Kontrola logu z RSIT
Napsal: 01 zář 2012 15:03
Dobrý den,
do počítače se mi dostal Live Security Platinum. Prosím o kontrolu logu z RSIT.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Aleš at 2012-09-01 16:00:37
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 376 GB (83%) free of 455 GB
Total RAM: 4030 MB (80% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:00:42, on 1.9.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Safe mode with network support
Running processes:
C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Aleš\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0HOVAGNC\RSIT.exe
C:\Program Files (x86)\trend micro\Aleš.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: BS Player - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [HPConnectionManager] c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [HPQuickWebProxy] "c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe -update activex
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe
--
End of file - 14009 bytes
======Scheduled tasks folder======
C:\windows\tasks\HPCeeScheduleForALES-HP$.job
C:\windows\tasks\HPCeeScheduleForAleš.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll [2012-06-22 1136600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-02-07 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-08-02 1152760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll [2011-05-09 176936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-08-02 1152760]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll [2011-05-09 176936]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll [2012-06-22 1136600]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2011-02-07 12274688]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"DTRun"=c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2010-11-24 517456]
"HPConnectionManager"=c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]
"HPQuickWebProxy"=c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-11-10 169528]
"ISTray"=C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe [2012-06-22 2673624]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe [2012-01-02 234656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2011-05-10 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\SysWow64\webcheck.dll [2011-04-14 203776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdAuxService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdCoreService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2012-09-01 16:00:37 ----D---- C:\rsit
2012-09-01 16:00:37 ----D---- C:\Program Files (x86)\trend micro
2012-09-01 15:44:25 ----D---- C:\windows\temp
2012-09-01 15:44:23 ----A---- C:\ComboFix.txt
2012-09-01 15:39:39 ----D---- C:\$RECYCLE.BIN
2012-09-01 15:27:39 ----A---- C:\windows\zip.exe
2012-09-01 15:27:39 ----A---- C:\windows\SWSC.exe
2012-09-01 15:27:39 ----A---- C:\windows\SWREG.exe
2012-09-01 15:27:39 ----A---- C:\windows\sed.exe
2012-09-01 15:27:39 ----A---- C:\windows\PEV.exe
2012-09-01 15:27:39 ----A---- C:\windows\NIRCMD.exe
2012-09-01 15:27:39 ----A---- C:\windows\MBR.exe
2012-09-01 15:27:39 ----A---- C:\windows\grep.exe
2012-09-01 15:17:52 ----D---- C:\Qoobox
2012-09-01 15:17:38 ----D---- C:\windows\erdnt
2012-09-01 15:01:32 ----A---- C:\windows\BDTSupport.dll
2012-09-01 15:01:31 ----A---- C:\windows\SGDetectionTool.dll
2012-09-01 15:01:31 ----A---- C:\windows\PCTBDRes.dll
2012-09-01 15:01:31 ----A---- C:\windows\PCTBDCore.dll
2012-09-01 15:00:53 ----D---- C:\Program Files (x86)\PC Tools
2012-09-01 14:59:21 ----D---- C:\Program Files (x86)\Common Files\PC Tools
2012-09-01 14:59:10 ----AD---- C:\ProgramData\TEMP
2012-09-01 14:59:09 ----D---- C:\Users\Aleš\AppData\Roaming\TestApp
2012-09-01 14:59:09 ----D---- C:\ProgramData\PC Tools
2012-09-01 14:55:01 ----A---- C:\windows\ntbtlog.txt
2012-08-27 21:17:23 ----A---- C:\windows\SysWOW64\mshtmled.dll
2012-08-27 21:17:22 ----A---- C:\windows\SysWOW64\url.dll
2012-08-27 21:17:21 ----A---- C:\windows\SysWOW64\urlmon.dll
2012-08-27 21:17:21 ----A---- C:\windows\SysWOW64\ieui.dll
2012-08-27 21:17:21 ----A---- C:\windows\SysWOW64\iertutil.dll
2012-08-27 21:17:20 ----A---- C:\windows\SysWOW64\ieUnatt.exe
2012-08-27 21:17:19 ----A---- C:\windows\SysWOW64\wininet.dll
