\AppData\Local\Avg2013\temp\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe"
"C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.06\AsusFanControlService.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgfws.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {232ff1d5-ec7f-4a3a-b422039e1b41c0e9}
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgemca.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\viakaraokesrv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c374631c-beb3-41da-952f-c920d9cf2987 -SystemEventPortName:HostProcess-2b0d0d8f-42b2-40bc-a9da-570755f4b25a -IoCancelEventPortName:HostProcess-5c2e682e-5589-4842-bf78-31e2cfffdeeb -NonStateChangingEventPortName:HostProcess-3581643f-c992-4558-84ad-559b28237fd0 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:cb53d338-a760-43d0-a868-fb26f6d48146 -DeviceGroupId:WudfDefaultDevicePool
taskhostex.exe
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
"C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe" -onlytray
C:\Windows\Explorer.EXE
C:\Windows\system32\msiexec.exe /V
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\3.4.0.50\LightShot.exe" Flags: uninsdeletevalue
"C:\Program Files (x86)\Clownfish\Clownfish.exe"
"C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
"C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\WmiApSrv.exe
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
"C:\Program Files (x86)\Winamp\winamp.exe"
taskhost.exe $(Arg0)
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4112.5332800.397795908 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox" E7CF176E110C211B 4112 "\\.\pipe\gecko-crash-server-pipe.4112" plugin
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe" --proxy-stub-channel=Flash4228.6F511D90.30726 --host-broker-channel=Flash4228.6F511D90.15028 --host-pid=4228 --host-npapi-version=27 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_11_7_700_169.dll"
"C:\Windows\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe" --channel=1656.00BAF144.638617114 --proxy-stub-channel=Flash4228.6F511D90.30726 --plugin-path="C:\Windows\SYSTEM32\Macromed\Flash\NPSWF32_11_7_700_169.dll" --host-npapi-version=27 --type=renderer
"C:\Windows\system32\SearchFilterHost.exe" 0 556 560 568 65536 564
"C:\Users\GAMELASTER\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\update-S-1-5-21-3732101377-2479867636-1582925402-1001.job
C:\Windows\tasks\update-sys.job
=========Mozilla firefox=========
ProfilePath - C:\Users\GAMELASTER\AppData\Roaming\Mozilla\Firefox\Profiles\l190mp8f.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.169 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.7.700.169 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_169.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{074C1DC5-9320-4A9A-947D-C042949C6216}]
ContributeBHO Class - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-04-12 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{876d9f09-c6d6-4324-a2cc-04dd9a4de12f}]
