Chyba wscript při spuštění pc
Napsal: 17 úno 2014 19:02
Při spuštětní notebooku a naběhnutí plochy se zobrazí "windows script host není z tohoto počítače dostupný"
Spojím i s preventivkou. Dík
Logfile of random's system information tool 1.09 (written by random/random)
Run by Janek at 2014-02-17 18:41:53
Microsoft Windows 8.1
System drive C: has 714 GB (79%) free of 905 GB
Total RAM: 3950 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:41:55, on 17. 2. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Janek.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - (no file)
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [Lenovo App Shop] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: @C:\WINDOWS\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\WINDOWS\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - (no file)
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - (no file)
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 11015 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\system32\WLANExt.exe 730985507744
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {e92ca6a7-0376-4da9-ba02a162d1515bff}
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe" /DisableUI
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b5892d9c-e573-4ee0-b963-f6ad5584a286 -SystemEventPortName:HostProcess-812a534c-4a0e-48e7-bb61-8575be62e468 -IoCancelEventPortName:HostProcess-47004573-620d-4dac-815b-5029016a381f -NonStateChangingEventPortName:HostProcess-c0ae8b6e-62ee-4d83-a429-ce3cb2d47fbb -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:1bbf33e1-bb1d-408e-846e-ef278bde310b -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\WINDOWS\system32\wbem\wmiprvse.exe
taskhostex.exe
ClassicStartMenu.exe -startup
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe" -start
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
C:\WINDOWS\system32\svchost.exe -k HPService
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
taskhost.exe
explorer.exe
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
taskeng.exe {5FBAF76E-B624-4C9C-B94E-32A23B3E4A9B}
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Janek\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Janek\AppData\Roaming\Mozilla\Firefox\Profiles\e366185m.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.8.4, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, firetorrent@radicalsoft.com:2.0.3, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://www.google.com/search?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.44 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll
C:\Users\Janek\AppData\Roaming\Mozilla\Firefox\Profiles\e366185m.default\searchplugins\
mapycz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-03 1143168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-03 1143168]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-09-05 2872720]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-10-17 6334096]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-09-14 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-04-11 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-04-11 191544]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2013-09-19 7818040]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2013-12-10 2279712]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2014-01-18 161984]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 13662936]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2000-01-01 1361112]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2000-01-01 1361112]
"Windows Mobile Device Center"=C:\WINDOWS\WindowsMobile\wmdc.exe [2007-05-31 660360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2013-07-18 156000]
"Lenovo App Shop"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2013-07-18 156000]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-02-03 3767096]
C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files (x86)\Stardock\WindowBlinds\fast64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoDispAppearancePage"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableFirstLogonAnimation"=1
"NoDispCPL"=0
"SynchronousUserGroupPolicy"=1
"DisplayLastLogonInfo"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoPreviewPane"=0
"StartMenuLogOff"=0
"NoClose"=0
"NoTrayContextMenu"=0
"NoFolderOptions"=0
"NoViewContextMenu"=0
"TaskbarNoNotification"=0
"NoWinkeys"=0
"HideClock"=0
"HideSCANetwork"=0
"HideSCAVolume"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
"NoRecentDocsNetHood"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-02-17 18:41:53 ----D---- C:\Program Files\trend micro
2014-02-17 18:25:46 ----D---- C:\rsit
2014-02-17 18:25:46 ----D---- C:\Program Files (x86)\trend micro
2014-02-17 17:47:01 ----A---- C:\WINDOWS\SYSWOW64\msdrm.dll
2014-02-17 17:47:01 ----A---- C:\WINDOWS\system32\msdrm.dll
2014-02-17 17:47:00 ----A---- C:\WINDOWS\system32\d2d1.dll
2014-02-17 17:46:59 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-02-17 17:46:59 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2014-02-17 17:46:59 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-02-17 17:46:58 ----A---- C:\WINDOWS\system32\msxml3.dll
