Kontrola po zachytenej infiltrácii
Napsal: 06 dub 2010 18:15
Dnes som dostal cez MSN link na ktorý som po kliknutí namiesto fotiek z oslavy dostal "darček", neviem ako sa tam dostal niekto tretí kto mi to poslal, ale teraz mi skôr ide o to že aj keď to MSE zachytil, rád by som vedel či predsa len dačo neostalo. Najprv sa ma chrome opýtal či má ten súbor stiahnuť, dal som nie ale chrome sťahuje súbory už pri tom okne takže sa do cache dostalo trochu z darčeku. Mohol by mi niekto skontrolovať či niečo neostalo? PC som kontroloval Spybotom, Spyware terminatorom a MSE, našli iba nejaké cookies a podobné blbosti.
MSE vírus označilo takto:

A tu je log
Logfile of random's system information tool 1.06 (written by random/random)
Run by Filip at 2010-04-06 19:10:21
Microsoft Windows 7 Ultimate Service Pack 3
System drive C: has 29 GB (10%) free of 305 GB
Total RAM: 2047 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:11:42, on 6. 4. 2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Filip\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Pidgin\pidgin.exe
C:\Program Files (x86)\Voipwise.com\Voipwise\voipwise.exe
C:\Users\Filip\AppData\Local\Microsoft\Live Mesh\GacBase\Moe.exe
C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\Documents\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Filip.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Google Update] "C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Users\Filip\AppData\Local\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe"
O4 - HKCU\..\Run: [KeePass Password Safe 2] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Pidgin] C:\Program Files (x86)\Pidgin\pidgin.exe
O4 - HKCU\..\Run: [Voipwise] "C:\Program Files (x86)\Voipwise.com\Voipwise\Voipwise.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird" -turbo
O4 - HKCU\..\Run: [Rapget.RS] C:\Users\Filip\Documents\Downloads\Rapget.RS_Public_v1.0.4.0_cz\RapgetRS.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.co ... 1.71.0.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {82CF9738-0BDA-4AAF-AB08-5AC5875FF3BB} - https://lms.iedu.sk/mod/hacp/runtime2/r ... ording.cab
O16 - DPF: {A3E21079-7F41-4125-9EBB-FD44CFCC0AC1} (WLCTSCControl Class) - https://www.mesh.com/0.9.4014.21/TSWeb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{50C172A2-88EE-441A-9C5D-247BA0E84C08}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{50C172A2-88EE-441A-9C5D-247BA0E84C08}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{50C172A2-88EE-441A-9C5D-247BA0E84C08}: NameServer = 208.67.220.220,208.67.222.222
O20 - AppInit_DLLs:
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11158 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1003UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-03-09 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2009-09-03 60928]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-25 1820040]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-22 135664]
"Steam"=c:\program files (x86)\steam\steam.exe [2010-04-03 1238352]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2009-10-09 25626408]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"MoeMonitor.exe"=C:\Users\Filip\AppData\Local\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe [2010-01-12 2149184]
"KeePass Password Safe 2"=C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2009-09-11 1473024]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-02-03 3037696]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2010-03-13 319792]
"Pidgin"=C:\Program Files (x86)\Pidgin\pidgin.exe [2010-02-16 45603]
"Voipwise"=C:\Program Files (x86)\Voipwise.com\Voipwise\Voipwise.exe [2010-03-11 9084720]