2012-08-27 21:17:18 ----A---- C:\windows\SysWOW64\jsproxy.dll
2012-08-27 21:17:18 ----A---- C:\windows\SysWOW64\jscript9.dll
2012-08-27 21:17:18 ----A---- C:\windows\SysWOW64\jscript.dll
2012-08-27 21:17:17 ----A---- C:\windows\SysWOW64\mshtml.dll
2012-08-27 21:17:15 ----A---- C:\windows\SysWOW64\ieframe.dll
2012-08-27 20:29:15 ----A---- C:\windows\SysWOW64\win32spl.dll
2012-08-27 20:29:15 ----A---- C:\windows\splwow64.exe
2012-08-27 20:29:13 ----A---- C:\windows\SysWOW64\srclient.dll
2012-08-27 20:29:11 ----A---- C:\windows\SysWOW64\netapi32.dll
2012-08-27 20:29:11 ----A---- C:\windows\SysWOW64\browcli.dll
2012-08-10 17:22:13 ----D---- C:\windows\SysWOW64\Wat
2012-08-10 15:25:27 ----A---- C:\windows\SysWOW64\wmi.dll
2012-08-10 15:25:27 ----A---- C:\windows\SysWOW64\wintrust.dll
2012-08-10 15:25:27 ----A---- C:\windows\SysWOW64\imagehlp.dll
2012-08-10 12:10:34 ----A---- C:\windows\SysWOW64\DWrite.dll
2012-08-10 12:10:32 ----A---- C:\windows\SysWOW64\poqexec.exe
2012-08-10 12:10:30 ----A---- C:\windows\SysWOW64\quartz.dll
2012-08-10 12:10:30 ----A---- C:\windows\SysWOW64\qdvd.dll
2012-08-10 12:10:28 ----A---- C:\windows\SysWOW64\ntshrui.dll
2012-08-10 12:10:27 ----A---- C:\windows\SysWOW64\webio.dll
2012-08-10 12:10:24 ----A---- C:\windows\SysWOW64\msxml6.dll
2012-08-10 12:10:24 ----A---- C:\windows\SysWOW64\msxml3r.dll
2012-08-10 12:10:24 ----A---- C:\windows\SysWOW64\msxml3.dll
2012-08-10 12:10:17 ----A---- C:\windows\SysWOW64\XpsPrint.dll
2012-08-10 12:10:14 ----A---- C:\windows\SysWOW64\shell32.dll
2012-08-10 12:10:11 ----A---- C:\windows\SysWOW64\schannel.dll
2012-08-10 12:10:10 ----A---- C:\windows\SysWOW64\sspicli.dll
2012-08-10 12:10:10 ----A---- C:\windows\SysWOW64\secur32.dll
2012-08-10 12:10:10 ----A---- C:\windows\SysWOW64\ncrypt.dll
2012-08-10 12:10:04 ----A---- C:\windows\SysWOW64\ntoskrnl.exe
2012-08-10 12:10:03 ----A---- C:\windows\SysWOW64\ntkrnlpa.exe
2012-08-10 12:09:24 ----A---- C:\windows\SysWOW64\psisdecd.dll
2012-08-10 12:09:20 ----A---- C:\windows\SysWOW64\msi.dll
2012-08-10 12:09:13 ----A---- C:\windows\SysWOW64\cryptsvc.dll
2012-08-10 12:09:13 ----A---- C:\windows\SysWOW64\cryptnet.dll
2012-08-10 12:09:13 ----A---- C:\windows\SysWOW64\crypt32.dll
2012-08-10 12:08:48 ----A---- C:\windows\SysWOW64\msvcrt.dll
2012-08-10 12:08:42 ----A---- C:\windows\SysWOW64\tzres.dll
2012-08-10 12:08:30 ----A---- C:\windows\SysWOW64\oleaut32.dll
2012-08-10 12:08:30 ----A---- C:\windows\SysWOW64\oleacc.dll
2012-08-10 12:08:29 ----A---- C:\windows\SysWOW64\EncDec.dll
2012-08-10 12:08:23 ----A---- C:\windows\SysWOW64\cdosys.dll
2012-08-10 12:08:21 ----A---- C:\windows\SysWOW64\ntdll.dll
2012-08-10 12:07:25 ----A---- C:\windows\SysWOW64\packager.dll
2012-08-09 20:20:33 ----ASH---- C:\pagefile.sys
2012-08-09 14:37:48 ----D---- C:\Users\Aleš\AppData\Roaming\ArcSoft
2012-08-09 13:40:26 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-08-09 13:39:54 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2012-08-09 13:39:45 ----D---- C:\ProgramData\Microsoft Help
2012-08-09 13:39:31 ----RD---- C:\MSOCache
2012-08-09 12:59:54 ----D---- C:\Users\Aleš\AppData\Roaming\Mozilla
2012-08-09 12:59:54 ----D---- C:\Program Files (x86)\Conduit
2012-08-09 12:59:51 ----D---- C:\Program Files (x86)\BS_Player
2012-08-09 12:59:47 ----D---- C:\Users\Aleš\AppData\Roaming\BSplayer Pro
2012-08-09 12:59:47 ----D---- C:\Users\Aleš\AppData\Roaming\BSplayer
2012-08-09 12:59:47 ----D---- C:\Program Files (x86)\Webteh
2012-08-09 12:53:09 ----D---- C:\Program Files (x86)\Common Files\Symantec Shared
2012-08-09 12:47:15 ----D---- C:\Users\Aleš\AppData\Roaming\Macromedia
2012-08-09 12:46:17 ----D---- C:\Users\Aleš\AppData\Roaming\Adobe
2012-08-09 12:40:51 ----D---- C:\Users\Aleš\AppData\Roaming\ATI
2012-08-09 12:39:53 ----D---- C:\Users\Aleš\AppData\Roaming\Intel Corporation
2012-08-09 12:39:50 ----D---- C:\Users\Aleš\AppData\Roaming\Synaptics
2012-08-09 12:39:27 ----D---- C:\Users\Aleš\AppData\Roaming\Identities
2012-08-09 12:35:34 ----A---- C:\windows\SysWOW64\rdpcore.dll
2012-08-09 12:34:54 ----D---- C:\Users\Aleš\AppData\Roaming\Hewlett-Packard
2012-08-09 12:31:31 ----D---- C:\Users\Aleš\AppData\Roaming\hpqLog
2012-08-09 11:29:18 ----D---- C:\ProgramData\WinZip
2012-08-09 11:29:17 ----D---- C:\Program Files (x86)\WinZip
