Stránka 1 z 3

Preventivní kontrola

Napsal: 02 říj 2013 09:32
od dufina
Dobrý den,
chtěla bych poprosit o preventivní kontrolu mého nového (již ale používaného) notebooku. Budu ho používat na účetnictví a fakturaci a nerada bych, aby obsahoval nějaké šmejdy.

Velice děkuji
dufina

Logfile of random's system information tool 1.08 (written by random/random)
Run by HP at 2013-10-02 10:29:23
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 408 GB (90%) free of 454 GB
Total RAM: 3976 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:29:33, on 2.10.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)
Boot mode: Normal

Running processes:
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
C:\Program Files\trend micro\HP.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" (file missing)
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [HPConnectionManager] c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [IFXSPMGT] "c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Company - c:\windows\SysWOW64\flcdlock.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Auto (HPAuto) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company, L.P. - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Endpoint Encryption Agent - Unknown owner - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Roxio Burn Launcher (RoxioBurnLauncher) - Unknown owner - C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12073 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe"
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-270e2501-94f7-4043-b841-12c216061a6d -SystemEventPortName:HostProcess-e1d44882-c8c7-4bd2-84a6-c0ada8a40fb6 -IoCancelEventPortName:HostProcess-8d53890f-2541-4fcb-9d51-375d6a00c83a -NonStateChangingEventPortName:HostProcess-9ac8027c-c4f3-47cf-956e-842a116a4d6d -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:b8bc295a-c82e-477b-992b-c5ef2e119ce5 -DeviceGroupId:
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe"
C:\windows\system32\WLANExt.exe 18462208
C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
\??\C:\windows\system32\conhost.exe "782948616-3887779641339922321-536214544560581-14779264691849781387-1737239183
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe"
"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe"
"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe"
"c:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe"
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe"
C:\windows\System32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe /Embedding
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"LogonUI.exe" /flags:0x1
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.EXE"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe" /start
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe"
"C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"C:\windows\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\windows\servicing\TrustedInstaller.exe
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" /hidden
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe" -Embedding
-Minimized
"c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe"
C:\windows\system32\igfxext.exe -Embedding
C:\windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Microsoft Security Client\msseces.exe" /UpdateAndQuickScan /OpenWebPageOnClose
"c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe"
"C:\Users\HP\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-08-30 245592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2012-03-22 122456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-14 1307928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-08-30 245592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-14 1307928]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-08-30 201784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-03-09 2887440]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [2013-10-02 7177728]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2012-04-02 170264]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2012-04-02 398616]
"Persistence"=C:\windows\system32\igfxpers.exe [2012-04-02 439064]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2012-03-15 15232]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2012-03-05 1425408]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-16 1436736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-03-01 56088]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2012-03-07 684024]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [2012-03-14 319360]
""= []
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-03-27 291608]
"HPConnectionManager"=c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2012-06-13 184736]
"File Sanitizer"=C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2012-03-22 12310616]
"IFXSPMGT"=c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2012-01-27 1127800]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-08-30 4858968]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\SYSTEM32\igfxdev.dll [2012-03-27 434688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2013-10-02 09:58:16 ----D---- C:\5dd69d72f7ed28cfc786c7530969