2014-02-17 17:46:57 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2014-02-17 17:46:53 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-02-17 17:46:53 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-02-17 17:46:53 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-02-17 17:46:51 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-02-17 17:46:51 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-02-17 17:46:49 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-02-17 17:46:49 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-02-17 17:46:49 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-02-17 17:46:48 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-02-17 17:46:48 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-02-17 17:46:48 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-02-17 17:46:47 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-02-17 17:46:47 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-02-17 17:46:47 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-02-17 17:46:47 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-02-17 17:46:46 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-02-17 17:46:45 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-02-17 17:46:45 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\wininet.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\msrating.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-02-17 17:46:43 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-02-17 17:46:07 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-02-17 17:46:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-02-17 17:46:06 ----A---- C:\WINDOWS\system32\twinui.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\system32\propsys.dll
2014-02-17 17:45:35 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-02-17 17:45:35 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-02-17 17:45:27 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2014-02-17 17:45:27 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\XpsGdiConverter.dll
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\win32k.sys
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2014-02-17 17:45:26 ----A---- C:\WINDOWS\system32\shell32.dll
2014-02-17 17:45:25 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-02-17 17:45:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-02-17 17:45:23 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\SYSWOW64\XpsGdiConverter.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\SYSWOW64\WSClient.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\SYSWOW64\OEMLicense.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\system32\WSClient.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\system32\OEMLicense.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-02-17 17:45:20 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-02-17 17:45:20 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\ReAgent.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\mfsvr.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2014-02-17 17:45:18 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\system32\pnrpsvc.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2014-02-17 17:45:16 ----A---- C:\WINDOWS\system32\hal.dll
2014-02-17 17:45:15 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-02-17 17:45:15 ----A---- C:\WINDOWS\system32\reseteng.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\sti.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\easinvoker.exe
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2014-02-17 17:45:13 ----A---- C:\WINDOWS\SYSWOW64\sti.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\SYSWOW64\easwrt.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\system32\easwrt.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2014-02-17 17:45:12 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-02-17 17:45:12 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-02-17 17:45:07 ----A---- C:\WINDOWS\system32\winbici.dll
2014-02-17 17:45:07 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-02-17 17:45:07 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-02-17 17:44:40 ----A---- C:\WINDOWS\SYSWOW64\pcaui.exe
2014-02-17 17:44:40 ----A---- C:\WINDOWS\system32\pcaui.exe
2014-02-17 17:30:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-02-09 23:37:50 ----D---- C:\Users\Janek\AppData\Roaming\Mp3tag
2014-02-09 23:37:29 ----D---- C:\Program Files (x86)\Mp3tag
2014-02-09 01:10:51 ----D---- C:\FFOutput
2014-02-09 01:09:44 ----D---- C:\Program Files (x86)\FreeTime
2014-02-07 18:42:18 ----D---- C:\Users\Janek\AppData\Roaming\AIMP3
2014-02-07 18:42:15 ----D---- C:\Program Files (x86)\AIMP3
2014-02-07 12:39:35 ----D---- C:\Users\Janek\AppData\Roaming\COWON
2014-02-07 12:31:13 ----D---- C:\Users\Janek\AppData\Roaming\Systweak
2014-02-04 18:05:51 ----D---- C:\iBTWU
2014-02-04 17:32:02 ----D---- C:\WINDOWS\WindowsMobile
2014-02-04 12:02:29 ----D---- C:\ProgramData\Orbit
2014-02-04 11:53:44 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrB.exe