2012-08-09 11:28:27 ----D---- C:\Users\Aleš\AppData\Roaming\DigitalPersona
2012-08-09 11:28:13 ----SD---- C:\Users\Aleš\AppData\Roaming\Microsoft
2012-08-09 11:28:08 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 month======
2012-09-01 16:00:37 ----RD---- C:\Program Files (x86)
2012-09-01 15:47:28 ----D---- C:\ProgramData\PDFC
2012-09-01 15:47:27 ----D---- C:\ProgramData\HPQLOG
2012-09-01 15:44:25 ----D---- C:\Windows
2012-09-01 15:43:16 ----D---- C:\windows\Tasks
2012-09-01 15:39:42 ----A---- C:\windows\system.ini
2012-09-01 15:37:17 ----A---- C:\windows\SysWOW64\log.txt
2012-09-01 15:34:01 ----SHD---- C:\System Volume Information
2012-09-01 15:32:58 ----D---- C:\ProgramData
2012-09-01 15:31:12 ----D---- C:\windows\SysWOW64\drivers
2012-09-01 15:31:12 ----D---- C:\windows\SysWOW64
2012-09-01 15:31:12 ----D---- C:\windows\AppPatch
2012-09-01 15:31:11 ----D---- C:\Program Files (x86)\Common Files
2012-09-01 15:24:58 ----D---- C:\ProgramData\Norton
2012-09-01 15:24:52 ----RD---- C:\Program Files
2012-09-01 15:24:44 ----D---- C:\ProgramData\NortonInstaller
2012-09-01 15:19:09 ----SD---- C:\ProgramData\Microsoft
2012-08-31 20:36:07 ----D---- C:\windows\System32
2012-08-31 20:36:07 ----D---- C:\windows\inf
2012-08-31 20:31:15 ----D---- C:\windows\winsxs
2012-08-31 20:29:02 ----RSD---- C:\windows\Fonts
2012-08-31 20:29:01 ----D---- C:\windows\SysWOW64\migration
2012-08-31 20:29:01 ----D---- C:\Program Files (x86)\Internet Explorer
2012-08-27 21:21:21 ----SHD---- C:\windows\Installer
2012-08-19 21:42:11 ----D---- C:\windows\Prefetch
2012-08-15 14:59:43 ----D---- C:\windows\debug
2012-08-14 09:54:28 ----D---- C:\windows\Microsoft.NET
2012-08-14 09:53:38 ----RSD---- C:\windows\assembly
2012-08-13 20:55:46 ----D---- C:\windows\rescache
2012-08-13 18:10:33 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-08-10 17:22:17 ----D---- C:\windows\ehome
2012-08-10 17:22:17 ----D---- C:\Program Files (x86)\Common Files\System
2012-08-10 17:22:10 ----D---- C:\windows\SysWOW64\cs-CZ
2012-08-10 17:21:57 ----D---- C:\windows\servicing
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Sidebar
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Media Player
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Mail
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Defender
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\winrm
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\slmgr
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\migwiz
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\en-US
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\en
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\drivers\en-US
2012-08-10 17:21:54 ----D---- C:\windows\SysWOW64\sl-SI
2012-08-10 17:21:50 ----D---- C:\windows\SysWOW64\WCN
2012-08-10 17:21:50 ----D---- C:\windows\SysWOW64\DriverStore
2012-08-10 17:21:50 ----D---- C:\windows\SysWOW64\Dism
2012-08-10 17:21:49 ----D---- C:\windows\SysWOW64\Printing_Admin_Scripts
2012-08-10 17:21:49 ----D---- C:\windows\en-US
2012-08-10 17:21:27 ----D---- C:\windows\SysWOW64\sk-SK
2012-08-10 17:21:12 ----D---- C:\windows\SysWOW64\hr-HR
2012-08-10 17:20:41 ----D---- C:\windows\Speech
2012-08-10 16:40:01 ----A---- C:\windows\SysWOW64\PerfStringBackup.INI
2012-08-10 16:26:47 ----A---- C:\windows\win.ini
2012-08-10 16:10:08 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2012-08-10 13:47:53 ----D---- C:\windows\Logs
2012-08-09 14:37:50 ----HD---- C:\ProgramData\ArcSoft
2012-08-09 13:43:34 ----D---- C:\windows\ShellNew
2012-08-09 13:42:52 ----D---- C:\Program Files (x86)\MSBuild
2012-08-09 13:42:41 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-08-09 13:39:47 ----D---- C:\Program Files (x86)\Microsoft Office
2012-08-09 12:40:54 ----D---- C:\windows\SoftwareDistribution
2012-08-09 12:38:47 ----AD---- C:\SYSTEM.SAV
2012-08-09 12:34:47 ----RD---- C:\Program Files (x86)\Online Services
2012-08-09 12:33:13 ----D---- C:\swsetup
2012-08-09 12:32:15 ----D---- C:\windows\Panther
2012-08-09 11:29:45 ----D---- C:\ProgramData\Hewlett-Packard
2012-08-09 11:28:12 ----RD---- C:\Users
2012-08-09 11:27:59 ----D---- C:\Recovery
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys []
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys []
R0 MfeEpePc;MfeEpePc; C:\windows\SysWOW64\drivers\MfeEpePc.sys []
R0 PCTCore;PCTools KDS; C:\windows\system32\drivers\PCTCore64.sys []
R0 pctDS;PC Tools Data Store; C:\windows\system32\drivers\pctDS64.sys []
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys []
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys []
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys []
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys []
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys []
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys []
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\drivers\SynTP.sys []
S1 PCTSD;PC Tools Spyware Doctor Driver; C:\windows\System32\Drivers\PCTSD64.sys []
S3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys []
S3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys []
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys []
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys []
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys []
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys []
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys []
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys []
S3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys []
S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys []
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys []
S3 PCTBD;PC Tools Browser Defender Driver; C:\windows\System32\Drivers\PCTBD64.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys []
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys []
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys []
S3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10301; C:\windows\system32\DRIVERS\stwrt64.sys []
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 sdAuxService;PC Tools Auxiliary Service; C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [2012-06-22 402368]
R2 sdCoreService;PC Tools Security Service; C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe [2012-06-22 1118680]
S2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe []
S2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-07-20 249648]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-16 680016]
S2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-06-22 575448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-19 138576]
S2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-02-12 481104]
S2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-12-10 126520]
S2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
S2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]
S2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
S2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
S2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe []
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
S2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
S2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
S2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
S2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-22 2708784]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-22 2286976]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-08-02 195320]
S3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-09 4151376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-03-01 1189968]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-05-10 464440]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-02-07 1028096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-02-07 647680]
S3 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2011-01-12 36864]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-03-29 799800]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
do počítače se mi dostal Live Security Platinum. Prosím o kontrolu logu z RSIT.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Aleš at 2012-09-01 16:00:37
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 376 GB (83%) free of 455 GB
Total RAM: 4030 MB (80% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:00:42, on 1.9.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Safe mode with network support
Running processes:
C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Aleš\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0HOVAGNC\RSIT.exe