"Thunderbird"=C:\Program Files (x86)\Mozilla Thunderbird\thunderbird -turbo []
"Rapget.RS"=C:\Users\Filip\Documents\Downloads\Rapget.RS_Public_v1.0.4.0_cz\RapgetRS.exe [2009-06-19 1184936]
C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f237b7ff-faf9-11de-a98d-00e012345678}]
shell\AutoRun\command - F:\Razor1911_Installer.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-04-06 19:10:22 ----D---- C:\Program Files (x86)\trend micro
2010-04-06 19:10:21 ----D---- C:\rsit
2010-04-05 20:17:45 ----D---- C:\ProgramData\TrackMania
2010-04-03 21:48:06 ----D---- C:\Users\Filip\AppData\Roaming\Braid
2010-04-02 18:44:44 ----D---- C:\ProgramData\Sun
2010-04-02 18:44:43 ----D---- C:\Program Files (x86)\Common Files\Java
2010-04-02 18:44:20 ----A---- C:\Windows\system32\javaws.exe
2010-04-02 18:44:19 ----A---- C:\Windows\system32\javaw.exe
2010-04-02 18:44:19 ----A---- C:\Windows\system32\java.exe
2010-04-02 15:00:35 ----D---- C:\ProgramData\vsosdk
2010-04-02 14:11:30 ----A---- C:\Users\Filip\AppData\Roaming\inst.exe
2010-04-02 14:11:20 ----A---- C:\Windows\system32\vp7vfw.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\sipr3260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\drv43260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\drv33260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\drv23260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\cook3260.dll
2010-04-02 14:11:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-04-01 20:43:51 ----D---- C:\ProgramData\FLEXnet
2010-04-01 20:30:57 ----D---- C:\Windows\system32\spool
2010-04-01 20:30:18 ----D---- C:\Program Files (x86)\Adobe Media Player
2010-04-01 20:28:15 ----D---- C:\Program Files (x86)\Common Files\Adobe AIR
2010-04-01 09:14:21 ----D---- C:\Program Files (x86)\EMDB
2010-03-31 10:23:50 ----A---- C:\Windows\system32\rmoc3260.dll
2010-03-31 10:23:50 ----A---- C:\Windows\system32\pndx5032.dll
2010-03-31 10:23:50 ----A---- C:\Windows\system32\pndx5016.dll
2010-03-31 10:23:50 ----A---- C:\Windows\system32\pncrt.dll
2010-03-31 10:23:49 ----D---- C:\Users\Filip\AppData\Roaming\Real
2010-03-31 10:23:49 ----D---- C:\ProgramData\Real
2010-03-31 10:23:49 ----D---- C:\Program Files (x86)\Real Alternative
2010-03-30 20:39:20 ----D---- C:\ProgramData\RoboForm
2010-03-30 16:53:21 ----D---- C:\Users\Filip\AppData\Roaming\KASTNER software
2010-03-30 14:53:33 ----D---- C:\Program Files (x86)\XTB-Trader
2010-03-29 16:49:18 ----D---- C:\Users\Filip\AppData\Roaming\NVIDIA
2010-03-29 16:40:13 ----A---- C:\Windows\system32\OpenCL.dll
2010-03-29 16:40:13 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-03-29 16:40:11 ----A---- C:\Windows\system32\nvoglv32.dll
2010-03-29 16:40:11 ----A---- C:\Windows\system32\nvencodemft.dll
2010-03-29 16:40:11 ----A---- C:\Windows\system32\nvdecodemft.dll
2010-03-29 16:40:10 ----A---- C:\Windows\system32\nvcuvid.dll
2010-03-29 16:40:10 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-03-29 16:40:08 ----A---- C:\Windows\system32\nvcuda.dll
2010-03-29 16:40:08 ----A---- C:\Windows\system32\nvcompiler.dll
2010-03-29 16:40:08 ----A---- C:\Windows\system32\nvapi.dll
2010-03-29 16:16:22 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2010-03-29 15:36:29 ----A---- C:\Windows\system32\XAudio2_6.dll
2010-03-29 15:36:29 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2010-03-29 15:36:29 ----A---- C:\Windows\system32\xactengine3_6.dll
2010-03-29 15:36:29 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2010-03-28 14:47:33 ----D---- C:\Users\Filip\AppData\Roaming\OpenDNS Updater
2010-03-26 16:58:56 ----D---- C:\Program Files (x86)\Microsoft Games
2010-03-26 16:58:05 ----D---- C:\ProgramData\Microsoft Games
