Prosba o kontrolu logu.
Napsal: 28 pro 2013 22:38
Zdravím Vás.Prosím o preventivní kontrolu logu.Občas mi při zobrazení výsledků v google zmizí "nalezené výsledky"...celá stránka kromě hlavičky.Po aktualizaci stránky se výsledky opět zobrazí.A to se děje několikrát.Děkuji za ochotu.Oslik6
Logfile of random's system information tool 1.08 (written by random/random)
Run by Pavilion at 2013-12-28 22:11:49
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 494 GB (82%) free of 598 GB
Total RAM: 3839 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:12:03, on 28.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Program Files\trend micro\Pavilion.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [CanonSolutionMenuEx] c:\program files (x86)\canon\solution menu ex\cnsemain.exe /logon
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Pavilion\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6437 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000648
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" /logon
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\splwow64.exe 12288
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3848.a45e100.997705845 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 3848 "\\.\pipe\gecko-crash-server-pipe.3848" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --proxy-stub-channel=Flash4304.6940B990.20586 --host-broker-channel=Flash4304.6940B990.25614 --host-pid=4304 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --channel=3940.0014F5D4.1554231409 --proxy-stub-channel=Flash4304.6940B990.20586 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --host-npapi-version=27 --type=renderer
taskhost.exe $(Arg0)
"C:\Users\Pavilion\Desktop\RSITx64(1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-29 553376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-29 211360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-14 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-14 170912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"=c:\program files\canon\myprinter\bjmyprt.exe [2010-03-24 2726728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autodesk Sync]
C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-18 684600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\program files (x86)\hp\hp software update\hpwuschd2.exe [2008-12-08 54576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe [2008-11-20 62768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KSS]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
c:\Program Files\Microsoft Security Client\msseces.exe [2013-10-23 1266912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
c:\program files (x86)\pdf complete\pdfsty.exe [2009-10-15 563736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"CanonSolutionMenuEx"=c:\program files (x86)\canon\solution menu ex\cnsemain.exe [2010-04-02 1185112]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-18 684600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EnableShellExecuteHooks"=1
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2013-12-20 19:54:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-15 01:31:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-15 01:31:39 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-15 01:31:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-15 01:31:39 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-15 01:31:39 ----A---- C:\Windows\system32\ieui.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-15 01:31:38 ----A---- C:\Windows\system32\iesetup.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\iernonce.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-15 01:31:37 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-15 01:31:37 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-15 01:31:37 ----A---- C:\Windows\system32\mshtml.dll
2013-12-15 01:31:37 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-15 01:31:37 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-15 01:31:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-15 01:31:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-15 01:31:36 ----A---- C:\Windows\system32\iertutil.dll
2013-12-15 01:31:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-15 01:31:35 ----A---- C:\Windows\system32\wininet.dll
2013-12-15 01:31:35 ----A---- C:\Windows\system32\urlmon.dll
2013-12-15 01:31:33 ----A---- C:\Windows\system32\ieframe.dll
2013-12-15 01:31:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-15 01:31:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-15 01:31:31 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-15 01:31:31 ----A---- C:\Windows\system32\jscript9.dll
2013-12-14 02:09:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-12-14 01:58:43 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-12-14 01:58:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-12-14 01:58:37 ----A---- C:\Windows\system32\elshyph.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\url.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msrating.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msls31.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msfeedssync.exe
