
Logfile of random's system information tool 1.09 (written by random/random)
Run by Home at 2012-03-13 18:15:29
Microsoft Windows 7 Home Premium
System drive C: has 130 GB (85%) free of 153 GB
Total RAM: 2038 MB (51% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4158525814-4002186199-1212276968-1000Core.job
C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4158525814-4002186199-1212276968-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\plukzznd.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
fcmdSrch.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\plukzznd.default\extensions\
ffxtlbr@Facemoods.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64182481-4F71-486b-A045-B233BD0DA8FC}]
CescrtHlpr Object - C:\Program Files\facemoods.com\facemoods\1.4.17.11\bh\facemoods.dll [2011-10-10 265944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-12-22 57224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - facemoods Toolbar - C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodsTlbr.dll [2011-10-10 220888]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-05-04 252136]
"facemoods"=C:\Program Files\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe [2011-10-10 362200]
"COMODO"=C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe [2011-11-23 208184]
"CPA"=C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe [2011-11-23 182584]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2012-03-11 6749512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"=C:\Users\Home\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-28 137536]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-10-13 17762440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" C:\Windows\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"msacm.l3fhg"=mp3fhg.acm
"VIDC.XVID"=xvidvfw.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-03-13 18:15:38 ----D---- C:\Program Files\trend micro
2012-03-13 18:15:29 ----D---- C:\rsit
2012-03-13 10:06:30 ----HD---- C:\VritualRoot
2012-03-13 08:49:50 ----D---- C:\ProgramData\CPA_VA
2012-03-13 08:36:06 ----A---- C:\Windows\system32\drivers\sfi.dat
2012-03-13 08:21:54 ----D---- C:\ProgramData\Comodo
2012-03-13 08:21:01 ----D---- C:\Program Files\Comodo
2012-03-13 08:19:41 ----A---- C:\Windows\system32\msvcr71.dll
2012-03-13 08:19:41 ----A---- C:\Windows\system32\mfc71.dll
2012-03-13 08:19:41 ----A---- C:\Windows\system32\gdiplus.dll
2012-03-13 07:58:56 ----D---- C:\Program Files\7-Zip
2012-03-13 07:51:22 ----D---- C:\Users\Home\AppData\Roaming\WinRAR
2012-03-13 07:50:43 ----D---- C:\Program Files\WinRAR
2012-03-13 07:17:37 ----D---- C:\Users\Home\AppData\Roaming\TeamViewer
2012-03-12 15:46:20 ----A---- C:\Windows\system32\FNTCACHE.DAT
2012-03-12 08:19:35 ----D---- C:\Program Files\TeamViewer
2012-03-11 21:13:38 ----A---- C:\Windows\system32\drivers\cmdhlp.sys
2012-03-11 21:13:36 ----A---- C:\Windows\system32\drivers\cmdGuard.sys
2012-03-11 21:13:36 ----A---- C:\Windows\system32\drivers\cmderd.sys
2012-03-11 21:13:20 ----A---- C:\Windows\system32\guard32.dll
2012-03-11 21:13:20 ----A---- C:\Windows\system32\cmdcsr.dll
2012-03-10 08:08:54 ----D---- C:\Users\Home\AppData\Roaming\Skype
2012-03-10 08:07:50 ----D---- C:\Program Files\Common Files\Skype
2012-03-10 08:07:36 ----RD---- C:\Program Files\Skype
2012-03-10 08:07:34 ----D---- C:\ProgramData\Skype
2012-03-06 21:19:27 ----D---- C:\Program Files\facemoods.com
2012-02-28 17:36:00 ----D---- C:\Users\Home\AppData\Roaming\EurotranXP3
2012-02-24 15:39:53 ----D---- C:\Windows\Minidump
======List of files/folders modified in the last 1 month======
2012-03-13 18:15:38 ----RD---- C:\Program Files
2012-03-13 15:40:25 ----D---- C:\Windows\system32\config
2012-03-13 15:33:13 ----D---- C:\Windows\Temp
2012-03-13 09:42:20 ----D---- C:\Windows\Prefetch
2012-03-13 08:49:50 ----HD---- C:\ProgramData
2012-03-13 08:47:18 ----D---- C:\ProgramData\AVAST Software
2012-03-13 08:47:16 ----D---- C:\Windows
2012-03-13 08:37:59 ----SHD---- C:\Windows\Installer
2012-03-13 08:36:06 ----D---- C:\Windows\system32\drivers
2012-03-13 08:35:53 ----D---- C:\Windows\inf
2012-03-13 08:35:40 ----D---- C:\Windows\system32\catroot
2012-03-13 08:35:31 ----D---- C:\Windows\system32\DriverStore
2012-03-13 08:35:07 ----SHD---- C:\System Volume Information
2012-03-13 08:22:32 ----D---- C:\Windows\System32
2012-03-12 08:58:15 ----D---- C:\ProgramData\Spybot - Search & Destroy
2012-03-12 08:49:08 ----D---- C:\Windows\debug
2012-03-11 17:28:46 ----D---- C:\Windows\system32\Tasks
2012-03-10 17:55:45 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-03-10 08:07:50 ----D---- C:\Program Files\Common Files
2012-02-28 18:00:18 ----D---- C:\Windows\Tasks
2012-02-23 09:18:36 ----N---- C:\Windows\system32\MpSigStub.exe
2012-02-19 15:27:15 ----D---- C:\Program Files\Mozilla Firefox
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2012-03-11 19600]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2012-03-11 491816]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2012-03-11 39640]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2012-02-03 82400]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2009-07-13 43008]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CLPSLS;COMODO livePCsupport Service; C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1052472]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2012-03-11 1983232]
R2 TeamViewer7;TeamViewer 7; C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe [2012-02-23 2886528]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-22 1343400]
-----------------EOF-----------------