2013-10-02 09:52:48 ----D---- C:\Users\HP\AppData\Roaming\InstallShield
2013-10-02 09:39:13 ----A---- C:\windows\system32\drivers\btwrchid.sys
2013-10-02 09:39:13 ----A---- C:\windows\system32\drivers\btwl2cap.sys
2013-10-02 09:39:13 ----A---- C:\windows\system32\drivers\btwavdt.sys
2013-10-02 09:39:13 ----A---- C:\windows\system32\drivers\btwaudio.sys
2013-10-02 09:24:12 ----D---- C:\Program Files\trend micro
2013-10-02 09:23:29 ----D---- C:\rsit
2013-10-02 09:23:29 ----D---- C:\Program Files (x86)\trend micro
2013-10-02 09:07:37 ----A---- C:\windows\system32\drivers\WdfLdr.sys
2013-10-02 09:07:37 ----A---- C:\windows\system32\drivers\Wdf01000.sys
2013-10-02 09:07:36 ----A---- C:\windows\system32\Wdfres.dll
2013-10-02 08:47:37 ----A---- C:\windows\SYSWOW64\elshyph.dll
2013-10-02 08:47:37 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\wextract.exe
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\webcheck.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\RegisterIEPKEYs.exe
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\pngfilt.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\msrating.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\msls31.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\inseng.dll
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\iexpress.exe
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-10-02 08:47:36 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-10-02 08:47:36 ----A---- C:\windows\system32\elshyph.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\url.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\SetIEInstalledDate.exe
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\occache.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\mshtmler.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\mshta.exe
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\msfeedssync.exe
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\msfeedsbs.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\licmgr10.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\imgutil.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\iesysprep.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\iesetup.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\iernonce.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\iepeers.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\IEAdvpack.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\icardie.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2013-10-02 08:47:35 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\wininet.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\wextract.exe
2013-10-02 08:47:34 ----A---- C:\windows\system32\webcheck.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\urlmon.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\url.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\RegisterIEPKEYs.exe
2013-10-02 08:47:34 ----A---- C:\windows\system32\msrating.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\msls31.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\mshtmlmedia.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\mshtmled.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\licmgr10.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\jsproxy.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\inseng.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\iesetup.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\iertutil.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\iernonce.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\iedkcs32.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\ieapfltr.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\ie4uinit.exe
2013-10-02 08:47:34 ----A---- C:\windows\system32\icardie.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\dxtrans.dll
2013-10-02 08:47:34 ----A---- C:\windows\system32\dxtmsft.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\vbscript.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\SetIEInstalledDate.exe
2013-10-02 08:47:33 ----A---- C:\windows\system32\pngfilt.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\occache.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\mshtmler.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\mshtml.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\mshta.exe
2013-10-02 08:47:33 ----A---- C:\windows\system32\msfeedssync.exe
2013-10-02 08:47:33 ----A---- C:\windows\system32\msfeedsbs.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\msfeeds.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\jscript9.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\jscript.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\imgutil.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\iexpress.exe
2013-10-02 08:47:33 ----A---- C:\windows\system32\ieUnatt.exe
2013-10-02 08:47:33 ----A---- C:\windows\system32\ieui.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\iesysprep.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\iepeers.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\ieframe.dll