2014-02-04 11:53:42 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrA.exe
2014-02-03 18:03:21 ----D---- C:\Program Files\Realtek
2014-02-03 18:02:08 ----A---- C:\WINDOWS\system32\WavesGUILib64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSWOW64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSTSX64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSTSH64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSHP64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\SYSWOW64\SFCOM.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFSS_APO.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFNHK64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFCOM64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFAPO64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\drivers\rtvienna.dat
2014-02-03 18:02:04 ----A---- C:\WINDOWS\system32\RtPgEx64.dll
2014-02-03 18:02:04 ----A---- C:\WINDOWS\system32\RtlCPAPI64.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\RtkGuiCompLib.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\RtkCoLDR64.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\RtkCfg64.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\drivers\RTKVHD64.sys
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RtkAPO64.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RtkApi64.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEEP64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEEL64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEEG64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEED64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RtDataProc64.dll
2014-02-03 18:02:01 ----A---- C:\WINDOWS\system32\RTCOM64.dll
2014-02-03 18:02:01 ----A---- C:\WINDOWS\system32\drivers\RTAIODAT.DAT
2014-02-03 18:02:00 ----A---- C:\WINDOWS\system32\RP3DHT64.dll
2014-02-03 18:02:00 ----A---- C:\WINDOWS\system32\RP3DAA64.dll
2014-02-03 18:01:59 ----A---- C:\WINDOWS\system32\RCoRes64.dat
2014-02-03 18:01:59 ----A---- C:\WINDOWS\system32\RCoInstII64.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEP64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEL64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEG64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EED64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEA64A.dll
2014-02-03 18:01:56 ----A---- C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
2014-02-03 18:01:48 ----A---- C:\WINDOWS\system32\MaxxAudioRealtek64.dll
2014-02-03 18:01:45 ----A---- C:\WINDOWS\system32\MaxxAudioRealtek264.dll
2014-02-03 18:01:43 ----A---- C:\WINDOWS\system32\MaxxAudioEQ64.dll
2014-02-03 18:01:41 ----A---- C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
2014-02-03 18:01:39 ----A---- C:\WINDOWS\system32\MaxxAudioAPO30.dll
2014-02-03 18:01:39 ----A---- C:\WINDOWS\system32\MaxxAudioAPO20.dll
2014-02-03 18:01:21 ----A---- C:\WINDOWS\system32\FMAPO64.dll
2014-02-03 18:01:18 ----A---- C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2014-02-03 18:01:17 ----A---- C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2014-02-03 18:01:16 ----A---- C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2014-02-03 18:01:15 ----A---- C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2014-02-03 18:01:14 ----A---- C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2014-02-03 18:01:14 ----A---- C:\WINDOWS\system32\DTSLimiterDLL64.dll
2014-02-03 18:01:12 ----A---- C:\WINDOWS\system32\DTSLFXAPO64.dll
2014-02-03 18:01:12 ----A---- C:\WINDOWS\system32\DTSGFXAPONS64.dll
2014-02-03 18:01:12 ----A---- C:\WINDOWS\system32\DTSGFXAPO64.dll
2014-02-03 18:01:11 ----A---- C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2014-02-03 18:01:11 ----A---- C:\WINDOWS\system32\DTSBoostDLL64.dll
2014-02-03 18:01:10 ----A---- C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2014-02-03 18:01:06 ----A---- C:\WINDOWS\system32\DDPP64A.dll
2014-02-03 18:01:06 ----A---- C:\WINDOWS\system32\DDPO64A.dll
2014-02-03 18:01:05 ----A---- C:\WINDOWS\system32\DDPD64A.dll
2014-02-03 18:01:05 ----A---- C:\WINDOWS\system32\DDPA64.dll
2014-02-03 18:01:04 ----A---- C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2014-02-03 18:01:01 ----A---- C:\WINDOWS\system32\AERTAR64.dll
2014-02-03 18:01:01 ----A---- C:\WINDOWS\system32\AERTAC64.dll
2014-02-03 18:00:49 ----A---- C:\WINDOWS\RtlExUpd.dll
2014-02-03 17:44:52 ----D---- C:\Program Files (x86)\SlimDrivers
2014-02-03 17:34:09 ----D---- C:\Program Files (x86)\Shai Raiten
2014-02-03 13:19:12 ----D---- C:\Program Files (x86)\Resource Hacker
2014-01-29 23:53:47 ----D---- C:\ProgramData\dbg
2014-01-29 23:53:44 ----D---- C:\AeroGlass
2014-01-27 00:19:40 ----D---- C:\Program Files\Classic Shell
2014-01-26 16:40:18 ----D---- C:\Users\Janek\AppData\Roaming\newnext.me
2014-01-26 16:38:07 ----D---- C:\Users\Janek\AppData\Roaming\GoforFiles
2014-01-26 14:02:27 ----D---- C:\ProgramData\Stardock
2014-01-26 14:02:27 ----A---- C:\WINDOWS\system32\wbload.dll
2014-01-24 23:03:34 ----D---- C:\ProgramData\IDMComp
2014-01-24 23:03:32 ----D---- C:\Users\Janek\AppData\Roaming\IDMComp
2014-01-24 19:22:58 ----D---- C:\Users\Janek\AppData\Roaming\Hex-Rays