Microsoft Web Test Recorder 10.0 Helper - E:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26 74888]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-04-12 170912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - Contribute Toolbar - E:\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll [2010-03-27 164312]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-03-22 165872]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-03-22 407536]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-03-22 441840]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-02-28 18672232]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"LightShot"=C:\Users\GAMELASTER\AppData\Local\Skillbrains\lightshot\LightShot.exe [2013-02-21 226152]
"Clownfish"=C:\Program Files (x86)\Clownfish\Clownfish.exe [2013-03-27 1262328]
"uTorrent"=C:\Users\GAMELASTER\AppData\Roaming\uTorrent\uTorrent.exe [2013-05-03 802136]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2012-06-28 74752]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-07-12 5256336]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2013\avgui.exe [2013-03-13 4394032]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-10-11 59280]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
ZyXEL G-202 Wireless Adapter Utility.lnk - C:\Program Files (x86)\ZyXEL G-202\ZyXEL G-202.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-03-19 434176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"disablecad"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.yuy2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"vidc.yvyu"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"vidc.uyvy"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 3 months======
2013-05-05 09:10:07 ----D---- C:\rsit
2013-05-05 09:10:07 ----D---- C:\Program Files\trend micro
2013-05-04 10:31:36 ----A---- C:\Windows\ntbtlog.txt
2013-05-04 10:30:54 ----D---- C:\Windows\pss
2013-05-04 10:01:57 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Apple Computer
2013-05-03 19:07:32 ----D---- C:\Program Files (x86)\MagicISO
2013-05-03 18:43:55 ----D---- C:\Program Files (x86)\Resource Hacker
2013-05-03 16:56:20 ----D---- C:\ProgramData\Apple Computer
2013-05-03 16:56:20 ----D---- C:\Program Files (x86)\QuickTime
2013-05-03 16:55:12 ----D---- C:\ProgramData\Apple
2013-05-03 16:55:12 ----D---- C:\Program Files (x86)\Apple Software Update
2013-05-03 16:49:57 ----D---- C:\Users\GAMELASTER\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2013-05-03 16:48:45 ----D---- C:\Users\GAMELASTER\AppData\Roaming\PACE Anti-Piracy
2013-05-03 16:48:45 ----D---- C:\ProgramData\PACE Anti-Piracy
2013-05-02 18:30:45 ----A---- C:\Windows\system32\netcfg-669312.txt
2013-05-02 18:21:01 ----A---- C:\Windows\system32\netcfg-85140.txt
2013-05-02 18:20:44 ----A---- C:\Windows\system32\netcfg-68015.txt
2013-05-01 22:10:39 ----A---- C:\Windows\system32\netcfg-10079421.txt
2013-05-01 21:04:22 ----A---- C:\Windows\dxsdkuninst.exe
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XAudioD2_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XAPOFXD1_5.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XactEngineD3_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\XactEngineA3_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\X3DAudioD1_7.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\D3DX9d_43.dll
2013-05-01 20:15:23 ----A---- C:\Windows\system32\d3dx9d_33.dll
2013-05-01 20:15:22 ----A---- C:\Windows\system32\D3DX11d_43.dll
2013-05-01 20:15:22 ----A---- C:\Windows\system32\D3DX10d_43.dll