2013-10-02 08:47:33 ----A---- C:\windows\system32\IEAdvpack.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-10-02 08:44:40 ----AH---- C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-10-02 08:44:39 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-10-02 08:44:39 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-10-02 08:44:39 ----AH---- C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-10-02 08:44:39 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-10-02 08:44:39 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\WindowsCodecsExt.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\DWrite.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\d3d10level9.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\d3d10core.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2013-10-02 08:44:39 ----A---- C:\windows\SYSWOW64\d3d10.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\XpsPrint.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\WMPhoto.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\msmpeg2vdec.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\FntCache.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\dxgi.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\DWrite.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\d3d10warp.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\d3d10core.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\d3d10_1core.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\d3d10_1.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\d3d10.dll
2013-10-02 08:44:39 ----A---- C:\windows\system32\d2d1.dll
2013-10-02 08:44:38 ----A---- C:\windows\SYSWOW64\UIAnimation.dll
2013-10-02 08:44:38 ----A---- C:\windows\SYSWOW64\dxgi.dll
2013-10-02 08:44:38 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2013-10-02 08:44:38 ----A---- C:\windows\SYSWOW64\d2d1.dll
2013-10-02 08:44:38 ----A---- C:\windows\system32\WindowsCodecs.dll
2013-10-02 08:44:38 ----A---- C:\windows\system32\UIAnimation.dll
2013-10-02 08:44:38 ----A---- C:\windows\system32\d3d10level9.dll
2013-10-02 08:34:03 ----A---- C:\windows\system32\browserchoice.exe
2013-10-02 06:29:55 ----A---- C:\windows\SYSWOW64\atmlib.dll
2013-10-02 06:29:54 ----A---- C:\windows\system32\atmlib.dll
2013-10-02 06:29:54 ----A---- C:\windows\system32\atmfd.dll
2013-10-02 06:29:53 ----A---- C:\windows\SYSWOW64\atmfd.dll
2013-10-02 06:28:45 ----A---- C:\windows\system32\drivers\WUDFRd.sys
2013-10-02 06:28:45 ----A---- C:\windows\system32\drivers\WUDFPf.sys
2013-10-02 06:28:44 ----A---- C:\windows\system32\WUDFSvc.dll
2013-10-02 06:28:44 ----A---- C:\windows\system32\WUDFPlatform.dll
2013-10-02 06:28:42 ----A---- C:\windows\system32\WUDFCoinstaller.dll
2013-10-02 06:28:41 ----A---- C:\windows\system32\WUDFx.dll
2013-10-02 06:28:41 ----A---- C:\windows\system32\WUDFHost.exe
2013-10-02 06:15:04 ----SHD---- C:\Config.Msi
2013-10-02 06:12:09 ----A---- C:\windows\SYSWOW64\imagehlp.dll
2013-10-02 06:12:09 ----A---- C:\windows\system32\imagehlp.dll
2013-10-02 06:12:09 ----A---- C:\windows\system32\drivers\fs_rec.sys
2013-10-02 06:12:08 ----A---- C:\windows\SYSWOW64\wmi.dll
2013-10-02 06:12:08 ----A---- C:\windows\system32\wmi.dll
2013-10-01 20:35:41 ----D---- C:\Program Files\CCleaner
2013-10-01 20:17:32 ----D---- C:\windows\SYSWOW64\Wat
2013-10-01 20:17:32 ----D---- C:\windows\system32\Wat
2013-10-01 20:07:50 ----D---- C:\Users\HP\AppData\Roaming\Macromedia
2013-10-01 20:07:11 ----D---- C:\windows\system32\Macromed
2013-10-01 19:56:05 ----A---- C:\windows\system32\drivers\aswFsBlk.sys
2013-10-01 19:56:04 ----A---- C:\windows\system32\drivers\aswTdi.sys
2013-10-01 19:56:04 ----A---- C:\windows\system32\drivers\aswSP.sys
2013-10-01 19:56:04 ----A---- C:\windows\system32\drivers\aswRdr2.sys
2013-10-01 19:56:03 ----A---- C:\windows\system32\drivers\aswVmm.sys
2013-10-01 19:56:03 ----A---- C:\windows\system32\drivers\aswSnx.sys
2013-10-01 19:56:03 ----A---- C:\windows\system32\drivers\aswRvrt.sys
2013-10-01 19:56:00 ----A---- C:\windows\system32\drivers\aswMonFlt.sys
2013-10-01 19:56:00 ----A---- C:\windows\system32\aswBoot.exe
2013-10-01 19:54:59 ----D---- C:\Program Files\AVAST Software
2013-10-01 19:54:01 ----D---- C:\ProgramData\AVAST Software
2013-10-01 19:53:45 ----A---- C:\windows\SYSWOW64\poqexec.exe
2013-10-01 19:53:45 ----A---- C:\windows\system32\poqexec.exe
2013-10-01 19:53:42 ----A---- C:\windows\SYSWOW64\dhcpcsvc6.dll
2013-10-01 19:53:42 ----A---- C:\windows\SYSWOW64\dhcpcore6.dll
2013-10-01 19:53:42 ----A---- C:\windows\system32\dhcpcsvc6.dll
2013-10-01 19:53:42 ----A---- C:\windows\system32\dhcpcore6.dll
2013-10-01 19:53:35 ----A---- C:\windows\system32\mstscax.dll
2013-10-01 19:53:34 ----A---- C:\windows\SYSWOW64\mstscax.dll
2013-10-01 19:53:33 ----A---- C:\windows\SYSWOW64\tsgqec.dll
2013-10-01 19:53:33 ----A---- C:\windows\SYSWOW64\aaclient.dll
2013-10-01 19:53:33 ----A---- C:\windows\system32\tsgqec.dll
2013-10-01 19:53:33 ----A---- C:\windows\system32\aaclient.dll
2013-10-01 19:53:25 ----A---- C:\windows\system32\crypt32.dll
2013-10-01 19:53:24 ----A---- C:\windows\SYSWOW64\wintrust.dll