2014-01-22 08:52:10 ----A---- C:\WINDOWS\system32\drivers\ssudmdm.sys
2014-01-22 08:52:10 ----A---- C:\WINDOWS\system32\drivers\ssudbus.sys
2014-01-21 23:47:06 ----D---- C:\Users\Janek\AppData\Roaming\Rainmeter
2014-01-21 23:46:44 ----D---- C:\Program Files\Rainmeter
2014-01-21 00:56:09 ----D---- C:\ProgramData\Codemasters
2014-01-21 00:56:07 ----D---- C:\ProgramData\Steam
2014-01-20 21:15:38 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-01-20 21:15:38 ----D---- C:\WINDOWS\system32\NV
2014-01-20 21:11:39 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2014-01-20 21:11:39 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2014-01-20 21:11:38 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2014-01-20 21:11:38 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2014-01-20 21:11:37 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2014-01-20 21:11:37 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2014-01-20 21:07:07 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2014-01-20 21:07:07 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2014-01-20 21:07:07 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2014-01-20 21:07:06 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2014-01-20 21:07:06 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvopencl.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvcuvenc.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvdispgenco6433221.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvdispco6433221.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\system32\nvcuda.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2014-01-20 20:38:08 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2014-01-20 20:38:08 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2014-01-20 20:38:07 ----A---- C:\WINDOWS\system32\combase.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-01-20 20:38:05 ----A---- C:\WINDOWS\system32\authui.dll
2014-01-20 20:38:04 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-01-20 20:38:04 ----A---- C:\WINDOWS\system32\winmde.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\system32\wmpmde.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-01-20 20:38:02 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\ubpm.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\ploptin.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\oleaut32.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\mfds.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\audiosrv.dll
2014-01-20 20:38:01 ----AC---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2014-01-20 20:38:01 ----AC---- C:\WINDOWS\system32\drivers\BtaMPM.sys
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\msieftp.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\Windows.Graphics.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\rastls.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\psmsrv.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\msieftp.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\mispace.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\drivers\ipnat.sys
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\bi.dll
2014-01-20 20:38:00 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2014-01-20 20:38:00 ----A---- C:\WINDOWS\system32\deviceregistration.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\WSService.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\WSCollect.exe
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-20 20:36:09 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-01-18 17:12:06 ----A---- C:\WINDOWS\system32\StartMenuHelper64.dll
2014-01-18 17:12:00 ----A---- C:\WINDOWS\SYSWOW64\StartMenuHelper32.dll
Spojím i s preventivkou. Dík
Logfile of random's system information tool 1.09 (written by random/random)
Run by Janek at 2014-02-17 18:41:53
Microsoft Windows 8.1
System drive C: has 714 GB (79%) free of 905 GB
Total RAM: 3950 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:41:55, on 17. 2. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Janek.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: (no name) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - (no file)
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [Lenovo App Shop] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
O9 - Extra button: @C:\WINDOWS\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\WINDOWS\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\WindowsMobile\INetRepl.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - (no file)
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - (no file)
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - (no file)
O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DokanMounter - Unknown owner - C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
--
End of file - 11015 bytes
======Listing Processes======
wininit.exe
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\system32\WLANExt.exe 730985507744
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
dashost.exe {e92ca6a7-0376-4da9-ba02a162d1515bff}
"C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe" /DisableUI