2013-05-01 20:15:22 ----A---- C:\Windows\system32\D3DCSXd_43.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XAudioD2_7.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XAPOFXD1_5.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XactEngineD3_7.dll
2013-05-01 20:15:21 ----A---- C:\Windows\SYSWOW64\XactEngineA3_7.dll
2013-05-01 20:15:20 ----A---- C:\Windows\SYSWOW64\X3DAudioD1_7.dll
2013-05-01 20:15:20 ----A---- C:\Windows\SYSWOW64\D3dx9d_43.dll
2013-05-01 20:15:20 ----A---- C:\Windows\SYSWOW64\d3dx9d_33.dll
2013-05-01 20:15:18 ----A---- C:\Windows\SYSWOW64\D3DX11d_43.dll
2013-05-01 20:15:17 ----A---- C:\Windows\SYSWOW64\D3DX10d_43.dll
2013-05-01 20:15:17 ----A---- C:\Windows\SYSWOW64\D3DCSXd_43.dll
2013-05-01 08:46:14 ----A---- C:\Windows\system32\netcfg-50758140.txt
2013-05-01 07:56:53 ----A---- C:\Windows\system32\netcfg-47796750.txt
2013-04-30 22:39:26 ----A---- C:\Windows\system32\netcfg-14356265.txt
2013-04-30 18:43:35 ----A---- C:\Windows\system32\netcfg-204656.txt
2013-04-30 18:43:21 ----A---- C:\Windows\system32\netcfg-191078.txt
2013-04-29 22:07:55 ----A---- C:\Windows\system32\netcfg-22218156.txt
2013-04-29 22:07:05 ----A---- C:\Windows\system32\netcfg-22168296.txt
2013-04-29 22:07:04 ----A---- C:\Windows\system32\netcfg-22166921.txt
2013-04-28 22:30:33 ----A---- C:\Windows\system32\netcfg-18728609.txt
2013-04-28 17:19:47 ----A---- C:\Windows\system32\netcfg-82625.txt
2013-04-28 17:18:10 ----A---- C:\Windows\system32\netcfg-18060828.txt
2013-04-28 16:17:05 ----D---- C:\Program Files\Application Verifier
2013-04-28 16:17:05 ----D---- C:\Program Files (x86)\Application Verifier
2013-04-28 16:17:01 ----D---- C:\ProgramData\Windows App Certification Kit
2013-04-28 16:14:20 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2013-04-28 16:14:12 ----D---- C:\Program Files\Microsoft
2013-04-28 16:13:56 ----D---- C:\Program Files\IIS Express
2013-04-28 16:13:56 ----D---- C:\Program Files (x86)\IIS Express
2013-04-28 16:12:49 ----D---- C:\Program Files (x86)\NuGet
2013-04-28 16:12:42 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2013-04-28 16:11:32 ----D---- C:\Program Files (x86)\Windows Kits
2013-04-28 16:07:48 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2013-04-28 16:02:27 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2013-04-28 16:00:00 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2013-04-28 15:58:46 ----D---- C:\Windows\system32\appmgmt
2013-04-28 14:02:07 ----D---- C:\ProgramData\ALM
2013-04-28 13:49:04 ----D---- C:\Program Files (x86)\Adobe Media Player
2013-04-28 13:48:51 ----N---- C:\Windows\system32\drivers\PxHlpa64.sys
2013-04-28 13:48:51 ----N---- C:\Windows\system32\drivers\cdralw2k.sys
2013-04-28 13:48:51 ----N---- C:\Windows\system32\drivers\cdr4_xp.sys
2013-04-28 13:48:51 ----D---- C:\Program Files (x86)\My Company Name
2013-04-28 13:47:15 ----D---- C:\Program Files\Common Files\Adobe
2013-04-28 13:47:15 ----D---- C:\Program Files\Adobe
2013-04-28 13:46:28 ----D---- C:\Program Files (x86)\Adobe
2013-04-28 13:45:09 ----D---- C:\ProgramData\Adobe
2013-04-28 12:24:57 ----A---- C:\Windows\system32\netcfg-467640.txt
2013-04-28 12:24:55 ----A---- C:\Windows\system32\netcfg-466296.txt
2013-04-28 12:11:40 ----A---- C:\Windows\system32\netcfg-11300859.txt