C:\Program Files (x86)\trend micro\Aleš.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT1750559
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: BS Player - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [DTRun] c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
O4 - HKLM\..\Run: [HPConnectionManager] c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [HPQuickWebProxy] "c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe -update activex
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\Windows\SysWOW64\flcdlock.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP DayStarter Service (HPDayStarterService) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XobniService - Xobni Corporation - C:\Program Files (x86)\Xobni\XobniService.exe
--
End of file - 14009 bytes
======Scheduled tasks folder======
C:\windows\tasks\HPCeeScheduleForALES-HP$.job
C:\windows\tasks\HPCeeScheduleForAleš.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll [2012-06-22 1136600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2011-02-07 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-08-02 1152760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll [2011-05-09 176936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-08-02 1152760]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files (x86)\BS_Player\prxtbBS_P.dll [2011-05-09 176936]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll [2012-06-22 1136600]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2011-02-07 12274688]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"DTRun"=c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [2010-11-24 517456]
"HPConnectionManager"=c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-04-05 94264]
"HPQuickWebProxy"=c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [2011-11-10 169528]
"ISTray"=C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe [2012-06-22 2673624]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10m_ActiveX.exe [2012-01-02 234656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2011-05-10 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\SysWow64\webcheck.dll [2011-04-14 203776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2011-06-12 4221328]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdAuxService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdCoreService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdAuxService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdCoreService]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2012-09-01 16:00:37 ----D---- C:\rsit
2012-09-01 16:00:37 ----D---- C:\Program Files (x86)\trend micro
2012-09-01 15:44:25 ----D---- C:\windows\temp
2012-09-01 15:44:23 ----A---- C:\ComboFix.txt
2012-09-01 15:39:39 ----D---- C:\$RECYCLE.BIN
2012-09-01 15:27:39 ----A---- C:\windows\zip.exe
2012-09-01 15:27:39 ----A---- C:\windows\SWSC.exe
2012-09-01 15:27:39 ----A---- C:\windows\SWREG.exe
2012-09-01 15:27:39 ----A---- C:\windows\sed.exe
2012-09-01 15:27:39 ----A---- C:\windows\PEV.exe
2012-09-01 15:27:39 ----A---- C:\windows\NIRCMD.exe
2012-09-01 15:27:39 ----A---- C:\windows\MBR.exe
2012-09-01 15:27:39 ----A---- C:\windows\grep.exe
2012-09-01 15:17:52 ----D---- C:\Qoobox
2012-09-01 15:17:38 ----D---- C:\windows\erdnt
2012-09-01 15:01:32 ----A---- C:\windows\BDTSupport.dll
2012-09-01 15:01:31 ----A---- C:\windows\SGDetectionTool.dll
2012-09-01 15:01:31 ----A---- C:\windows\PCTBDRes.dll
2012-09-01 15:01:31 ----A---- C:\windows\PCTBDCore.dll
2012-09-01 15:00:53 ----D---- C:\Program Files (x86)\PC Tools
2012-09-01 14:59:21 ----D---- C:\Program Files (x86)\Common Files\PC Tools
2012-09-01 14:59:10 ----AD---- C:\ProgramData\TEMP
2012-09-01 14:59:09 ----D---- C:\Users\Aleš\AppData\Roaming\TestApp
2012-09-01 14:59:09 ----D---- C:\ProgramData\PC Tools
2012-09-01 14:55:01 ----A---- C:\windows\ntbtlog.txt
2012-08-27 21:17:23 ----A---- C:\windows\SysWOW64\mshtmled.dll
2012-08-27 21:17:22 ----A---- C:\windows\SysWOW64\url.dll
2012-08-27 21:17:21 ----A---- C:\windows\SysWOW64\urlmon.dll
2012-08-27 21:17:21 ----A---- C:\windows\SysWOW64\ieui.dll
2012-08-27 21:17:21 ----A---- C:\windows\SysWOW64\iertutil.dll
2012-08-27 21:17:20 ----A---- C:\windows\SysWOW64\ieUnatt.exe