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\SysWOW64\PnkBstrA.exe
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b5892d9c-e573-4ee0-b963-f6ad5584a286 -SystemEventPortName:HostProcess-812a534c-4a0e-48e7-bb61-8575be62e468 -IoCancelEventPortName:HostProcess-47004573-620d-4dac-815b-5029016a381f -NonStateChangingEventPortName:HostProcess-c0ae8b6e-62ee-4d83-a429-ce3cb2d47fbb -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:1bbf33e1-bb1d-408e-846e-ef278bde310b -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\WINDOWS\system32\wbem\wmiprvse.exe
taskhostex.exe
ClassicStartMenu.exe -startup
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe" -autostart
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe" -start
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\Rainmeter\Rainmeter.exe"
"C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
C:\WINDOWS\system32\svchost.exe -k HPService
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\WINDOWS\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
taskhost.exe
explorer.exe
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
taskeng.exe {5FBAF76E-B624-4C9C-B94E-32A23B3E4A9B}
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 564 568 576 65536 572
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Janek\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Janek\AppData\Roaming\Mozilla\Firefox\Profiles\e366185m.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.8.4, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, firetorrent@radicalsoft.com:2.0.3, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://www.google.com/search?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.44 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 12.0.0.43 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll
C:\Users\Janek\AppData\Roaming\Mozilla\Firefox\Profiles\e366185m.default\searchplugins\
mapycz.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-03 1143168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-02-03 1390368]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-02-03 1143168]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-09-05 2872720]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-10-17 6334096]
"OnekeyStudio"=C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [2012-09-14 4196432]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-04-11 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-04-11 191544]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2013-09-19 7818040]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2013-12-10 2279712]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2014-01-18 161984]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 13662936]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2000-01-01 1361112]
"RtHDVBg_LENOVO_MICPKEY"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2000-01-01 1361112]
"Windows Mobile Device Center"=C:\WINDOWS\WindowsMobile\wmdc.exe [2007-05-31 660360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2012-10-31 168464]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2012-04-19 217088]
"RemoteControl10"=C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2013-07-18 156000]
"Lenovo App Shop"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2013-07-18 156000]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-02-03 3767096]
C:\Users\Janek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
C:\Program Files (x86)\Stardock\WindowBlinds\fast64.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicDisplay.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BasicRender.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BrokerInfrastructure]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DeviceInstall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dxgkrnl.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FsDepends.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LSM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SmartcardSimulator]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SystemEventsBroker]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VirtualSmartcardReader]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wcmsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{9DA2B80F-F89F-4A49-A5C2-511B085B9E8A}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"NoDispAppearancePage"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"EnableUIADesktopToggle"=0
"EnableCursorSuppression"=1
"ConsentPromptBehaviorUser"=3
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableFirstLogonAnimation"=1
"NoDispCPL"=0
"SynchronousUserGroupPolicy"=1
"DisplayLastLogonInfo"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoPreviewPane"=0
"StartMenuLogOff"=0
"NoClose"=0
"NoTrayContextMenu"=0
"NoFolderOptions"=0
"NoViewContextMenu"=0
"TaskbarNoNotification"=0
"NoWinkeys"=0
"HideClock"=0
"HideSCANetwork"=0
"HideSCAVolume"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktopChanges"=1
"NoActiveDesktop"=1
"NoRecentDocsNetHood"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-02-17 18:41:53 ----D---- C:\Program Files\trend micro