2013-10-01 19:53:24 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2013-10-01 19:53:24 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2013-10-01 19:53:24 ----A---- C:\windows\SYSWOW64\crypt32.dll
2013-10-01 19:53:24 ----A---- C:\windows\system32\wintrust.dll
2013-10-01 19:53:24 ----A---- C:\windows\system32\cryptsvc.dll
2013-10-01 19:53:24 ----A---- C:\windows\system32\cryptnet.dll
2013-10-01 19:53:07 ----A---- C:\windows\system32\authui.dll
2013-10-01 19:53:06 ----A---- C:\windows\SYSWOW64\authui.dll
2013-10-01 19:53:06 ----A---- C:\windows\system32\consent.exe
2013-10-01 19:53:06 ----A---- C:\windows\system32\appinfo.dll
2013-10-01 19:52:55 ----A---- C:\windows\system32\wwansvc.dll
2013-10-01 19:52:55 ----A---- C:\windows\system32\wwanprotdim.dll
2013-10-01 19:52:54 ----A---- C:\windows\system32\drivers\ntfs.sys
2013-10-01 19:52:48 ----A---- C:\windows\SYSWOW64\tzres.dll
2013-10-01 19:52:48 ----A---- C:\windows\system32\tzres.dll
2013-10-01 19:52:05 ----A---- C:\windows\system32\drivers\ataport.sys
2013-10-01 19:52:00 ----A---- C:\windows\system32\drivers\RNDISMP.sys
2013-10-01 19:52:00 ----A---- C:\windows\system32\drivers\ndis.sys
2013-10-01 19:51:56 ----A---- C:\windows\system32\ntoskrnl.exe
2013-10-01 19:51:55 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-10-01 19:51:55 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-10-01 19:51:54 ----A---- C:\windows\SYSWOW64\ntdll.dll
2013-10-01 19:51:54 ----A---- C:\windows\SYSWOW64\KernelBase.dll
2013-10-01 19:51:54 ----A---- C:\windows\system32\wow64win.dll
2013-10-01 19:51:54 ----A---- C:\windows\system32\wow64.dll
2013-10-01 19:51:54 ----A---- C:\windows\system32\winsrv.dll
2013-10-01 19:51:54 ----A---- C:\windows\system32\ntdll.dll
2013-10-01 19:51:54 ----A---- C:\windows\system32\KernelBase.dll
2013-10-01 19:51:54 ----A---- C:\windows\system32\kernel32.dll
2013-10-01 19:51:53 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-01 19:51:53 ----AH---- C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-10-01 19:51:53 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-10-01 19:51:53 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-10-01 19:51:53 ----A---- C:\windows\SYSWOW64\kernel32.dll
2013-10-01 19:51:53 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-10-01 19:51:53 ----A---- C:\windows\system32\wow64cpu.dll
2013-10-01 19:51:53 ----A---- C:\windows\system32\smss.exe
2013-10-01 19:51:53 ----A---- C:\windows\system32\ntvdm64.dll
2013-10-01 19:51:53 ----A---- C:\windows\system32\csrsrv.dll
2013-10-01 19:51:53 ----A---- C:\windows\system32\conhost.exe
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-10-01 19:51:52 ----AH---- C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-10-01 19:51:52 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-10-01 19:51:51 ----AH---- C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-10-01 19:51:51 ----A---- C:\windows\SYSWOW64\user.exe
2013-10-01 19:51:51 ----A---- C:\windows\SYSWOW64\apisetschema.dll
2013-10-01 19:51:51 ----A---- C:\windows\system32\apisetschema.dll
2013-10-01 19:51:31 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2013-10-01 19:51:31 ----A---- C:\windows\system32\WMVDECOD.DLL
2013-10-01 19:51:30 ----A---- C:\windows\system32\drivers\usb8023.sys
2013-10-01 19:51:29 ----A---- C:\windows\system32\rdrmemptylst.exe
2013-10-01 19:51:29 ----A---- C:\windows\system32\rdpwsx.dll
2013-10-01 19:51:29 ----A---- C:\windows\system32\rdpcorekmts.dll
2013-10-01 19:51:28 ----A---- C:\windows\SYSWOW64\sspicli.dll
2013-10-01 19:51:28 ----A---- C:\windows\SYSWOW64\schannel.dll
2013-10-01 19:51:28 ----A---- C:\windows\SYSWOW64\secur32.dll
2013-10-01 19:51:28 ----A---- C:\windows\system32\schannel.dll
2013-10-01 19:51:28 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2013-10-01 19:51:28 ----A---- C:\windows\system32\drivers\ksecdd.sys
2013-10-01 19:51:28 ----A---- C:\windows\system32\drivers\cng.sys
2013-10-01 19:51:17 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2013-10-01 19:51:17 ----A---- C:\windows\system32\rpcrt4.dll
2013-10-01 19:51:16 ----A---- C:\windows\SYSWOW64\msxml6.dll
2013-10-01 19:51:16 ----A---- C:\windows\system32\msxml6.dll
2013-10-01 19:51:16 ----A---- C:\windows\system32\msxml3.dll
2013-10-01 19:51:15 ----A---- C:\windows\SYSWOW64\msxml3r.dll
2013-10-01 19:51:15 ----A---- C:\windows\SYSWOW64\msxml3.dll
2013-10-01 19:51:15 ----A---- C:\windows\system32\msxml3r.dll
2013-10-01 19:51:14 ----A---- C:\windows\system32\ncsi.dll
2013-10-01 19:51:13 ----A---- C:\windows\SYSWOW64\nlaapi.dll
2013-10-01 19:51:13 ----A---- C:\windows\SYSWOW64\netcorehc.dll
2013-10-01 19:51:13 ----A---- C:\windows\SYSWOW64\ncsi.dll
2013-10-01 19:51:13 ----A---- C:\windows\system32\nlasvc.dll
2013-10-01 19:51:13 ----A---- C:\windows\system32\nlaapi.dll
2013-10-01 19:51:13 ----A---- C:\windows\system32\netcorehc.dll
2013-10-01 19:51:13 ----A---- C:\windows\system32\iphlpsvc.dll
2013-10-01 19:51:13 ----A---- C:\windows\system32\drivers\tcpipreg.sys
2013-10-01 19:51:12 ----A---- C:\windows\SYSWOW64\netevent.dll
2013-10-01 19:51:12 ----A---- C:\windows\system32\netevent.dll
2013-10-01 19:51:09 ----A---- C:\windows\system32\profsvc.dll
2013-10-01 19:50:08 ----A---- C:\windows\system32\dpnet.dll