2010-03-26 16:57:20 ----D---- C:\Users\Filip\AppData\Roaming\Microsoft Game Studios
2010-03-24 19:41:40 ----D---- C:\Users\Filip\AppData\Roaming\KDE
2010-03-23 23:01:39 ----D---- C:\Users\Filip\AppData\Roaming\VSO
2010-03-23 23:01:21 ----D---- C:\Program Files (x86)\VSO
2010-03-23 18:42:47 ----A---- C:\Program Files (x86)\README_win32_ja.txt
2010-03-23 18:42:47 ----A---- C:\Program Files (x86)\README_win32_en.txt
2010-03-23 18:42:47 ----A---- C:\Program Files (x86)\pidgin-twitter.dll
2010-03-23 15:53:47 ----D---- C:\Users\Filip\AppData\Roaming\Opera
2010-03-23 15:53:34 ----D---- C:\Program Files (x86)\Opera
2010-03-22 22:08:10 ----D---- C:\ProgramData\Last.fm
2010-03-22 22:07:34 ----D---- C:\Program Files (x86)\Last.fm
2010-03-22 21:47:00 ----D---- C:\Users\Filip\AppData\Roaming\Instantbird
2010-03-22 21:35:27 ----D---- C:\Program Files (x86)\GTK2-Runtime
2010-03-20 18:10:35 ----D---- C:\Users\Filip\AppData\Roaming\Bioshock2
2010-03-20 18:08:42 ----D---- C:\Windows\system32\xlive
2010-03-20 18:08:42 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2010-03-20 17:45:21 ----D---- C:\Program Files (x86)\BioShock 2
2010-03-19 13:55:54 ----D---- C:\Users\Filip\AppData\Roaming\Ubisoft
2010-03-19 13:55:54 ----D---- C:\ProgramData\Ubisoft
2010-03-17 19:40:59 ----D---- C:\Program Files (x86)\TagRename
2010-03-17 15:28:36 ----A---- C:\Windows\ODBC.INI
2010-03-17 15:28:15 ----D---- C:\Windows\system32\js
2010-03-17 15:28:15 ----D---- C:\Windows\system32\images
2010-03-17 15:28:15 ----D---- C:\Windows\system32\html
2010-03-17 15:28:15 ----D---- C:\Windows\system32\css
2010-03-17 15:28:15 ----D---- C:\Program Files (x86)\Business Objects
2010-03-17 15:24:18 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2010-03-17 15:24:02 ----D---- C:\Program Files (x86)\Microsoft Device Emulator
2010-03-17 15:23:13 ----D---- C:\Program Files (x86)\Windows Mobile 5.0 SDK R2
2010-03-17 15:22:50 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2010-03-17 15:16:52 ----D---- C:\ProgramData\PreEmptive Solutions
2010-03-17 15:14:25 ----D---- C:\Windows\symbols
2010-03-17 15:14:10 ----D---- C:\Windows\system32\1033
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\Microsoft SDKs
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\HTML Help Workshop
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\Common Files\Merge Modules
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\CE Remote Tools
2010-03-17 15:10:54 ----D---- C:\Program Files (x86)\Microsoft Web Designer Tools
2010-03-16 20:56:21 ----D---- C:\Users\Filip\AppData\Roaming\GameRanger
2010-03-16 17:24:55 ----D---- C:\MinGW
2010-03-16 16:45:44 ----D---- C:\Program Files (x86)\Adobe
2010-03-16 14:24:54 ----D---- C:\Users\Filip\AppData\Roaming\Nokia
2010-03-16 14:24:07 ----D---- C:\Qt
2010-03-13 17:35:21 ----D---- C:\Program Files (x86)\Codemasters
2010-03-13 17:34:08 ----D---- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2010-03-13 12:56:29 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2010-03-12 19:57:50 ----D---- C:\Program Files (x86)\Microsoft Research
2010-03-12 16:25:59 ----D---- C:\Program Files (x86)\VirtualDJ
2010-03-11 18:22:41 ----D---- C:\Users\Filip\AppData\Roaming\Voipwise
2010-03-11 18:22:13 ----D---- C:\Program Files (x86)\Voipwise.com
2010-03-08 18:01:45 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-03-08 18:01:42 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-03-08 18:01:42 ----A---- C:\Windows\system32\pbsvc_bc2.exe
2010-03-08 17:51:43 ----D---- C:\Program Files (x86)\Electronic Arts
2010-03-07 11:21:49 ----D---- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
MSE vírus označilo takto:

A tu je log
Logfile of random's system information tool 1.06 (written by random/random)