2014-02-17 18:25:46 ----D---- C:\rsit
2014-02-17 18:25:46 ----D---- C:\Program Files (x86)\trend micro
2014-02-17 17:47:01 ----A---- C:\WINDOWS\SYSWOW64\msdrm.dll
2014-02-17 17:47:01 ----A---- C:\WINDOWS\system32\msdrm.dll
2014-02-17 17:47:00 ----A---- C:\WINDOWS\system32\d2d1.dll
2014-02-17 17:46:59 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2014-02-17 17:46:59 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2014-02-17 17:46:59 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2014-02-17 17:46:58 ----A---- C:\WINDOWS\system32\msxml3.dll
2014-02-17 17:46:57 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2014-02-17 17:46:53 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-02-17 17:46:53 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-02-17 17:46:53 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-02-17 17:46:52 ----A---- C:\WINDOWS\system32\ieetwcollectorres.dll
2014-02-17 17:46:51 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-02-17 17:46:51 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-02-17 17:46:50 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-02-17 17:46:49 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-02-17 17:46:49 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-02-17 17:46:49 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-02-17 17:46:48 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-02-17 17:46:48 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-02-17 17:46:48 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-02-17 17:46:47 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-02-17 17:46:47 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-02-17 17:46:47 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-02-17 17:46:47 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-02-17 17:46:46 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-02-17 17:46:45 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-02-17 17:46:45 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\wininet.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\msrating.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-02-17 17:46:44 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-02-17 17:46:43 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-02-17 17:46:07 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-02-17 17:46:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-02-17 17:46:06 ----A---- C:\WINDOWS\system32\twinui.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-02-17 17:46:05 ----A---- C:\WINDOWS\system32\propsys.dll
2014-02-17 17:45:35 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-02-17 17:45:35 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-02-17 17:45:27 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2014-02-17 17:45:27 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\XpsGdiConverter.dll
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\win32k.sys
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2014-02-17 17:45:27 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2014-02-17 17:45:26 ----A---- C:\WINDOWS\system32\shell32.dll
2014-02-17 17:45:25 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-02-17 17:45:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2014-02-17 17:45:23 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\SYSWOW64\XpsGdiConverter.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\SYSWOW64\WSClient.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\SYSWOW64\OEMLicense.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\system32\WSClient.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\system32\OEMLicense.dll
2014-02-17 17:45:21 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-02-17 17:45:20 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-02-17 17:45:20 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\schedsvc.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\ReAgent.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\mfsvr.dll
2014-02-17 17:45:19 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2014-02-17 17:45:18 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\system32\pnrpsvc.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2014-02-17 17:45:18 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2014-02-17 17:45:16 ----A---- C:\WINDOWS\system32\hal.dll
2014-02-17 17:45:15 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-02-17 17:45:15 ----A---- C:\WINDOWS\system32\reseteng.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\sti.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\easinvoker.exe
2014-02-17 17:45:14 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2014-02-17 17:45:13 ----A---- C:\WINDOWS\SYSWOW64\sti.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\SYSWOW64\easwrt.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\system32\easwrt.dll
2014-02-17 17:45:13 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2014-02-17 17:45:12 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-02-17 17:45:12 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-02-17 17:45:07 ----A---- C:\WINDOWS\system32\winbici.dll