2013-10-01 19:50:07 ----A---- C:\windows\SYSWOW64\qedit.dll
2013-10-01 19:50:07 ----A---- C:\windows\SYSWOW64\dpnet.dll
2013-10-01 19:50:07 ----A---- C:\windows\system32\qedit.dll
2013-10-01 19:50:06 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2013-10-01 19:50:06 ----A---- C:\windows\system32\ncrypt.dll
2013-10-01 19:50:05 ----A---- C:\windows\system32\OxpsConverter.exe
2013-10-01 19:48:52 ----A---- C:\windows\SYSWOW64\usp10.dll
2013-10-01 19:48:52 ----A---- C:\windows\system32\usp10.dll
2013-10-01 19:48:51 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2013-10-01 19:48:49 ----A---- C:\windows\SYSWOW64\Wpc.dll
2013-10-01 19:48:49 ----A---- C:\windows\SYSWOW64\gameux.dll
2013-10-01 19:48:49 ----A---- C:\windows\system32\Wpc.dll
2013-10-01 19:48:49 ----A---- C:\windows\system32\gameux.dll
2013-10-01 19:48:33 ----A---- C:\windows\system32\drivers\rdpwd.sys
2013-10-01 19:48:15 ----A---- C:\windows\system32\win32k.sys
2013-10-01 19:48:02 ----A---- C:\windows\system32\drivers\partmgr.sys
2013-10-01 19:48:00 ----A---- C:\windows\SYSWOW64\kerberos.dll
2013-10-01 19:48:00 ----A---- C:\windows\system32\kerberos.dll
2013-10-01 19:47:59 ----A---- C:\windows\SYSWOW64\msi.dll
2013-10-01 19:47:59 ----A---- C:\windows\system32\msi.dll
2013-10-01 19:44:45 ----A---- C:\windows\system32\drivers\bthport.sys
2013-10-01 19:44:43 ----A---- C:\windows\SYSWOW64\synceng.dll
2013-10-01 19:44:43 ----A---- C:\windows\system32\synceng.dll
2013-10-01 19:44:42 ----A---- C:\windows\system32\shell32.dll
2013-10-01 19:44:41 ----A---- C:\windows\SYSWOW64\shell32.dll
2013-10-01 19:44:40 ----A---- C:\windows\SYSWOW64\shdocvw.dll
2013-10-01 19:44:40 ----A---- C:\windows\system32\shdocvw.dll
2013-10-01 19:44:36 ----A---- C:\windows\system32\win32spl.dll
2013-10-01 19:44:35 ----A---- C:\windows\SYSWOW64\win32spl.dll
2013-10-01 19:44:33 ----A---- C:\windows\system32\taskhost.exe
2013-10-01 19:44:30 ----A---- C:\windows\SYSWOW64\cryptdlg.dll
2013-10-01 19:44:30 ----A---- C:\windows\system32\cryptdlg.dll
2013-10-01 19:44:20 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-10-01 19:44:20 ----A---- C:\windows\system32\drivers\netio.sys
2013-10-01 19:44:20 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2013-10-01 19:44:12 ----A---- C:\windows\SYSWOW64\netapi32.dll
2013-10-01 19:44:12 ----A---- C:\windows\SYSWOW64\browcli.dll
2013-10-01 19:44:12 ----A---- C:\windows\system32\netapi32.dll
2013-10-01 19:44:12 ----A---- C:\windows\system32\browser.dll
2013-10-01 19:44:12 ----A---- C:\windows\system32\browcli.dll
2013-10-01 19:44:10 ----A---- C:\windows\system32\drivers\fvevol.sys
2013-10-01 19:44:09 ----A---- C:\windows\SYSWOW64\srclient.dll
2013-10-01 19:44:09 ----A---- C:\windows\system32\srcore.dll
2013-10-01 19:44:05 ----A---- C:\windows\SYSWOW64\certutil.exe
2013-10-01 19:44:05 ----A---- C:\windows\system32\certutil.exe
2013-10-01 19:44:04 ----A---- C:\windows\SYSWOW64\certenc.dll
2013-10-01 19:44:04 ----A---- C:\windows\system32\certenc.dll
2013-10-01 19:43:49 ----A---- C:\windows\system32\localspl.dll
2013-10-01 19:43:21 ----A---- C:\windows\SYSWOW64\cdosys.dll
2013-10-01 19:43:20 ----A---- C:\windows\system32\cdosys.dll
2013-10-01 19:43:17 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-10-01 19:43:17 ----A---- C:\windows\system32\d3d11.dll
2013-10-01 19:43:12 ----A---- C:\windows\system32\spoolsv.exe
2013-10-01 19:43:11 ----A---- C:\windows\splwow64.exe
2013-10-01 19:36:07 ----D---- C:\ProgramData\Synaptics
2013-10-01 19:28:45 ----D---- C:\Users\HP\AppData\Roaming\Mozilla
2013-10-01 19:28:37 ----D---- C:\ProgramData\Mozilla
2013-10-01 19:28:37 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-01 19:28:34 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-10-01 19:27:21 ----D---- C:\Users\HP\AppData\Roaming\Adobe
2013-10-01 19:25:39 ----A---- C:\windows\system32\wups2.dll
2013-10-01 19:25:39 ----A---- C:\windows\system32\wucltux.dll
2013-10-01 19:25:39 ----A---- C:\windows\system32\wuaueng.dll
2013-10-01 19:25:39 ----A---- C:\windows\system32\wuauclt.exe
2013-10-01 19:25:30 ----A---- C:\windows\system32\wups.dll
2013-10-01 19:25:30 ----A---- C:\windows\system32\wudriver.dll
2013-10-01 19:25:30 ----A---- C:\windows\system32\wuapi.dll
2013-10-01 19:25:24 ----A---- C:\windows\system32\wuwebv.dll
2013-10-01 19:25:24 ----A---- C:\windows\system32\wuapp.exe
2013-09-05 12:41:09 ----D---- C:\windows\CSC
2013-09-05 12:39:33 ----SHD---- C:\System Volume Information
2013-09-05 12:39:33 ----ASH---- C:\pagefile.sys
2013-09-05 03:48:46 ----D---- C:\Users\HP\AppData\Roaming\Intel Corporation
2013-09-05 03:47:53 ----D---- C:\Users\HP\AppData\Roaming\Hewlett-Packard
2013-09-05 03:47:42 ----D---- C:\Users\HP\AppData\Roaming\Synaptics
2013-09-05 03:47:25 ----D---- C:\Users\HP\AppData\Roaming\Identities
2013-09-05 03:46:00 ----D---- C:\Users\HP\AppData\Roaming\Roxio
2013-09-05 03:44:39 ----D---- C:\Users\HP\AppData\Roaming\Infineon
2013-09-05 03:44:31 ----D---- C:\Users\HP\AppData\Roaming\hpqLog
2013-09-05 03:44:20 ----D---- C:\Users\HP\AppData\Roaming\DigitalPersona
2013-09-05 03:44:04 ----SD---- C:\Users\HP\AppData\Roaming\Microsoft
2013-09-05 03:43:59 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 months======