Run by Filip at 2010-04-06 19:10:21
Microsoft Windows 7 Ultimate Service Pack 3
System drive C: has 29 GB (10%) free of 305 GB
Total RAM: 2047 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:11:42, on 6. 4. 2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Filip\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files (x86)\Pidgin\pidgin.exe
C:\Program Files (x86)\Voipwise.com\Voipwise\voipwise.exe
C:\Users\Filip\AppData\Local\Microsoft\Live Mesh\GacBase\Moe.exe
C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Filip\Documents\Downloads\RSIT.exe
C:\Program Files (x86)\trend micro\Filip.exe
C:\Users\Filip\AppData\Local\Google\Chrome\Application\chrome.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Google Update] "C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Users\Filip\AppData\Local\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe"
O4 - HKCU\..\Run: [KeePass Password Safe 2] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Pidgin] C:\Program Files (x86)\Pidgin\pidgin.exe
O4 - HKCU\..\Run: [Voipwise] "C:\Program Files (x86)\Voipwise.com\Voipwise\Voipwise.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Thunderbird] "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird" -turbo
O4 - HKCU\..\Run: [Rapget.RS] C:\Users\Filip\Documents\Downloads\Rapget.RS_Public_v1.0.4.0_cz\RapgetRS.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.co ... 1.71.0.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... ab_nvd.cab
O16 - DPF: {82CF9738-0BDA-4AAF-AB08-5AC5875FF3BB} - https://lms.iedu.sk/mod/hacp/runtime2/r ... ording.cab
O16 - DPF: {A3E21079-7F41-4125-9EBB-FD44CFCC0AC1} (WLCTSCControl Class) - https://www.mesh.com/0.9.4014.21/TSWeb.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{50C172A2-88EE-441A-9C5D-247BA0E84C08}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{50C172A2-88EE-441A-9C5D-247BA0E84C08}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{50C172A2-88EE-441A-9C5D-247BA0E84C08}: NameServer = 208.67.220.220,208.67.222.222
O20 - AppInit_DLLs:
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files (x86)\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files (x86)\Spyware Terminator\sp_rsser.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11158 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1000UA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1003Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2400927823-3852806677-1213962376-1003UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~2\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-03-09 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"ioCentre"=C:\Genius\ioCentre\gTaskBar.exe [2009-09-03 60928]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-25 1820040]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-22 135664]
"Steam"=c:\program files (x86)\steam\steam.exe [2010-04-03 1238352]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2009-10-09 25626408]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"MoeMonitor.exe"=C:\Users\Filip\AppData\Local\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe [2010-01-12 2149184]
"KeePass Password Safe 2"=C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2009-09-11 1473024]
"SpywareTerminatorUpdate"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-02-03 3037696]
"uTorrent"=C:\Program Files (x86)\uTorrent\uTorrent.exe [2010-03-13 319792]
"Pidgin"=C:\Program Files (x86)\Pidgin\pidgin.exe [2010-02-16 45603]
"Voipwise"=C:\Program Files (x86)\Voipwise.com\Voipwise\Voipwise.exe [2010-03-11 9084720]
"Thunderbird"=C:\Program Files (x86)\Mozilla Thunderbird\thunderbird -turbo []