2014-02-17 17:45:07 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-02-17 17:45:07 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-02-17 17:45:06 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-02-17 17:44:40 ----A---- C:\WINDOWS\SYSWOW64\pcaui.exe
2014-02-17 17:44:40 ----A---- C:\WINDOWS\system32\pcaui.exe
2014-02-17 17:30:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-02-09 23:37:50 ----D---- C:\Users\Janek\AppData\Roaming\Mp3tag
2014-02-09 23:37:29 ----D---- C:\Program Files (x86)\Mp3tag
2014-02-09 01:10:51 ----D---- C:\FFOutput
2014-02-09 01:09:44 ----D---- C:\Program Files (x86)\FreeTime
2014-02-07 18:42:18 ----D---- C:\Users\Janek\AppData\Roaming\AIMP3
2014-02-07 18:42:15 ----D---- C:\Program Files (x86)\AIMP3
2014-02-07 12:39:35 ----D---- C:\Users\Janek\AppData\Roaming\COWON
2014-02-07 12:31:13 ----D---- C:\Users\Janek\AppData\Roaming\Systweak
2014-02-04 18:05:51 ----D---- C:\iBTWU
2014-02-04 17:32:02 ----D---- C:\WINDOWS\WindowsMobile
2014-02-04 12:02:29 ----D---- C:\ProgramData\Orbit
2014-02-04 11:53:44 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrB.exe
2014-02-04 11:53:42 ----A---- C:\WINDOWS\SYSWOW64\PnkBstrA.exe
2014-02-03 18:03:21 ----D---- C:\Program Files\Realtek
2014-02-03 18:02:08 ----A---- C:\WINDOWS\system32\WavesGUILib64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSWOW64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSTSX64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSTSH64.dll
2014-02-03 18:02:07 ----A---- C:\WINDOWS\system32\SRSHP64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\SYSWOW64\SFCOM.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFSS_APO.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFNHK64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFCOM64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\SFAPO64.dll
2014-02-03 18:02:05 ----A---- C:\WINDOWS\system32\drivers\rtvienna.dat
2014-02-03 18:02:04 ----A---- C:\WINDOWS\system32\RtPgEx64.dll
2014-02-03 18:02:04 ----A---- C:\WINDOWS\system32\RtlCPAPI64.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\RtkGuiCompLib.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\RtkCoLDR64.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\RtkCfg64.dll
2014-02-03 18:02:03 ----A---- C:\WINDOWS\system32\drivers\RTKVHD64.sys
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RtkAPO64.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RtkApi64.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEEP64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEEL64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEEG64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RTEED64A.dll
2014-02-03 18:02:02 ----A---- C:\WINDOWS\system32\RtDataProc64.dll
2014-02-03 18:02:01 ----A---- C:\WINDOWS\system32\RTCOM64.dll
2014-02-03 18:02:01 ----A---- C:\WINDOWS\system32\drivers\RTAIODAT.DAT
2014-02-03 18:02:00 ----A---- C:\WINDOWS\system32\RP3DHT64.dll
2014-02-03 18:02:00 ----A---- C:\WINDOWS\system32\RP3DAA64.dll
2014-02-03 18:01:59 ----A---- C:\WINDOWS\system32\RCoRes64.dat
2014-02-03 18:01:59 ----A---- C:\WINDOWS\system32\RCoInstII64.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEP64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEL64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEG64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EED64A.dll
2014-02-03 18:01:58 ----A---- C:\WINDOWS\system32\R4EEA64A.dll
2014-02-03 18:01:56 ----A---- C:\WINDOWS\system32\MaxxVolumeSDAPO.dll
2014-02-03 18:01:48 ----A---- C:\WINDOWS\system32\MaxxAudioRealtek64.dll
2014-02-03 18:01:45 ----A---- C:\WINDOWS\system32\MaxxAudioRealtek264.dll
2014-02-03 18:01:43 ----A---- C:\WINDOWS\system32\MaxxAudioEQ64.dll
2014-02-03 18:01:41 ----A---- C:\WINDOWS\system32\MaxxAudioAPOShell64.dll
2014-02-03 18:01:39 ----A---- C:\WINDOWS\system32\MaxxAudioAPO30.dll
2014-02-03 18:01:39 ----A---- C:\WINDOWS\system32\MaxxAudioAPO20.dll
2014-02-03 18:01:21 ----A---- C:\WINDOWS\system32\FMAPO64.dll
2014-02-03 18:01:18 ----A---- C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2014-02-03 18:01:17 ----A---- C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2014-02-03 18:01:16 ----A---- C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2014-02-03 18:01:15 ----A---- C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2014-02-03 18:01:14 ----A---- C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2014-02-03 18:01:14 ----A---- C:\WINDOWS\system32\DTSLimiterDLL64.dll
2014-02-03 18:01:12 ----A---- C:\WINDOWS\system32\DTSLFXAPO64.dll
2014-02-03 18:01:12 ----A---- C:\WINDOWS\system32\DTSGFXAPONS64.dll
2014-02-03 18:01:12 ----A---- C:\WINDOWS\system32\DTSGFXAPO64.dll
2014-02-03 18:01:11 ----A---- C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2014-02-03 18:01:11 ----A---- C:\WINDOWS\system32\DTSBoostDLL64.dll
2014-02-03 18:01:10 ----A---- C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2014-02-03 18:01:06 ----A---- C:\WINDOWS\system32\DDPP64A.dll
2014-02-03 18:01:06 ----A---- C:\WINDOWS\system32\DDPO64A.dll
2014-02-03 18:01:05 ----A---- C:\WINDOWS\system32\DDPD64A.dll
2014-02-03 18:01:05 ----A---- C:\WINDOWS\system32\DDPA64.dll