2013-10-02 10:29:34 ----D---- C:\windows\Temp
2013-10-02 10:26:33 ----D---- C:\windows\System32
2013-10-02 10:26:33 ----D---- C:\windows\inf
2013-10-02 10:26:33 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-10-02 10:25:03 ----RSD---- C:\windows\assembly
2013-10-02 10:25:03 ----D---- C:\windows\Microsoft.NET
2013-10-02 10:22:20 ----D---- C:\windows\system32\config
2013-10-02 10:21:28 ----A---- C:\windows\SYSWOW64\log.txt
2013-10-02 10:20:53 ----D---- C:\windows\Prefetch
2013-10-02 10:20:28 ----D---- C:\Windows
2013-10-02 10:20:24 ----D---- C:\windows\SysWOW64
2013-10-02 10:20:09 ----D---- C:\windows\winsxs
2013-10-02 10:19:39 ----D---- C:\ProgramData\PDFC
2013-10-02 10:19:31 ----D---- C:\windows\Panther
2013-10-02 10:11:58 ----D---- C:\windows\system32\sl-SI
2013-10-02 10:11:58 ----D---- C:\windows\system32\sk-SK
2013-10-02 10:11:58 ----D---- C:\windows\system32\hr-HR
2013-10-02 10:11:58 ----D---- C:\windows\system32\en-US
2013-10-02 10:11:58 ----D---- C:\windows\system32\cs-CZ
2013-10-02 10:11:58 ----D---- C:\Program Files\Common Files\System
2013-10-02 10:11:57 ----D---- C:\windows\SYSWOW64\en-US
2013-10-02 10:11:57 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-10-02 10:11:56 ----D---- C:\windows\SYSWOW64\sk-SK
2013-10-02 10:11:55 ----D---- C:\windows\SYSWOW64\sl-SI
2013-10-02 10:11:55 ----D---- C:\windows\SYSWOW64\hr-HR
2013-10-02 10:11:55 ----D---- C:\windows\AppPatch
2013-10-02 10:11:53 ----D---- C:\windows\system32\drivers
2013-10-02 10:11:52 ----D---- C:\windows\system32\wbem
2013-10-02 10:11:52 ----D---- C:\windows\system32\drivers\en-US
2013-10-02 10:11:52 ----D---- C:\windows\system32\drivers\cs-CZ
2013-10-02 10:11:51 ----D---- C:\Program Files\Windows Defender
2013-10-02 10:11:51 ----D---- C:\Program Files (x86)\Windows Defender
2013-10-02 10:11:50 ----D---- C:\Program Files\Internet Explorer
2013-10-02 10:11:50 ----D---- C:\Program Files (x86)\Internet Explorer
2013-10-02 10:11:44 ----D---- C:\windows\SYSWOW64\migration
2013-10-02 10:11:41 ----D---- C:\windows\system32\migration
2013-10-02 10:11:41 ----D---- C:\windows\PolicyDefinitions
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\zh-TW
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\zh-HK
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\zh-CN
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\tr-TR
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\sv-SE
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\ru-RU
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\pt-PT
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\pt-BR
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\pl-PL
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\nl-NL
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\nb-NO
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\ko-KR
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\ja-JP
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\it-IT
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\hu-HU
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\fr-FR
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\fi-FI
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\es-ES
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\el-GR
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\de-DE
2013-10-02 10:11:37 ----D---- C:\windows\SYSWOW64\da-DK
2013-10-02 10:11:36 ----D---- C:\windows\system32\pt-PT
2013-10-02 10:11:36 ----D---- C:\windows\system32\pt-BR
2013-10-02 10:11:36 ----D---- C:\windows\system32\pl-PL
2013-10-02 10:11:36 ----D---- C:\windows\system32\ko-KR
2013-10-02 10:11:36 ----D---- C:\windows\system32\it-IT
2013-10-02 10:11:35 ----D---- C:\windows\system32\zh-TW
2013-10-02 10:11:35 ----D---- C:\windows\system32\zh-HK
2013-10-02 10:11:35 ----D---- C:\windows\system32\zh-CN
2013-10-02 10:11:35 ----D---- C:\windows\system32\tr-TR
2013-10-02 10:11:35 ----D---- C:\windows\system32\sv-SE
2013-10-02 10:11:35 ----D---- C:\windows\system32\ru-RU
2013-10-02 10:11:35 ----D---- C:\windows\system32\nl-NL
2013-10-02 10:11:35 ----D---- C:\windows\system32\nb-NO
2013-10-02 10:11:35 ----D---- C:\windows\system32\ja-JP
2013-10-02 10:11:35 ----D---- C:\windows\system32\hu-HU
2013-10-02 10:11:35 ----D---- C:\windows\system32\fr-FR
2013-10-02 10:11:35 ----D---- C:\windows\system32\fi-FI
2013-10-02 10:11:35 ----D---- C:\windows\system32\es-ES
2013-10-02 10:11:35 ----D---- C:\windows\system32\el-GR
2013-10-02 10:11:35 ----D---- C:\windows\system32\de-DE
2013-10-02 10:11:35 ----D---- C:\windows\system32\da-DK
2013-10-02 10:11:12 ----RSD---- C:\windows\Fonts
2013-10-02 10:11:11 ----D---- C:\Program Files\Windows Journal
2013-10-02 10:08:20 ----D---- C:\windows\system32\DriverStore
2013-10-02 10:06:03 ----SHD---- C:\windows\Installer
2013-10-02 10:06:03 ----D---- C:\Program Files (x86)\Hewlett-Packard
2013-10-02 09:56:58 ----D---- C:\windows\SYSWOW64\drivers
2013-10-02 09:56:42 ----D---- C:\swsetup
2013-10-02 09:56:13 ----D---- C:\windows\system32\th-TH
2013-10-02 09:56:13 ----D---- C:\windows\system32\ro-RO
2013-10-02 09:56:13 ----D---- C:\windows\system32\lv-LV
2013-10-02 09:56:13 ----D---- C:\windows\system32\lt-LT
2013-10-02 09:56:13 ----D---- C:\windows\system32\he-IL
2013-10-02 09:56:13 ----D---- C:\windows\system32\et-EE
2013-10-02 09:56:13 ----D---- C:\windows\system32\bg-BG
2013-10-02 09:56:13 ----D---- C:\windows\system32\ar-SA
2013-10-02 09:56:13 ----D---- C:\windows\Help
2013-10-02 09:55:41 ----D---- C:\windows\system32\catroot
2013-10-02 09:53:12 ----D---- C:\Program Files (x86)\Cisco
2013-10-02 09:52:33 ----A---- C:\windows\system32\wltrynt.dll
2013-10-02 09:52:33 ----A---- C:\windows\system32\vcredist_x64.exe
2013-10-02 09:52:30 ----A---- C:\windows\system32\vcredist_x64.bat
2013-10-02 09:52:30 ----A---- C:\windows\system32\bcmttls.dll
2013-10-02 09:52:29 ----A---- C:\windows\SYSWOW64\vcredist_x64.exe
2013-10-02 09:52:29 ----A---- C:\windows\SYSWOW64\vcredist_x64.bat
2013-10-02 09:52:29 ----A---- C:\windows\system32\BCMLogon.dll
2013-10-02 09:52:06 ----A---- C:\windows\system32\bcmwlrc.dll
2013-10-02 09:52:05 ----A---- C:\windows\system32\bcmwlcoi.dll
2013-10-02 09:52:05 ----A---- C:\windows\system32\bcmihvui64.dll
2013-10-02 09:52:05 ----A---- C:\windows\system32\bcmihvsrv64.dll
2013-10-02 09:49:20 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2013-10-02 09:39:26 ----D---- C:\windows\system32\catroot2
2013-10-02 09:24:12 ----RD---- C:\Program Files
2013-10-02 09:23:29 ----RD---- C:\Program Files (x86)
2013-10-02 08:55:50 ----D---- C:\windows\Logs
2013-10-02 06:04:47 ----D---- C:\windows\SoftwareDistribution
2013-10-01 21:19:54 ----D---- C:\windows\system32\Tasks
2013-10-01 21:05:56 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2013-10-01 20:52:33 ----D---- C:\windows\system32\wdi
2013-10-01 20:36:55 ----D---- C:\windows\debug
2013-10-01 19:54:01 ----HD---- C:\ProgramData
2013-10-01 19:47:39 ----D---- C:\windows\system32\LogFiles
2013-10-01 19:26:06 ----SD---- C:\ProgramData\Microsoft
2013-09-05 03:47:53 ----D---- C:\ProgramData\Hewlett-Packard
2013-09-05 03:47:16 ----SHD---- C:\$Recycle.Bin