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\jsIntl.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-12-14 01:58:32 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-14 01:58:32 ----A---- C:\Windows\system32\mshtmler.dll
2013-12-14 01:58:32 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-14 01:58:32 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\wextract.exe
2013-12-14 01:58:31 ----A---- C:\Windows\system32\webcheck.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\url.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\mshtmled.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\licmgr10.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\inseng.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\iexpress.exe
2013-12-14 01:58:31 ----A---- C:\Windows\system32\iedkcs32.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\icardie.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\dxtrans.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\dxtmsft.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\vbscript.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\pngfilt.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\occache.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\mshta.exe
2013-12-14 01:58:30 ----A---- C:\Windows\system32\jscript.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\imgutil.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\iepeers.dll
2013-12-12 01:45:07 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-12 01:45:06 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-12 01:45:06 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-12 01:45:04 ----A---- C:\Windows\system32\wmp.dll
2013-12-11 11:23:32 ----A---- C:\Windows\system32\msieftp.dll
2013-12-11 11:23:31 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-11 11:23:29 ----A---- C:\Windows\system32\win32k.sys
2013-12-11 11:23:28 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-11 11:23:28 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-11 11:23:27 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-11 11:23:27 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-11 11:23:24 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-11 11:23:24 ----A---- C:\Windows\system32\tzres.dll
2013-12-11 11:23:19 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 11:23:19 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 11:23:19 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-11 11:23:19 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 11:23:19 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 11:23:19 ----A---- C:\Windows\system32\cscript.exe
2013-12-01 22:07:17 ----D---- C:\Users\Pavilion\AppData\Roaming\Guitar Pro 6
2013-12-01 22:07:17 ----D---- C:\ProgramData\Guitar Pro 6
======List of files/folders modified in the last 1 months======
2013-12-28 22:12:03 ----D---- C:\Windows\Prefetch
2013-12-28 22:11:53 ----D---- C:\Program Files\trend micro
2013-12-28 22:10:48 ----D---- C:\Windows\temp
2013-12-28 21:59:39 ----D---- C:\Windows\system32\config
2013-12-28 20:49:36 ----D---- C:\Users\Pavilion\AppData\Roaming\QuickScan
2013-12-28 20:06:48 ----D---- C:\ProgramData\Spybot - Search & Destroy
2013-12-28 19:55:06 ----D---- C:\Users\Pavilion\AppData\Roaming\Winamp
2013-12-28 19:55:03 ----D---- C:\Windows\inf
2013-12-28 19:55:00 ----AD---- C:\Windows
2013-12-27 20:30:16 ----D---- C:\Program Files (x86)\The KMPlayer
2013-12-27 18:09:27 ----SHD---- C:\System Volume Information
2013-12-25 20:45:22 ----AD---- C:\Windows\System32
2013-12-25 20:45:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-22 00:18:46 ----D---- C:\ProgramData\PDFC
2013-12-21 08:48:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-20 21:13:31 ----D---- C:\Program Files (x86)
2013-12-18 07:58:53 ----D---- C:\Windows\system32\catroot
2013-12-18 07:58:52 ----D---- C:\Windows\system32\drivers
2013-12-16 10:16:49 ----D---- C:\Windows\debug
2013-12-16 00:42:05 ----D---- C:\Windows\system32\MRT
2013-12-16 00:39:52 ----A---- C:\Windows\system32\MRT.exe
2013-12-16 00:39:42 ----D---- C:\Windows\system32\catroot2
2013-12-15 09:35:01 ----D---- C:\Windows\winsxs
2013-12-15 09:34:02 ----D---- C:\Windows\SysWOW64
2013-12-15 09:34:02 ----D---- C:\Program Files\Internet Explorer
2013-12-15 09:34:02 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-14 19:20:36 ----D---- C:\Windows\system32\drivers\etc
2013-12-14 19:13:33 ----D---- C:\Windows\Panther
2013-12-14 19:13:33 ----D---- C:\Windows\Logs
2013-12-14 11:26:39 ----D---- C:\Windows\SYSWOW64\sv-SE
2013-12-14 11:26:38 ----D---- C:\Windows\SYSWOW64\nb-NO
2013-12-14 11:26:38 ----D---- C:\Windows\system32\sv-SE
2013-12-14 11:26:38 ----D---- C:\Windows\system32\nb-NO
2013-12-14 11:26:37 ----D---- C:\Windows\SYSWOW64\fi-FI
2013-12-14 11:26:37 ----D---- C:\Windows\system32\fi-FI
2013-12-14 11:26:36 ----D---- C:\Windows\SYSWOW64\da-DK
2013-12-14 11:26:36 ----D---- C:\Windows\system32\da-DK
2013-12-14 11:26:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-14 11:26:35 ----D---- C:\Windows\system32\cs-CZ