2014-02-03 18:01:04 ----A---- C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2014-02-03 18:01:01 ----A---- C:\WINDOWS\system32\AERTAR64.dll
2014-02-03 18:01:01 ----A---- C:\WINDOWS\system32\AERTAC64.dll
2014-02-03 18:00:49 ----A---- C:\WINDOWS\RtlExUpd.dll
2014-02-03 17:44:52 ----D---- C:\Program Files (x86)\SlimDrivers
2014-02-03 17:34:09 ----D---- C:\Program Files (x86)\Shai Raiten
2014-02-03 13:19:12 ----D---- C:\Program Files (x86)\Resource Hacker
2014-01-29 23:53:47 ----D---- C:\ProgramData\dbg
2014-01-29 23:53:44 ----D---- C:\AeroGlass
2014-01-27 00:19:40 ----D---- C:\Program Files\Classic Shell
2014-01-26 16:40:18 ----D---- C:\Users\Janek\AppData\Roaming\newnext.me
2014-01-26 16:38:07 ----D---- C:\Users\Janek\AppData\Roaming\GoforFiles
2014-01-26 14:02:27 ----D---- C:\ProgramData\Stardock
2014-01-26 14:02:27 ----A---- C:\WINDOWS\system32\wbload.dll
2014-01-24 23:03:34 ----D---- C:\ProgramData\IDMComp
2014-01-24 23:03:32 ----D---- C:\Users\Janek\AppData\Roaming\IDMComp
2014-01-24 19:22:58 ----D---- C:\Users\Janek\AppData\Roaming\Hex-Rays
2014-01-22 08:52:10 ----A---- C:\WINDOWS\system32\drivers\ssudmdm.sys
2014-01-22 08:52:10 ----A---- C:\WINDOWS\system32\drivers\ssudbus.sys
2014-01-21 23:47:06 ----D---- C:\Users\Janek\AppData\Roaming\Rainmeter
2014-01-21 23:46:44 ----D---- C:\Program Files\Rainmeter
2014-01-21 00:56:09 ----D---- C:\ProgramData\Codemasters
2014-01-21 00:56:07 ----D---- C:\ProgramData\Steam
2014-01-20 21:15:38 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-01-20 21:15:38 ----D---- C:\WINDOWS\system32\NV
2014-01-20 21:11:39 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2014-01-20 21:11:39 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2014-01-20 21:11:38 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2014-01-20 21:11:38 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2014-01-20 21:11:37 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2014-01-20 21:11:37 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2014-01-20 21:07:07 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2014-01-20 21:07:07 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2014-01-20 21:07:07 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2014-01-20 21:07:06 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2014-01-20 21:07:06 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvopencl.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-01-20 21:07:05 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvcuvenc.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvdispgenco6433221.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvdispco6433221.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2014-01-20 21:07:03 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\system32\nvcuda.dll
2014-01-20 21:07:02 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2014-01-20 20:38:08 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2014-01-20 20:38:08 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2014-01-20 20:38:07 ----A---- C:\WINDOWS\system32\combase.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\system32\mfcore.dll
2014-01-20 20:38:06 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-01-20 20:38:05 ----A---- C:\WINDOWS\system32\authui.dll
2014-01-20 20:38:04 ----A---- C:\WINDOWS\system32\wlansvc.dll
2014-01-20 20:38:04 ----A---- C:\WINDOWS\system32\winmde.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\system32\wmpmde.dll
2014-01-20 20:38:03 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2014-01-20 20:38:02 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\ubpm.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\ploptin.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\oleaut32.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\mfds.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-01-20 20:38:02 ----A---- C:\WINDOWS\system32\audiosrv.dll
2014-01-20 20:38:01 ----AC---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2014-01-20 20:38:01 ----AC---- C:\WINDOWS\system32\drivers\BtaMPM.sys
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\msieftp.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\Windows.Graphics.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\rastls.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\psmsrv.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\msieftp.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\mispace.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\drivers\ipnat.sys
2014-01-20 20:38:01 ----A---- C:\WINDOWS\system32\bi.dll
2014-01-20 20:38:00 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2014-01-20 20:38:00 ----A---- C:\WINDOWS\system32\deviceregistration.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\WSService.dll
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\WSCollect.exe
2014-01-20 20:36:18 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-20 20:36:09 ----A---- C:\WINDOWS\system32\uDWM.dll
2014-01-18 17:12:06 ----A---- C:\WINDOWS\system32\StartMenuHelper64.dll
2014-01-18 17:12:00 ----A---- C:\WINDOWS\SYSWOW64\StartMenuHelper32.dll