2013-04-28 09:48:56 ----D---- C:\Users\GAMELASTER\AppData\Roaming\stetic
2013-04-28 09:48:19 ----D---- C:\Users\GAMELASTER\AppData\Roaming\MonoDevelop-Unity-2.8
2013-04-28 09:23:32 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Unity
2013-04-28 09:23:21 ----D---- C:\ProgramData\Unity
2013-04-27 21:12:17 ----D---- C:\Users\GAMELASTER\AppData\Roaming\uTorrent
2013-04-27 20:35:28 ----A---- C:\Windows\system32\netcfg-2394031.txt
2013-04-27 20:35:15 ----A---- C:\Windows\system32\netcfg-2380812.txt
2013-04-27 20:34:41 ----A---- C:\Windows\system32\netcfg-2347265.txt
2013-04-27 20:33:22 ----A---- C:\Windows\system32\netcfg-2268250.txt
2013-04-27 20:23:09 ----A---- C:\Windows\system32\netcfg-1655250.txt
2013-04-27 20:21:25 ----A---- C:\Windows\system32\netcfg-1551281.txt
2013-04-27 20:19:41 ----A---- C:\Windows\system32\netcfg-1447171.txt
2013-04-27 20:19:41 ----A---- C:\Windows\system32\netcfg-1447125.txt
2013-04-27 20:19:35 ----A---- C:\Windows\system32\netcfg-1440750.txt
2013-04-27 20:19:25 ----A---- C:\Windows\system32\netcfg-1431015.txt
2013-04-27 20:18:48 ----A---- C:\Windows\system32\netcfg-1393937.txt
2013-04-27 19:52:51 ----A---- C:\Windows\system32\netcfg-272353593.txt
2013-04-27 15:54:07 ----D---- C:\Program Files (x86)\sounds
2013-04-27 15:54:06 ----D---- C:\Program Files (x86)\Uninstall
2013-04-27 15:54:06 ----A---- C:\Program Files (x86)\uninstall.exe
2013-04-27 15:54:06 ----A---- C:\Program Files (x86)\lua5.1.dll
2013-04-27 13:54:40 ----A---- C:\Windows\system32\netcfg-250862703.txt
2013-04-27 13:30:49 ----A---- C:\Windows\system32\netcfg-249431468.txt
2013-04-27 12:01:38 ----A---- C:\Windows\system32\netcfg-244080296.txt
2013-04-26 22:28:13 ----A---- C:\Windows\system32\netcfg-195281484.txt
2013-04-26 19:10:42 ----D---- C:\Program Files (x86)\OpenAL
2013-04-26 19:10:42 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2013-04-26 19:10:42 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2013-04-26 19:10:42 ----A---- C:\Windows\system32\wrap_oal.dll
2013-04-26 19:10:42 ----A---- C:\Windows\system32\OpenAL32.dll
2013-04-26 19:07:25 ----D---- C:\Program Files (x86)\MonoGame
2013-04-26 19:01:59 ----D---- C:\Windows\SYSWOW64\xlive
2013-04-26 19:01:58 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-04-26 18:18:26 ----A---- C:\Windows\system32\netcfg-180294812.txt
2013-04-26 14:45:28 ----A---- C:\Windows\system32\netcfg-167522890.txt
2013-04-26 14:32:21 ----A---- C:\Windows\system32\netcfg-166736515.txt
2013-04-25 21:54:54 ----A---- C:\Windows\system32\netcfg-106894687.txt
2013-04-25 20:00:32 ----D---- C:\Users\GAMELASTER\AppData\Roaming\TeamViewer
2013-04-25 19:40:19 ----D---- C:\Program Files (x86)\Microsoft XNA
2013-04-25 17:26:28 ----D---- C:\Program Files (x86)\Game_Maker8
2013-04-25 17:01:37 ----A---- C:\Windows\system32\netcfg-89298281.txt
2013-04-24 22:07:02 ----A---- C:\Windows\system32\netcfg-21228937.txt
2013-04-24 17:09:06 ----A---- C:\Windows\system32\netcfg-3353171.txt
2013-04-24 17:09:00 ----A---- C:\Windows\system32\netcfg-3347140.txt
2013-04-23 22:12:31 ----A---- C:\Windows\system32\netcfg-15051953.txt
2013-04-23 22:12:15 ----A---- C:\Windows\system32\netcfg-15036093.txt
2013-04-23 22:10:19 ----A---- C:\Windows\system32\netcfg-14920078.txt