2013-12-14 11:26:32 ----D---- C:\Windows\SYSWOW64\migration
2013-12-14 11:26:31 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-14 11:26:28 ----D---- C:\Windows\system32\migration
2013-12-14 11:26:28 ----D---- C:\Windows\PolicyDefinitions
2013-12-14 11:26:27 ----D---- C:\Windows\system32\en-US
2013-12-12 10:16:07 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-12 10:16:05 ----D---- C:\Program Files\Windows Media Player
2013-12-12 10:15:54 ----D---- C:\Windows\system32\DriverStore
2013-12-12 01:44:45 ----SHD---- C:\Windows\Installer
2013-12-12 01:44:45 ----D---- C:\Config.Msi
2013-12-01 22:07:17 ----D---- C:\ProgramData
2013-11-30 13:47:53 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-03-10 16440]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-09-27 248240]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2013-12-18 131576]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2013-11-25 28600]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2013-12-18 108440]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-02 6366720]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-01 186880]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-03-31 2332192]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-21 38456]
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2009-10-23 46592]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 KORGUMDS;KORG USB-MIDI Driver for Windows x64 Edition; C:\Windows\System32\Drivers\KORGUM64.SYS [2009-10-15 31832]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 134944]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-10-26 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-04-09 243744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-10-26 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-02 202752]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-11-25 440376]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-12-18 440376]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-10-23 23808]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2009-10-15 635416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-02-19 1432400]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-20 119408]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-08-19 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
Logfile of random's system information tool 1.08 (written by random/random)
Run by Pavilion at 2013-12-28 22:11:49
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 494 GB (82%) free of 598 GB
Total RAM: 3839 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:12:03, on 28.12.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
C:\Program Files\trend micro\Pavilion.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [CanonSolutionMenuEx] c:\program files (x86)\canon\solution menu ex\cnsemain.exe /logon
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Pavilion\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 6437 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000648
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE" /logon
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" /logon
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\splwow64.exe 12288
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3848.a45e100.997705845 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 3848 "\\.\pipe\gecko-crash-server-pipe.3848" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --proxy-stub-channel=Flash4304.6940B990.20586 --host-broker-channel=Flash4304.6940B990.25614 --host-pid=4304 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --channel=3940.0014F5D4.1554231409 --proxy-stub-channel=Flash4304.6940B990.20586 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --host-npapi-version=27 --type=renderer
taskhost.exe $(Arg0)
"C:\Users\Pavilion\Desktop\RSITx64(1).exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-05-29 553376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-05-29 211360]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08 202144]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-14 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-14 170912]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CanonMyPrinter"=c:\program files\canon\myprinter\bjmyprt.exe [2010-03-24 2726728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autodesk Sync]
C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-18 684600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
c:\program files (x86)\hp\hp software update\hpwuschd2.exe [2008-12-08 54576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe [2008-11-20 62768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KSS]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
c:\Program Files\Microsoft Security Client\msseces.exe [2013-10-23 1266912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
c:\program files (x86)\pdf complete\pdfsty.exe [2009-10-15 563736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"CanonSolutionMenuEx"=c:\program files (x86)\canon\solution menu ex\cnsemain.exe [2010-04-02 1185112]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2013-12-18 684600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EnableShellExecuteHooks"=1