2013-09-05 03:46:53 ----D---- C:\windows\system32\restore
2013-09-05 03:46:52 ----HD---- C:\SYSTEM.SAV
2013-09-05 03:46:40 ----RD---- C:\Program Files (x86)\Online Services
2013-09-05 03:46:37 ----D---- C:\Program Files\Windows Sidebar
2013-09-05 03:46:37 ----D---- C:\Program Files (x86)\Windows Sidebar
2013-09-05 03:44:04 ----RD---- C:\Users
2013-09-05 03:43:52 ----SHD---- C:\Recovery
2013-09-05 03:43:52 ----D---- C:\windows\system32\Recovery
2013-09-05 03:41:45 ----D---- C:\windows\rescache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2013-08-30 65336]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2013-08-30 204880]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2012-04-27 30488]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\drivers\iaStor.sys [2012-02-02 568600]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\DRIVERS\iusb3hcs.sys [2012-03-27 19224]
R0 MfeEpeOpal;MfeEpeOpal; C:\windows\system32\drivers\MfeEpeOpal.sys [2012-03-22 93640]
R0 MfeEpePc;MfeEpePc; C:\windows\system32\drivers\MfeEpePc.sys [2012-03-22 158792]
R0 PxHlpa64;PxHlpa64; C:\windows\System32\Drivers\PxHlpa64.sys [2012-03-08 58000]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2013-08-30 72016]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2013-08-30 1030952]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2013-08-30 378944]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2013-08-30 64288]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2011-04-18 189440]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [2010-01-26 44576]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2013-08-30 33400]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2013-08-30 80816]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2012-04-27 43800]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2012-02-03 42816]
R3 bcbtums;Bluetooth RAM Firmware Download USB Filter; C:\windows\system32\drivers\bcbtums.sys [2013-10-02 165688]
R3 BCM42RLY;BCM42RLY; C:\windows\system32\drivers\BCM42RLY.sys [2013-10-02 22632]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\windows\system32\DRIVERS\bcmwl664.sys [2013-10-02 4747880]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-05-17 80384]
R3 btwampfl;btwampfl Bluetooth filter driver; \??\C:\windows\system32\drivers\btwampfl.sys [2013-10-02 598808]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2013-10-02 184144]
R3 btwavdt;Bluetooth AVDT; C:\windows\system32\DRIVERS\btwavdt.sys [2013-10-02 210984]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2013-10-02 39976]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2013-10-02 21544]
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C; C:\windows\system32\DRIVERS\e1c62x64.sys [2012-02-22 360624]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2011-07-18 25912]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-03-27 14748416]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\iusb3hub.sys [2012-03-27 356632]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\DRIVERS\iusb3xhc.sys [2012-03-27 789272]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2012-02-28 173656]
R3 johci;JMicron 1394 Filter Driver; C:\windows\system32\DRIVERS\johci.sys [2012-02-28 26200]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\HECIx64.sys [2011-11-09 60184]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 40832]
R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-28 84864]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2012-03-31 1863680]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10301; C:\windows\system32\DRIVERS\stwrt64.sys [2012-03-05 536064]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2012-03-09 425232]
R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTWDPAN;Bluetooth Personal Area Network; C:\windows\system32\DRIVERS\btwdpan.sys [2012-02-02 89640]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv64.sys [2012-11-09 64832]
S3 dmvsc;dmvsc; C:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 storvsc;storvsc; C:\windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-08-30 46808]
R2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [2012-02-14 193816]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2012-12-06 1005944]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 DpHost;@c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2012-03-15 493904]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2012-03-15 152992]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]
R2 HPAuto;HP Auto; C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2012-03-22 372824]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [2012-03-14 365440]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2012-04-27 33560]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-03-01 13592]
R2 IFXSpMgtSrv;Security Platform Management Service; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2012-01-27 1127800]
R2 IFXTCS;Trusted Platform Core Service; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [2012-01-27 984440]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-03-07 629984]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-03-28 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-03-28 165144]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-03-28 277784]
R2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2012-03-22 1327104]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-28 12784]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2012-03-07 1134584]
R2 PersonalSecureDriveService;Personal Secure Drive Service; c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [2012-01-27 212344]
R2 RoxioBurnLauncher;Roxio Burn Launcher; C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [2012-03-21 536848]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10101; C:\Program Files\IDT\WDM\STacSV64.exe [2012-03-05 314880]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2012-02-03 498352]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-03-28 363800]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2012-03-20 2694224]
R3 hpCMSrv;HP Connection Manager 4 Service; c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2012-06-13 1421728]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-04-26 994176]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-28 288272]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-01 257416]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [2012-02-14 240408]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2012-04-02 276248]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; c:\windows\SysWOW64\flcdlock.exe [2012-11-19 477056]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-09-11 118680]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM; C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2012-03-07 1118480]
S3 stllssvr;stllssvr; C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2011-12-08 76416]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2013-10-01 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2012-03-09 117552]