2013-04-23 22:10:15 ----A---- C:\Windows\system32\netcfg-14916078.txt
2013-04-23 18:26:10 ----A---- C:\Windows\system32\netcfg-1470734.txt
2013-04-23 18:25:45 ----A---- C:\Windows\system32\netcfg-1446578.txt
2013-04-23 18:25:21 ----A---- C:\Windows\system32\netcfg-1421906.txt
2013-04-23 18:25:21 ----A---- C:\Windows\system32\netcfg-1421843.txt
2013-04-23 18:22:04 ----A---- C:\Windows\system32\netcfg-1224640.txt
2013-04-23 18:20:50 ----A---- C:\Windows\system32\netcfg-1151234.txt
2013-04-23 18:05:01 ----A---- C:\Windows\system32\netcfg-202640.txt
2013-04-23 18:04:59 ----A---- C:\Windows\system32\netcfg-200250.txt
2013-04-23 18:04:56 ----A---- C:\Windows\system32\netcfg-197234.txt
2013-04-23 18:04:53 ----A---- C:\Windows\system32\netcfg-194218.txt
2013-04-23 18:03:48 ----A---- C:\Windows\system32\netcfg-129234.txt
2013-04-23 18:00:23 ----A---- C:\Windows\system32\netcfg-869812.txt
2013-04-23 17:54:47 ----A---- C:\Windows\system32\netcfg-534156.txt
2013-04-23 17:54:44 ----A---- C:\Windows\system32\netcfg-531109.txt
2013-04-23 17:52:09 ----A---- C:\Windows\system32\netcfg-376140.txt
2013-04-23 17:52:06 ----A---- C:\Windows\system32\netcfg-372984.txt
2013-04-23 17:52:03 ----A---- C:\Windows\system32\netcfg-370281.txt
2013-04-23 17:48:48 ----A---- C:\Windows\system32\netcfg-174921.txt
2013-04-23 17:48:37 ----A---- C:\Windows\system32\netcfg-164500.txt
2013-04-23 17:47:25 ----A---- C:\Windows\system32\netcfg-92062.txt
2013-04-23 17:46:48 ----A---- C:\Windows\system32\netcfg-54890.txt
2013-04-23 17:45:19 ----D---- C:\Program Files (x86)\ZyXEL G-202
2013-04-23 17:45:19 ----A---- C:\Windows\system32\drivers\WlanGZG.sys
2013-04-23 17:41:33 ----A---- C:\Windows\system32\netcfg-442125.txt
2013-04-23 17:41:33 ----A---- C:\Windows\system32\netcfg-442046.txt
2013-04-23 17:41:33 ----A---- C:\Windows\system32\netcfg-441906.txt
2013-04-23 17:41:27 ----A---- C:\Windows\system32\netcfg-435875.txt
2013-04-23 17:40:46 ----A---- C:\Windows\system32\netcfg-395593.txt
2013-04-23 17:40:32 ----A---- C:\Windows\system32\netcfg-381578.txt
2013-04-23 17:39:24 ----A---- C:\Windows\system32\netcfg-312796.txt
2013-04-23 17:39:22 ----A---- C:\Windows\system32\netcfg-310734.txt
2013-04-23 17:38:21 ----A---- C:\Windows\system32\netcfg-250062.txt
2013-04-23 17:37:58 ----A---- C:\Windows\system32\netcfg-227468.txt
2013-04-23 17:36:45 ----A---- C:\Windows\system32\netcfg-153843.txt
2013-04-23 17:31:59 ----A---- C:\Windows\system32\netcfg-8512718.txt
2013-04-23 17:25:57 ----A---- C:\Windows\system32\netcfg-8151015.txt
2013-04-23 17:25:45 ----A---- C:\Windows\system32\netcfg-8139531.txt
2013-04-23 17:24:58 ----A---- C:\Windows\system32\netcfg-8091765.txt
2013-04-23 17:24:48 ----A---- C:\Windows\system32\netcfg-8082562.txt
2013-04-23 17:19:58 ----A---- C:\Windows\system32\netcfg-7791765.txt
2013-04-23 17:19:57 ----A---- C:\Windows\system32\netcfg-7791234.txt
2013-04-23 17:18:54 ----A---- C:\Windows\system32\netcfg-7727718.txt
2013-04-23 15:55:15 ----A---- C:\Windows\system32\netcfg-2708968.txt
2013-04-23 15:54:47 ----A---- C:\Windows\system32\netcfg-2680953.txt
2013-04-23 15:54:42 ----A---- C:\Windows\system32\netcfg-2676062.txt
2013-04-22 22:27:07 ----A---- C:\Windows\system32\netcfg-439078.txt
2013-04-22 22:22:14 ----A---- C:\Windows\system32\netcfg-145703.txt