"Rapget.RS"=C:\Users\Filip\Documents\Downloads\Rapget.RS_Public_v1.0.4.0_cz\RapgetRS.exe [2009-06-19 1184936]
C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Filip\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=
"NoActiveDesktopChanges"=
"ForceActiveDesktopOn"=
"NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f237b7ff-faf9-11de-a98d-00e012345678}]
shell\AutoRun\command - F:\Razor1911_Installer.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-04-06 19:10:22 ----D---- C:\Program Files (x86)\trend micro
2010-04-06 19:10:21 ----D---- C:\rsit
2010-04-05 20:17:45 ----D---- C:\ProgramData\TrackMania
2010-04-03 21:48:06 ----D---- C:\Users\Filip\AppData\Roaming\Braid
2010-04-02 18:44:44 ----D---- C:\ProgramData\Sun
2010-04-02 18:44:43 ----D---- C:\Program Files (x86)\Common Files\Java
2010-04-02 18:44:20 ----A---- C:\Windows\system32\javaws.exe
2010-04-02 18:44:19 ----A---- C:\Windows\system32\javaw.exe
2010-04-02 18:44:19 ----A---- C:\Windows\system32\java.exe
2010-04-02 15:00:35 ----D---- C:\ProgramData\vsosdk
2010-04-02 14:11:30 ----A---- C:\Users\Filip\AppData\Roaming\inst.exe
2010-04-02 14:11:20 ----A---- C:\Windows\system32\vp7vfw.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\sipr3260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\drv43260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\drv33260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\drv23260.dll
2010-04-02 14:11:20 ----A---- C:\Windows\system32\cook3260.dll
2010-04-02 14:11:19 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-04-01 20:43:51 ----D---- C:\ProgramData\FLEXnet
2010-04-01 20:30:57 ----D---- C:\Windows\system32\spool
2010-04-01 20:30:18 ----D---- C:\Program Files (x86)\Adobe Media Player
2010-04-01 20:28:15 ----D---- C:\Program Files (x86)\Common Files\Adobe AIR
2010-04-01 09:14:21 ----D---- C:\Program Files (x86)\EMDB
2010-03-31 10:23:50 ----A---- C:\Windows\system32\rmoc3260.dll
2010-03-31 10:23:50 ----A---- C:\Windows\system32\pndx5032.dll
2010-03-31 10:23:50 ----A---- C:\Windows\system32\pndx5016.dll
2010-03-31 10:23:50 ----A---- C:\Windows\system32\pncrt.dll
2010-03-31 10:23:49 ----D---- C:\Users\Filip\AppData\Roaming\Real
2010-03-31 10:23:49 ----D---- C:\ProgramData\Real
2010-03-31 10:23:49 ----D---- C:\Program Files (x86)\Real Alternative
2010-03-30 20:39:20 ----D---- C:\ProgramData\RoboForm
2010-03-30 16:53:21 ----D---- C:\Users\Filip\AppData\Roaming\KASTNER software
2010-03-30 14:53:33 ----D---- C:\Program Files (x86)\XTB-Trader
2010-03-29 16:49:18 ----D---- C:\Users\Filip\AppData\Roaming\NVIDIA
2010-03-29 16:40:13 ----A---- C:\Windows\system32\OpenCL.dll
2010-03-29 16:40:13 ----A---- C:\Windows\system32\nvwgf2um.dll
2010-03-29 16:40:11 ----A---- C:\Windows\system32\nvoglv32.dll
2010-03-29 16:40:11 ----A---- C:\Windows\system32\nvencodemft.dll
2010-03-29 16:40:11 ----A---- C:\Windows\system32\nvdecodemft.dll
2010-03-29 16:40:10 ----A---- C:\Windows\system32\nvcuvid.dll
2010-03-29 16:40:10 ----A---- C:\Windows\system32\nvcuvenc.dll
2010-03-29 16:40:08 ----A---- C:\Windows\system32\nvcuda.dll
2010-03-29 16:40:08 ----A---- C:\Windows\system32\nvcompiler.dll
2010-03-29 16:40:08 ----A---- C:\Windows\system32\nvapi.dll
2010-03-29 16:16:22 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2010-03-29 15:36:29 ----A---- C:\Windows\system32\XAudio2_6.dll
2010-03-29 15:36:29 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2010-03-29 15:36:29 ----A---- C:\Windows\system32\xactengine3_6.dll
2010-03-29 15:36:29 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2010-03-28 14:47:33 ----D---- C:\Users\Filip\AppData\Roaming\OpenDNS Updater
2010-03-26 16:58:56 ----D---- C:\Program Files (x86)\Microsoft Games
2010-03-26 16:58:05 ----D---- C:\ProgramData\Microsoft Games