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2013-12-20 19:54:09 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-15 01:31:40 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-15 01:31:39 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-15 01:31:39 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-15 01:31:39 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-15 01:31:39 ----A---- C:\Windows\system32\ieui.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-15 01:31:38 ----A---- C:\Windows\system32\iesetup.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\iernonce.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-15 01:31:38 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-15 01:31:37 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-15 01:31:37 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-15 01:31:37 ----A---- C:\Windows\system32\mshtml.dll
2013-12-15 01:31:37 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-15 01:31:37 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-15 01:31:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-15 01:31:36 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-15 01:31:36 ----A---- C:\Windows\system32\iertutil.dll
2013-12-15 01:31:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-15 01:31:35 ----A---- C:\Windows\system32\wininet.dll
2013-12-15 01:31:35 ----A---- C:\Windows\system32\urlmon.dll
2013-12-15 01:31:33 ----A---- C:\Windows\system32\ieframe.dll
2013-12-15 01:31:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-15 01:31:31 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-15 01:31:31 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-15 01:31:31 ----A---- C:\Windows\system32\jscript9.dll
2013-12-14 02:09:44 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-12-14 01:58:43 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-12-14 01:58:43 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-12-14 01:58:37 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-12-14 01:58:37 ----A---- C:\Windows\system32\elshyph.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\url.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-12-14 01:58:36 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-14 01:58:35 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-12-14 01:58:34 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msrating.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msls31.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msfeedssync.exe
2013-12-14 01:58:33 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\jsIntl.dll
2013-12-14 01:58:33 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-12-14 01:58:32 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-14 01:58:32 ----A---- C:\Windows\system32\mshtmler.dll
2013-12-14 01:58:32 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-14 01:58:32 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\wextract.exe
2013-12-14 01:58:31 ----A---- C:\Windows\system32\webcheck.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\url.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\mshtmled.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\licmgr10.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\inseng.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\iexpress.exe
2013-12-14 01:58:31 ----A---- C:\Windows\system32\iedkcs32.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\icardie.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\dxtrans.dll
2013-12-14 01:58:31 ----A---- C:\Windows\system32\dxtmsft.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\vbscript.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\pngfilt.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\occache.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\mshta.exe
2013-12-14 01:58:30 ----A---- C:\Windows\system32\jscript.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\imgutil.dll
2013-12-14 01:58:30 ----A---- C:\Windows\system32\iepeers.dll
2013-12-12 01:45:07 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-12 01:45:06 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-12 01:45:06 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-12 01:45:04 ----A---- C:\Windows\system32\wmp.dll
2013-12-11 11:23:32 ----A---- C:\Windows\system32\msieftp.dll
2013-12-11 11:23:31 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-11 11:23:29 ----A---- C:\Windows\system32\win32k.sys
2013-12-11 11:23:28 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-11 11:23:28 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-11 11:23:27 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-11 11:23:27 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-11 11:23:24 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-11 11:23:24 ----A---- C:\Windows\system32\tzres.dll