-----------------EOF-----------------

Re: Preventivní kontrola

Napsal: 02 říj 2013 11:14
od Márty84
Zdravim :)

:???: A dokoncite to tentokrat? Nebo to dopadne jak minule? :cry:

:???: Je s tim pc nejaky problem?

:!: Bezi vam tam dva antiviry! Jeden musi pryc, za sebe doporucuji ponechat v pc Avast.


:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Preventivní kontrola

Napsal: 02 říj 2013 11:50
od Márty84
Jeste se zeptam, jestli je to vas osobni domaci stroj, nebo nejaky firemni :)

Re: Preventivní kontrola

Napsal: 02 říj 2013 13:06
od dufina
Za minule se omlouvám, problém byl odstraněn, zapomněla jsem to napsat. PC to bude můj soukromý, domácí, používaný k mé práci doma. Scan udělám, poté hodím log. S počítačem zatím není žádný problém - mám ho 2 dny, takže se s ním seznamuji, jen jsem doinstalovala Avast. Pro jistotu jsem sem dala log, nevím co s ním předchozí uživatel dělal. :-)

Re: Preventivní kontrola

Napsal: 02 říj 2013 14:32
od dufina
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Verze: v2013.10.02.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16686
HP :: HP-PC [administrátor]

2.10.2013 14:54:34
mbam-log-2013-10-02 (14-54-34).txt

Typ: Kompletní kontrola (C:\|E:\|G:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 362748
Uplynulý čas: 36 minut, 23 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Re: Preventivní kontrola

Napsal: 02 říj 2013 18:38
od Márty84
OK :wink:

MBAM muzete odinstalovat.

Avast je dobra volba, ale musite odinstalovat MSE, jinak se budou prat :)

Prohlidnem ho tedy poradne, at vite, ze je opravdu cisty.



:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner\AdwCleaner[R?].txt ), ten mi sem zkopirujte.

Re: Preventivní kontrola

Napsal: 03 říj 2013 16:09
od dufina
Posílám log:

# AdwCleaner v3.006 - Report created 03/10/2013 at 17:07:00
# Updated 01/10/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : HP - HP-PC
# Running from : C:\Users\HP\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****

Service Found : BackupStack

***** [ Files / Folders ] *****

File Found : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
File Found : C:\Users\HP\Desktop\MyPC Backup.lnk
Folder Found C:\Program Files (x86)\MyPC Backup
Folder Found C:\Program Files (x86)\MyPC Backup
Folder Found C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Folder Found C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686


-\\ Mozilla Firefox v24.0 (cs)

[ File : C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\a1ff903s.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1601 octets] - [03/10/2013 17:07:00]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1661 octets] ##########

Re: Preventivní kontrola

Napsal: 03 říj 2013 19:49
od Márty84
:arrow: Znovu ukoncete vsechny programy a spustte AdwCleaner jako spravce.
Tentokrat kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne dalsi log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zase zkopirujte.

Re: Preventivní kontrola

Napsal: 04 říj 2013 08:00
od dufina
nový log:

# AdwCleaner v3.006 - Report created 04/10/2013 at 08:55:16
# Updated 01/10/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : HP - HP-PC
# Running from : C:\Users\HP\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\MyPC Backup

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16686


-\\ Mozilla Firefox v24.0 (cs)

[ File : C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\a1ff903s.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [1753 octets] - [03/10/2013 17:07:00]
AdwCleaner[R1].txt - [1357 octets] - [04/10/2013 08:54:47]
AdwCleaner[S0].txt - [1122 octets] - [04/10/2013 08:55:16]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1182 octets] ##########

Re: Preventivní kontrola

Napsal: 04 říj 2013 08:56
od Márty84
:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu, kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte

Re: Preventivní kontrola

Napsal: 04 říj 2013 09:18
od dufina
RogueKiller V8.7.1 [Oct 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : HP [Práva správce]
Mód : Kontrola -- Datum : 10/04/2013 10:16:23
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - TOSHIBA MK5061GSYN +++++
--- User ---
[MBR] 66901dfd95c380d51515e8ad691d1b34
[BSP] d591c868d18c2835ba5cb21994e04de8 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 453540 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 929466368 | Size: 21048 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 972572672 | Size: 2043 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_10042013_101623.txt >>

Re: Preventivní kontrola

Napsal: 04 říj 2013 09:45
od Márty84
:arrow: Znovu spustte RogueKiller jako spravce (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.

Re: Preventivní kontrola

Napsal: 04 říj 2013 10:46
od dufina
RogueKiller V8.7.1 [Oct 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : HP [Práva správce]
Mód : Odebrat -- Datum : 10/04/2013 11:35:22
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 3 ¤¤¤
[HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standardní diskové jednotky) - TOSHIBA MK5061GSYN +++++
--- User ---
[MBR] 66901dfd95c380d51515e8ad691d1b34
[BSP] d591c868d18c2835ba5cb21994e04de8 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 453540 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 929466368 | Size: 21048 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 972572672 | Size: 2043 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_10042013_113522.txt >>
RKreport[0]_S_10042013_101623.txt

Re: Preventivní kontrola

Napsal: 04 říj 2013 10:48
od dufina
RogueKiller V8.7.1 [Oct 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : HP [Práva správce]
Mód : Oprava HOSTS -- Datum : 10/04/2013 11:37:46
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost


Dokončeno : << RKreport[0]_H_10042013_113746.txt >>
RKreport[0]_D_10042013_113522.txt;RKreport[0]_S_10042013_101623.txt;RKreport[0]_S_10042013_113635.txt

Re: Preventivní kontrola

Napsal: 04 říj 2013 17:50
od Márty84
:arrow: Dejte novy log z RSIT

+

:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).