2012-08-27 21:17:19 ----A---- C:\windows\SysWOW64\wininet.dll
2012-08-27 21:17:18 ----A---- C:\windows\SysWOW64\jsproxy.dll
2012-08-27 21:17:18 ----A---- C:\windows\SysWOW64\jscript9.dll
2012-08-27 21:17:18 ----A---- C:\windows\SysWOW64\jscript.dll
2012-08-27 21:17:17 ----A---- C:\windows\SysWOW64\mshtml.dll
2012-08-27 21:17:15 ----A---- C:\windows\SysWOW64\ieframe.dll
2012-08-27 20:29:15 ----A---- C:\windows\SysWOW64\win32spl.dll
2012-08-27 20:29:15 ----A---- C:\windows\splwow64.exe
2012-08-27 20:29:13 ----A---- C:\windows\SysWOW64\srclient.dll
2012-08-27 20:29:11 ----A---- C:\windows\SysWOW64\netapi32.dll
2012-08-27 20:29:11 ----A---- C:\windows\SysWOW64\browcli.dll
2012-08-10 17:22:13 ----D---- C:\windows\SysWOW64\Wat
2012-08-10 15:25:27 ----A---- C:\windows\SysWOW64\wmi.dll
2012-08-10 15:25:27 ----A---- C:\windows\SysWOW64\wintrust.dll
2012-08-10 15:25:27 ----A---- C:\windows\SysWOW64\imagehlp.dll
2012-08-10 12:10:34 ----A---- C:\windows\SysWOW64\DWrite.dll
2012-08-10 12:10:32 ----A---- C:\windows\SysWOW64\poqexec.exe
2012-08-10 12:10:30 ----A---- C:\windows\SysWOW64\quartz.dll
2012-08-10 12:10:30 ----A---- C:\windows\SysWOW64\qdvd.dll
2012-08-10 12:10:28 ----A---- C:\windows\SysWOW64\ntshrui.dll
2012-08-10 12:10:27 ----A---- C:\windows\SysWOW64\webio.dll
2012-08-10 12:10:24 ----A---- C:\windows\SysWOW64\msxml6.dll
2012-08-10 12:10:24 ----A---- C:\windows\SysWOW64\msxml3r.dll
2012-08-10 12:10:24 ----A---- C:\windows\SysWOW64\msxml3.dll
2012-08-10 12:10:17 ----A---- C:\windows\SysWOW64\XpsPrint.dll
2012-08-10 12:10:14 ----A---- C:\windows\SysWOW64\shell32.dll
2012-08-10 12:10:11 ----A---- C:\windows\SysWOW64\schannel.dll
2012-08-10 12:10:10 ----A---- C:\windows\SysWOW64\sspicli.dll
2012-08-10 12:10:10 ----A---- C:\windows\SysWOW64\secur32.dll
2012-08-10 12:10:10 ----A---- C:\windows\SysWOW64\ncrypt.dll
2012-08-10 12:10:04 ----A---- C:\windows\SysWOW64\ntoskrnl.exe
2012-08-10 12:10:03 ----A---- C:\windows\SysWOW64\ntkrnlpa.exe
2012-08-10 12:09:24 ----A---- C:\windows\SysWOW64\psisdecd.dll
2012-08-10 12:09:20 ----A---- C:\windows\SysWOW64\msi.dll
2012-08-10 12:09:13 ----A---- C:\windows\SysWOW64\cryptsvc.dll
2012-08-10 12:09:13 ----A---- C:\windows\SysWOW64\cryptnet.dll
2012-08-10 12:09:13 ----A---- C:\windows\SysWOW64\crypt32.dll
2012-08-10 12:08:48 ----A---- C:\windows\SysWOW64\msvcrt.dll
2012-08-10 12:08:42 ----A---- C:\windows\SysWOW64\tzres.dll
2012-08-10 12:08:30 ----A---- C:\windows\SysWOW64\oleaut32.dll
2012-08-10 12:08:30 ----A---- C:\windows\SysWOW64\oleacc.dll
2012-08-10 12:08:29 ----A---- C:\windows\SysWOW64\EncDec.dll
2012-08-10 12:08:23 ----A---- C:\windows\SysWOW64\cdosys.dll
2012-08-10 12:08:21 ----A---- C:\windows\SysWOW64\ntdll.dll
2012-08-10 12:07:25 ----A---- C:\windows\SysWOW64\packager.dll
2012-08-09 20:20:33 ----ASH---- C:\pagefile.sys
2012-08-09 14:37:48 ----D---- C:\Users\Aleš\AppData\Roaming\ArcSoft
2012-08-09 13:40:26 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2012-08-09 13:39:54 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2012-08-09 13:39:45 ----D---- C:\ProgramData\Microsoft Help
2012-08-09 13:39:31 ----RD---- C:\MSOCache
2012-08-09 12:59:54 ----D---- C:\Users\Aleš\AppData\Roaming\Mozilla
2012-08-09 12:59:54 ----D---- C:\Program Files (x86)\Conduit
2012-08-09 12:59:51 ----D---- C:\Program Files (x86)\BS_Player
2012-08-09 12:59:47 ----D---- C:\Users\Aleš\AppData\Roaming\BSplayer Pro
2012-08-09 12:59:47 ----D---- C:\Users\Aleš\AppData\Roaming\BSplayer
2012-08-09 12:59:47 ----D---- C:\Program Files (x86)\Webteh
2012-08-09 12:53:09 ----D---- C:\Program Files (x86)\Common Files\Symantec Shared
2012-08-09 12:47:15 ----D---- C:\Users\Aleš\AppData\Roaming\Macromedia
2012-08-09 12:46:17 ----D---- C:\Users\Aleš\AppData\Roaming\Adobe
2012-08-09 12:40:51 ----D---- C:\Users\Aleš\AppData\Roaming\ATI
2012-08-09 12:39:53 ----D---- C:\Users\Aleš\AppData\Roaming\Intel Corporation
2012-08-09 12:39:50 ----D---- C:\Users\Aleš\AppData\Roaming\Synaptics
2012-08-09 12:39:27 ----D---- C:\Users\Aleš\AppData\Roaming\Identities
2012-08-09 12:35:34 ----A---- C:\windows\SysWOW64\rdpcore.dll
2012-08-09 12:34:54 ----D---- C:\Users\Aleš\AppData\Roaming\Hewlett-Packard
2012-08-09 12:31:31 ----D---- C:\Users\Aleš\AppData\Roaming\hpqLog