2013-12-11 11:23:19 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-11 11:23:19 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-11 11:23:19 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-11 11:23:19 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 11:23:19 ----A---- C:\Windows\system32\scrrun.dll
2013-12-11 11:23:19 ----A---- C:\Windows\system32\cscript.exe
2013-12-01 22:07:17 ----D---- C:\Users\Pavilion\AppData\Roaming\Guitar Pro 6
2013-12-01 22:07:17 ----D---- C:\ProgramData\Guitar Pro 6
======List of files/folders modified in the last 1 months======
2013-12-28 22:12:03 ----D---- C:\Windows\Prefetch
2013-12-28 22:11:53 ----D---- C:\Program Files\trend micro
2013-12-28 22:10:48 ----D---- C:\Windows\temp
2013-12-28 21:59:39 ----D---- C:\Windows\system32\config
2013-12-28 20:49:36 ----D---- C:\Users\Pavilion\AppData\Roaming\QuickScan
2013-12-28 20:06:48 ----D---- C:\ProgramData\Spybot - Search & Destroy
2013-12-28 19:55:06 ----D---- C:\Users\Pavilion\AppData\Roaming\Winamp
2013-12-28 19:55:03 ----D---- C:\Windows\inf
2013-12-28 19:55:00 ----AD---- C:\Windows
2013-12-27 20:30:16 ----D---- C:\Program Files (x86)\The KMPlayer
2013-12-27 18:09:27 ----SHD---- C:\System Volume Information
2013-12-25 20:45:22 ----AD---- C:\Windows\System32
2013-12-25 20:45:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-22 00:18:46 ----D---- C:\ProgramData\PDFC
2013-12-21 08:48:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-20 21:13:31 ----D---- C:\Program Files (x86)
2013-12-18 07:58:53 ----D---- C:\Windows\system32\catroot
2013-12-18 07:58:52 ----D---- C:\Windows\system32\drivers
2013-12-16 10:16:49 ----D---- C:\Windows\debug
2013-12-16 00:42:05 ----D---- C:\Windows\system32\MRT
2013-12-16 00:39:52 ----A---- C:\Windows\system32\MRT.exe
2013-12-16 00:39:42 ----D---- C:\Windows\system32\catroot2
2013-12-15 09:35:01 ----D---- C:\Windows\winsxs
2013-12-15 09:34:02 ----D---- C:\Windows\SysWOW64
2013-12-15 09:34:02 ----D---- C:\Program Files\Internet Explorer
2013-12-15 09:34:02 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-14 19:20:36 ----D---- C:\Windows\system32\drivers\etc
2013-12-14 19:13:33 ----D---- C:\Windows\Panther
2013-12-14 19:13:33 ----D---- C:\Windows\Logs
2013-12-14 11:26:39 ----D---- C:\Windows\SYSWOW64\sv-SE
2013-12-14 11:26:38 ----D---- C:\Windows\SYSWOW64\nb-NO
2013-12-14 11:26:38 ----D---- C:\Windows\system32\sv-SE
2013-12-14 11:26:38 ----D---- C:\Windows\system32\nb-NO
2013-12-14 11:26:37 ----D---- C:\Windows\SYSWOW64\fi-FI
2013-12-14 11:26:37 ----D---- C:\Windows\system32\fi-FI
2013-12-14 11:26:36 ----D---- C:\Windows\SYSWOW64\da-DK
2013-12-14 11:26:36 ----D---- C:\Windows\system32\da-DK
2013-12-14 11:26:35 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-14 11:26:35 ----D---- C:\Windows\system32\cs-CZ
2013-12-14 11:26:32 ----D---- C:\Windows\SYSWOW64\migration
2013-12-14 11:26:31 ----D---- C:\Windows\SYSWOW64\en-US
2013-12-14 11:26:28 ----D---- C:\Windows\system32\migration
2013-12-14 11:26:28 ----D---- C:\Windows\PolicyDefinitions
2013-12-14 11:26:27 ----D---- C:\Windows\system32\en-US
2013-12-12 10:16:07 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-12 10:16:05 ----D---- C:\Program Files\Windows Media Player
2013-12-12 10:15:54 ----D---- C:\Windows\system32\DriverStore
2013-12-12 01:44:45 ----SHD---- C:\Windows\Installer
2013-12-12 01:44:45 ----D---- C:\Config.Msi
2013-12-01 22:07:17 ----D---- C:\ProgramData
2013-11-30 13:47:53 ----D---- C:\Windows\system32\NDF
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-03-10 16440]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-09-27 248240]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2013-12-18 131576]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2013-11-25 28600]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2013-12-18 108440]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atipmdag.sys [2010-02-02 6366720]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-02-01 186880]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-03-31 2332192]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2009-12-21 38456]
S3 AmUStor;AM USB Stroage Driver; C:\Windows\system32\drivers\AmUStor.SYS [2009-10-23 46592]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 KORGUMDS;KORG USB-MIDI Driver for Windows x64 Edition; C:\Windows\System32\Drivers\KORGUM64.SYS [2009-10-15 31832]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 134944]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-10-26 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-04-09 243744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-10-26 57856]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-02-02 202752]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-11-25 440376]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-12-18 440376]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-10-23 23808]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2009-10-15 635416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-02-19 1432400]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-12-20 119408]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 348376]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-08-19 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]