2010-03-26 16:57:20 ----D---- C:\Users\Filip\AppData\Roaming\Microsoft Game Studios
2010-03-24 19:41:40 ----D---- C:\Users\Filip\AppData\Roaming\KDE
2010-03-23 23:01:39 ----D---- C:\Users\Filip\AppData\Roaming\VSO
2010-03-23 23:01:21 ----D---- C:\Program Files (x86)\VSO
2010-03-23 18:42:47 ----A---- C:\Program Files (x86)\README_win32_ja.txt
2010-03-23 18:42:47 ----A---- C:\Program Files (x86)\README_win32_en.txt
2010-03-23 18:42:47 ----A---- C:\Program Files (x86)\pidgin-twitter.dll
2010-03-23 15:53:47 ----D---- C:\Users\Filip\AppData\Roaming\Opera
2010-03-23 15:53:34 ----D---- C:\Program Files (x86)\Opera
2010-03-22 22:08:10 ----D---- C:\ProgramData\Last.fm
2010-03-22 22:07:34 ----D---- C:\Program Files (x86)\Last.fm
2010-03-22 21:47:00 ----D---- C:\Users\Filip\AppData\Roaming\Instantbird
2010-03-22 21:35:27 ----D---- C:\Program Files (x86)\GTK2-Runtime
2010-03-20 18:10:35 ----D---- C:\Users\Filip\AppData\Roaming\Bioshock2
2010-03-20 18:08:42 ----D---- C:\Windows\system32\xlive
2010-03-20 18:08:42 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2010-03-20 17:45:21 ----D---- C:\Program Files (x86)\BioShock 2
2010-03-19 13:55:54 ----D---- C:\Users\Filip\AppData\Roaming\Ubisoft
2010-03-19 13:55:54 ----D---- C:\ProgramData\Ubisoft
2010-03-17 19:40:59 ----D---- C:\Program Files (x86)\TagRename
2010-03-17 15:28:36 ----A---- C:\Windows\ODBC.INI
2010-03-17 15:28:15 ----D---- C:\Windows\system32\js
2010-03-17 15:28:15 ----D---- C:\Windows\system32\images
2010-03-17 15:28:15 ----D---- C:\Windows\system32\html
2010-03-17 15:28:15 ----D---- C:\Windows\system32\css
2010-03-17 15:28:15 ----D---- C:\Program Files (x86)\Business Objects
2010-03-17 15:24:18 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2010-03-17 15:24:02 ----D---- C:\Program Files (x86)\Microsoft Device Emulator
2010-03-17 15:23:13 ----D---- C:\Program Files (x86)\Windows Mobile 5.0 SDK R2
2010-03-17 15:22:50 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2010-03-17 15:16:52 ----D---- C:\ProgramData\PreEmptive Solutions
2010-03-17 15:14:25 ----D---- C:\Windows\symbols
2010-03-17 15:14:10 ----D---- C:\Windows\system32\1033
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 9.0
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\Microsoft SDKs
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\HTML Help Workshop
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\Common Files\Merge Modules
2010-03-17 15:12:52 ----D---- C:\Program Files (x86)\CE Remote Tools
2010-03-17 15:10:54 ----D---- C:\Program Files (x86)\Microsoft Web Designer Tools
2010-03-16 20:56:21 ----D---- C:\Users\Filip\AppData\Roaming\GameRanger
2010-03-16 17:24:55 ----D---- C:\MinGW
2010-03-16 16:45:44 ----D---- C:\Program Files (x86)\Adobe
2010-03-16 14:24:54 ----D---- C:\Users\Filip\AppData\Roaming\Nokia
2010-03-16 14:24:07 ----D---- C:\Qt
2010-03-13 17:35:21 ----D---- C:\Program Files (x86)\Codemasters
2010-03-13 17:34:08 ----D---- C:\Program Files (x86)\Common Files\Blizzard Entertainment
2010-03-13 12:56:29 ----D---- C:\Program Files (x86)\SystemRequirementsLab
2010-03-12 19:57:50 ----D---- C:\Program Files (x86)\Microsoft Research
2010-03-12 16:25:59 ----D---- C:\Program Files (x86)\VirtualDJ
2010-03-11 18:22:41 ----D---- C:\Users\Filip\AppData\Roaming\Voipwise
2010-03-11 18:22:13 ----D---- C:\Program Files (x86)\Voipwise.com
2010-03-08 18:01:45 ----A---- C:\Windows\system32\PnkBstrB.exe
2010-03-08 18:01:42 ----A---- C:\Windows\system32\PnkBstrA.exe
2010-03-08 18:01:42 ----A---- C:\Windows\system32\pbsvc_bc2.exe
2010-03-08 17:51:43 ----D---- C:\Program Files (x86)\Electronic Arts
2010-03-07 11:21:49 ----D---- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2