2012-08-09 11:29:18 ----D---- C:\ProgramData\WinZip
2012-08-09 11:29:17 ----D---- C:\Program Files (x86)\WinZip
2012-08-09 11:28:27 ----D---- C:\Users\Aleš\AppData\Roaming\DigitalPersona
2012-08-09 11:28:13 ----SD---- C:\Users\Aleš\AppData\Roaming\Microsoft
2012-08-09 11:28:08 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 month======
2012-09-01 16:00:37 ----RD---- C:\Program Files (x86)
2012-09-01 15:47:28 ----D---- C:\ProgramData\PDFC
2012-09-01 15:47:27 ----D---- C:\ProgramData\HPQLOG
2012-09-01 15:44:25 ----D---- C:\Windows
2012-09-01 15:43:16 ----D---- C:\windows\Tasks
2012-09-01 15:39:42 ----A---- C:\windows\system.ini
2012-09-01 15:37:17 ----A---- C:\windows\SysWOW64\log.txt
2012-09-01 15:34:01 ----SHD---- C:\System Volume Information
2012-09-01 15:32:58 ----D---- C:\ProgramData
2012-09-01 15:31:12 ----D---- C:\windows\SysWOW64\drivers
2012-09-01 15:31:12 ----D---- C:\windows\SysWOW64
2012-09-01 15:31:12 ----D---- C:\windows\AppPatch
2012-09-01 15:31:11 ----D---- C:\Program Files (x86)\Common Files
2012-09-01 15:24:58 ----D---- C:\ProgramData\Norton
2012-09-01 15:24:52 ----RD---- C:\Program Files
2012-09-01 15:24:44 ----D---- C:\ProgramData\NortonInstaller
2012-09-01 15:19:09 ----SD---- C:\ProgramData\Microsoft
2012-08-31 20:36:07 ----D---- C:\windows\System32
2012-08-31 20:36:07 ----D---- C:\windows\inf
2012-08-31 20:31:15 ----D---- C:\windows\winsxs
2012-08-31 20:29:02 ----RSD---- C:\windows\Fonts
2012-08-31 20:29:01 ----D---- C:\windows\SysWOW64\migration
2012-08-31 20:29:01 ----D---- C:\Program Files (x86)\Internet Explorer
2012-08-27 21:21:21 ----SHD---- C:\windows\Installer
2012-08-19 21:42:11 ----D---- C:\windows\Prefetch
2012-08-15 14:59:43 ----D---- C:\windows\debug
2012-08-14 09:54:28 ----D---- C:\windows\Microsoft.NET
2012-08-14 09:53:38 ----RSD---- C:\windows\assembly
2012-08-13 20:55:46 ----D---- C:\windows\rescache
2012-08-13 18:10:33 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2012-08-10 17:22:17 ----D---- C:\windows\ehome
2012-08-10 17:22:17 ----D---- C:\Program Files (x86)\Common Files\System
2012-08-10 17:22:10 ----D---- C:\windows\SysWOW64\cs-CZ
2012-08-10 17:21:57 ----D---- C:\windows\servicing
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Sidebar
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Media Player
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Mail
2012-08-10 17:21:57 ----D---- C:\Program Files (x86)\Windows Defender
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\winrm
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\slmgr
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\migwiz
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\en-US
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\en
2012-08-10 17:21:56 ----D---- C:\windows\SysWOW64\drivers\en-US
2012-08-10 17:21:54 ----D---- C:\windows\SysWOW64\sl-SI
2012-08-10 17:21:50 ----D---- C:\windows\SysWOW64\WCN
2012-08-10 17:21:50 ----D---- C:\windows\SysWOW64\DriverStore
2012-08-10 17:21:50 ----D---- C:\windows\SysWOW64\Dism
2012-08-10 17:21:49 ----D---- C:\windows\SysWOW64\Printing_Admin_Scripts
2012-08-10 17:21:49 ----D---- C:\windows\en-US
2012-08-10 17:21:27 ----D---- C:\windows\SysWOW64\sk-SK
2012-08-10 17:21:12 ----D---- C:\windows\SysWOW64\hr-HR
2012-08-10 17:20:41 ----D---- C:\windows\Speech
2012-08-10 16:40:01 ----A---- C:\windows\SysWOW64\PerfStringBackup.INI
2012-08-10 16:26:47 ----A---- C:\windows\win.ini
2012-08-10 16:10:08 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2012-08-10 13:47:53 ----D---- C:\windows\Logs
2012-08-09 14:37:50 ----HD---- C:\ProgramData\ArcSoft
2012-08-09 13:43:34 ----D---- C:\windows\ShellNew
2012-08-09 13:42:52 ----D---- C:\Program Files (x86)\MSBuild
2012-08-09 13:42:41 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-08-09 13:39:47 ----D---- C:\Program Files (x86)\Microsoft Office
2012-08-09 12:40:54 ----D---- C:\windows\SoftwareDistribution
2012-08-09 12:38:47 ----AD---- C:\SYSTEM.SAV
2012-08-09 12:34:47 ----RD---- C:\Program Files (x86)\Online Services
2012-08-09 12:33:13 ----D---- C:\swsetup
2012-08-09 12:32:15 ----D---- C:\windows\Panther
2012-08-09 11:29:45 ----D---- C:\ProgramData\Hewlett-Packard
2012-08-09 11:28:12 ----RD---- C:\Users
2012-08-09 11:27:59 ----D---- C:\Recovery