2013-04-22 22:22:14 ----A---- C:\Windows\system32\netcfg-145656.txt
2013-04-22 22:22:09 ----A---- C:\Windows\system32\netcfg-140859.txt
2013-04-22 22:20:37 ----A---- C:\Windows\system32\netcfg-49062.txt
2013-04-22 22:19:32 ----A---- C:\Windows\system32\netcfg-1348015.txt
2013-04-22 22:19:26 ----A---- C:\Windows\system32\netcfg-1342578.txt
2013-04-22 22:19:23 ----A---- C:\Windows\system32\netcfg-1339437.txt
2013-04-22 22:18:38 ----D---- C:\Program Files\ASUS
2013-04-22 22:18:37 ----A---- C:\Windows\SYSWOW64\drivers\ASUSFILTER.sys
2013-04-22 22:17:51 ----A---- C:\Windows\system32\drivers\ndisrd.sys
2013-04-22 22:16:58 ----A---- C:\Windows\system32\netcfg-1194296.txt
2013-04-22 21:59:38 ----A---- C:\Windows\system32\netcfg-154125.txt
2013-04-22 21:58:23 ----A---- C:\Windows\system32\netcfg-79437.txt
2013-04-22 21:57:58 ----A---- C:\Windows\system32\netcfg-54484.txt
2013-04-22 17:48:03 ----A---- C:\Windows\PE_Rom.dll
2013-04-22 17:46:59 ----A---- C:\Windows\system32\netcfg-183062.txt
2013-04-22 17:46:45 ----A---- C:\Windows\system32\netcfg-168875.txt
2013-04-22 16:49:11 ----A---- C:\Windows\system32\netcfg-55796.txt
2013-04-21 19:55:57 ----D---- C:\Users\GAMELASTER\AppData\Roaming\Microsoft Corporation
2013-04-21 18:44:06 ----A---- C:\Windows\system32\netcfg-66937.txt
2013-04-21 18:43:52 ----A---- C:\Windows\system32\netcfg-53515.txt
2013-04-21 09:32:12 ----A---- C:\Windows\system32\netcfg-45937.txt
2013-04-21 09:27:27 ----A---- C:\Windows\system32\netcfg-593421.txt
2013-04-21 09:18:20 ----A---- C:\Windows\system32\netcfg-46546.txt
2013-04-21 09:17:06 ----A---- C:\Windows\system32\netcfg-657234.txt
2013-04-20 22:57:35 ----A---- C:\Windows\system32\netcfg-9955828.txt
2013-04-20 15:04:45 ----D---- C:\Program Files\Paint.NET
2013-04-20 12:12:49 ----A---- C:\Windows\system32\netcfg-12240921.txt
2013-04-20 10:23:20 ----A---- C:\Windows\system32\netcfg-5677125.txt
2013-04-19 22:20:51 ----A---- C:\Windows\system32\netcfg-7120890.txt
2013-04-19 20:23:39 ----A---- C:\Windows\system32\netcfg-89500.txt
2013-04-19 20:23:19 ----A---- C:\Windows\system32\netcfg-69609.txt
2013-04-19 20:21:39 ----A---- C:\Windows\SYSWOW64\ZDCN50.dll
2013-04-19 20:21:28 ----A---- C:\Windows\system32\netcfg-328500.txt
2013-04-19 20:21:28 ----A---- C:\Windows\system32\netcfg-327875.txt
2013-04-19 20:15:25 ----A---- C:\Windows\system32\netcfg-61843.txt
2013-04-19 20:13:48 ----A---- C:\Windows\system32\ZDCN50.dll
2013-04-19 20:13:22 ----A---- C:\Windows\system32\drivers\WlanGZ64.sys
2013-04-19 20:12:53 ----A---- C:\Windows\system32\netcfg-773171.txt
2013-04-19 20:12:53 ----A---- C:\Windows\system32\netcfg-773093.txt
2013-04-19 20:12:47 ----A---- C:\Windows\system32\netcfg-766828.txt
2013-04-19 20:07:26 ----A---- C:\Windows\system32\netcfg-445875.txt
2013-04-19 20:07:17 ----A---- C:\Windows\system32\netcfg-436937.txt
2013-04-19 20:03:14 ----A---- C:\Windows\system32\netcfg-194531.txt
2013-04-19 20:03:12 ----A---- C:\Windows\system32\netcfg-192343.txt
2013-04-19 20:02:45 ----A---- C:\Windows\system32\netcfg-165093.txt
2013-04-19 16:00:33 ----A---- C:\Windows\system32\netcfg-8932875.txt
2013-04-19 13:36:05 ----A---- C:\Windows\system32\netcfg-264656.txt
2013-04-19 13:35:59 ----A---- C:\Windows\system32\netcfg-259406.txt
2013-04-19 13:35:32 ----A---- C:\Windows\system32\netcfg-232171.txt