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys []
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys []
R0 MfeEpePc;MfeEpePc; C:\windows\SysWOW64\drivers\MfeEpePc.sys []
R0 PCTCore;PCTools KDS; C:\windows\system32\drivers\PCTCore64.sys []
R0 pctDS;PC Tools Data Store; C:\windows\system32\drivers\pctDS64.sys []
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys []
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys []
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys []
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys []
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys []
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys []
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys []
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\drivers\SynTP.sys []
S1 PCTSD;PC Tools Spyware Doctor Driver; C:\windows\System32\Drivers\PCTSD64.sys []
S3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys []
S3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys []
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys []
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys []
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys []
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys []
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys []
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys []
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys []
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys []
S3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys []
S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys []
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys []
S3 PCTBD;PC Tools Browser Defender Driver; C:\windows\System32\Drivers\PCTBD64.sys []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys []
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys []
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys []
S3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10301; C:\windows\system32\DRIVERS\stwrt64.sys []
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 sdAuxService;PC Tools Auxiliary Service; C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [2012-06-22 402368]
R2 sdCoreService;PC Tools Security Service; C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe [2012-06-22 1118680]
S2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe []
S2 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-07-20 249648]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-16 680016]
S2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [2012-06-22 575448]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-19 138576]
S2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2011-02-12 481104]
S2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-12-10 126520]
S2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
S2 HPDayStarterService;HP DayStarter Service; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]
S2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
S2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
S2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe []
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-02-09 1318912]
S2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
S2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
S2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
S2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-22 2708784]
S2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-22 2286976]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-08-02 195320]
S3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-09 4151376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-03-01 1189968]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\Windows\SysWOW64\flcdlock.exe [2011-05-10 464440]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-02-07 1028096]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-02-07 647680]
S3 HP ProtectTools Service;HP ProtectTools Service; c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2011-01-12 36864]
S3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-04-05 1094712]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-03-29 799800]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------