Logfile of random's system information tool 1.08 (written by random/random) Run by Filip at 2011-02-02 20:09:35 Microsoft Windows 7 Home Premium System drive C: has 392 GB (85%) free of 459 GB Total RAM: 2972 MB (59% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 20:09:44, on 2.2.2011 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16700) Boot mode: Normal Running processes: C:\windows\system32\Dwm.exe C:\windows\system32\taskhost.exe C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\windows\system32\igfxsrvc.exe C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\program files\steam\steamapps\common\alien swarm\srcds.exe C:\windows\system32\taskhost.exe C:\windows\explorer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\windows\system32\SearchFilterHost.exe C:\Users\Filip\Desktop\RSIT.exe C:\Program Files\trend micro\Filip.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll O4 - HKLM\..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe /start O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKCU\..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler O4 - HKCU\..\Run: [Google Update] "C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Global Startup: Bluetooth.lnk = ? O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200 O8 - Extra context menu item: Append the content of the link to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML O8 - Extra context menu item: Append the content of the selected links to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML O8 - Extra context menu item: Append to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML O8 - Extra context menu item: Create PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML O8 - Extra context menu item: Create PDF file from the content of the link - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML O8 - Extra context menu item: Create PDF files from the selected links - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - res://C:\Program Files\Nuance\PDF Professional 6\cnvres_eng.dll /100 O8 - Extra context menu item: Open with PDF Professional 6 - res://C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O15 - Trusted Zone: http://*.mcafee.com (HKLM) O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM) O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM) O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM) O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM) O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM) O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM) O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM) O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\aestsrv.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe O23 - Service: hpqwmiex - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\windows\system32\IoctlSvc.exe O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe -- End of file - 11756 bytes ======Scheduled tasks folder====== C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2907295079-3182079450-2103325329-1001Core.job C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2907295079-3182079450-2103325329-1001UA.job C:\windows\tasks\HPCeeScheduleForFilip.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{551A852F-39A6-44A7-9C13-AFBEC9185A9D}] PlusIEEventHelper Class - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll [2009-02-06 249856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}] Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2010-09-23 393600] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9}] ZeonIEEventHelper Class - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll [2009-03-26 475136] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-11-28 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - Nuance PDF - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll [2009-03-26 475136] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "QLBController"=C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-01-28 256056] "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2010-01-08 186904] "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-06-04 1791272] "WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-09-01 499768] "IgfxTray"=C:\windows\system32\igfxtray.exe [2010-03-12 141848] "HotKeysCmds"=C:\windows\system32\hkcmd.exe [2010-03-12 175640] "Persistence"=C:\windows\system32\igfxpers.exe [2010-03-12 166936] "SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2010-01-29 495708] "SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552] "MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"=C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2009-05-05 222496] "Google Update"=C:\Users\Filip\AppData\Local\Google\Update\GoogleUpdate.exe [2010-12-11 136176] "Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe [2008-06-27 91432] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee Managed Services Tray] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nuance PDF Reader-reminder] C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe [2008-11-03 328992] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe [2010-01-12 563736] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [2009-11-03 110880] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFHook] C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [2009-11-13 1277952] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD8LanguageShortcut] C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl8] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] C:\Program Files\Steam\Steam.exe -silent [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk] C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2002-09-25 113664] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\windows\system32\igfxdev.dll [2010-01-25 225792] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\wpdshserviceobj.dll [2009-07-14 105984] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"=credssp.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "ConsentPromptBehaviorAdmin"=5 "ConsentPromptBehaviorUser"=3 "EnableUIADesktopToggle"=0 "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] ======File associations====== .js - edit - C:\Windows\System32\Notepad.exe %1 .js - open - C:\Windows\System32\WScript.exe "%1" %* ======List of files/folders created in the last 1 months====== 2011-02-02 20:09:36 ----D---- C:\Program Files\trend micro 2011-02-02 20:09:35 ----D---- C:\rsit 2011-02-02 17:31:42 ----D---- C:\Program Files\SystemRequirementsLab 2011-02-02 14:04:43 ----D---- C:\Program Files\Common Files\Steam 2011-02-02 14:04:42 ----D---- C:\Program Files\Steam 2011-01-31 21:01:08 ----A---- C:\Users\Filip\AppData\Roaming\PnkBstrK.sys 2011-01-28 17:25:56 ----D---- C:\Users\Filip\AppData\Roaming\TeamViewer 2011-01-28 17:16:20 ----D---- C:\totalcmd 2011-01-28 16:35:51 ----D---- C:\Users\Filip\AppData\Roaming\mIRC 2011-01-27 21:08:59 ----D---- C:\Program Files\Metin 2 2011-01-26 20:21:55 ----SHD---- C:\windows\ftpcache 2011-01-26 20:19:30 ----D---- C:\Program Files\Activision 2011-01-26 19:58:21 ----D---- C:\ProgramData\SUPERAntiSpyware.com 2011-01-26 18:23:30 ----D---- C:\windows\Temp3F371995-3930-C07C-0FDC-766FFBA9D5ED-Signatures 2011-01-26 18:23:12 ----A---- C:\windows\system32\drivers\netio.sys 2011-01-26 14:20:57 ----D---- C:\windows\Temp96345407-EEAC-FF68-5ACF-3CD075FD68E6-Signatures 2011-01-26 14:20:45 ----D---- C:\Program Files\Microsoft Security Client 2011-01-25 19:23:19 ----D---- C:\ProgramData\Synetic 2011-01-25 18:13:42 ----D---- C:\Users\Filip\AppData\Roaming\ConMet 2011-01-25 18:13:42 ----D---- C:\ProgramData\ConMet 2011-01-24 19:11:03 ----D---- C:\Users\Filip\AppData\Roaming\FTP4Shell 2011-01-23 19:23:34 ----D---- C:\windows\ERDNT 2011-01-23 15:24:24 ----HD---- C:\windows\msdownld.tmp 2011-01-21 14:52:50 ----D---- C:\Program Files\XYplorer 2011-01-20 21:06:13 ----D---- C:\Program Files\uTorrent 2011-01-20 21:05:35 ----D---- C:\Users\Filip\AppData\Roaming\uTorrent 2011-01-20 20:49:40 ----D---- C:\Users\Filip\AppData\Roaming\IObit 2011-01-20 17:22:07 ----D---- C:\ProgramData\IObit 2011-01-20 17:19:00 ----A---- C:\windows\xptools.ini 2011-01-20 17:11:54 ----A---- C:\windows\system32\bn.dll 2011-01-18 20:53:31 ----D---- C:\Users\Filip\AppData\Roaming\hpqLog 2011-01-18 18:00:02 ----D---- C:\Users\Filip\AppData\Roaming\TuneUp Software 2011-01-18 17:59:38 ----D---- C:\ProgramData\TuneUp Software 2011-01-18 17:59:31 ----SHD---- C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2011-01-17 17:19:15 ----A---- C:\windows\system32\drivers\hamachi.sys 2011-01-16 13:56:27 ----D---- C:\Users\Filip\AppData\Roaming\Uniblue 2011-01-14 14:53:48 ----D---- C:\Users\Filip\AppData\Roaming\FileZilla 2011-01-14 14:09:00 ----A---- C:\windows\system32\twftpup.exe 2011-01-14 14:09:00 ----A---- C:\windows\system32\FTPReadMe.txt 2011-01-14 14:08:59 ----A---- C:\windows\system32\ftpshell.dll 2011-01-12 20:48:21 ----A---- C:\windows\system32\drivers\VBoxDrv.sys 2011-01-12 20:48:17 ----A---- C:\windows\system32\drivers\VBoxUSBMon.sys 2011-01-12 11:35:32 ----A---- C:\windows\system32\odbc32.dll 2011-01-12 11:35:12 ----A---- C:\windows\system32\XpsPrint.dll 2011-01-12 11:35:12 ----A---- C:\windows\system32\FntCache.dll 2011-01-12 11:35:12 ----A---- C:\windows\system32\DWrite.dll 2011-01-12 11:35:12 ----A---- C:\windows\system32\drivers\dxgkrnl.sys 2011-01-12 11:35:12 ----A---- C:\windows\system32\d3d10warp.dll 2011-01-12 11:35:12 ----A---- C:\windows\system32\d2d1.dll 2011-01-12 11:35:11 ----A---- C:\windows\system32\XpsRasterService.dll 2011-01-12 11:35:11 ----A---- C:\windows\system32\XpsGdiConverter.dll 2011-01-12 11:35:11 ----A---- C:\windows\system32\ExplorerFrame.dll 2011-01-12 11:35:11 ----A---- C:\windows\system32\drivers\dxgmms1.sys 2011-01-12 11:35:11 ----A---- C:\windows\system32\d3d10_1core.dll 2011-01-12 11:35:11 ----A---- C:\windows\system32\d3d10_1.dll 2011-01-12 11:35:11 ----A---- C:\windows\system32\cdd.dll 2011-01-11 18:06:26 ----AH---- C:\windows\system32\hamachi.sys 2011-01-08 17:43:56 ----D---- C:\Users\Filip\AppData\Roaming\DonationCoder 2011-01-07 14:39:43 ----D---- C:\Program Files\Lavalys 2011-01-04 17:44:22 ----A---- C:\windows\SetACL.exe 2011-01-03 20:26:54 ----A---- C:\windows\system32\wbhelp2.dll 2011-01-03 20:20:20 ----A---- C:\windows\uninst.exe ======List of files/folders modified in the last 1 months====== 2011-02-02 20:09:42 ----D---- C:\windows\Temp 2011-02-02 20:09:36 ----D---- C:\Program Files 2011-02-02 19:49:55 ----D---- C:\Users\Filip\AppData\Roaming\Skype 2011-02-02 19:47:48 ----SHD---- C:\windows\Installer 2011-02-02 19:47:48 ----RSD---- C:\windows\assembly 2011-02-02 19:47:48 ----D---- C:\Program Files\Common Files\microsoft shared 2011-02-02 19:47:42 ----SHD---- C:\System Volume Information 2011-02-02 19:25:51 ----D---- C:\windows\Prefetch 2011-02-02 18:59:04 ----D---- C:\Users\Filip\AppData\Roaming\skypePM 2011-02-02 17:53:18 ----D---- C:\Windows 2011-02-02 17:00:56 ----D---- C:\windows\system32\Tasks 2011-02-02 16:50:22 ----D---- C:\windows\system32\config 2011-02-02 14:04:43 ----D---- C:\Program Files\Common Files 2011-02-02 13:52:50 ----D---- C:\windows\System32 2011-02-01 21:04:19 ----D---- C:\windows\system32\drivers 2011-02-01 21:04:05 ----HD---- C:\ProgramData 2011-02-01 16:17:26 ----HD---- C:\Program Files\InstallShield Installation Information 2011-01-31 18:30:11 ----RD---- C:\Users 2011-01-31 18:29:29 ----SHD---- C:\$Recycle.Bin 2011-01-31 15:39:11 ----D---- C:\windows\rescache 2011-01-30 16:05:31 ----D---- C:\windows\system32\NDF 2011-01-29 19:50:19 ----D---- C:\windows\Tasks 2011-01-29 18:03:22 ----D---- C:\windows\system32\catroot2 2011-01-28 17:16:44 ----D---- C:\Users\Filip\AppData\Roaming\GHISLER 2011-01-27 21:11:33 ----AD---- C:\ProgramData\TEMP 2011-01-27 20:04:08 ----D---- C:\windows\winsxs 2011-01-27 20:04:05 ----D---- C:\Program Files\Windows Sidebar 2011-01-26 20:21:45 ----A---- C:\windows\game.ini 2011-01-26 20:14:13 ----D---- C:\windows\system32\wdi 2011-01-26 18:23:40 ----D---- C:\windows\system32\catroot 2011-01-26 18:23:40 ----A---- C:\windows\system32\PerfStringBackup.INI 2011-01-26 18:07:03 ----D---- C:\windows\system32\wfp 2011-01-26 18:07:01 ----D---- C:\windows\system32\wbem 2011-01-26 18:06:19 ----D---- C:\windows\system32\DriverStore 2011-01-26 18:06:18 ----D---- C:\windows\Downloaded Program Files 2011-01-26 18:06:04 ----D---- C:\windows\system32\drivers\etc 2011-01-26 18:06:02 ----D---- C:\windows\inf 2011-01-26 18:05:48 ----D---- C:\windows\registration 2011-01-26 18:04:34 ----SD---- C:\ProgramData\Microsoft 2011-01-25 19:20:09 ----D---- C:\windows\Logs 2011-01-24 13:23:38 ----D---- C:\Program Files\WinRAR 2011-01-23 19:54:09 ----D---- C:\windows\system32\cs-CZ 2011-01-23 19:54:06 ----D---- C:\Program Files\CCleaner 2011-01-23 19:53:59 ----SD---- C:\Users\Filip\AppData\Roaming\Microsoft 2011-01-23 15:24:24 ----D---- C:\Program Files\Internet Explorer 2011-01-21 15:18:30 ----HD---- C:\hp 2011-01-20 20:52:39 ----D---- C:\windows\Panther 2011-01-20 20:52:39 ----D---- C:\windows\Hewlett-Packard 2011-01-20 20:52:39 ----D---- C:\ProgramData\Roxio 2011-01-20 20:52:39 ----D---- C:\Program Files\Mozilla Firefox 2011-01-20 20:52:39 ----D---- C:\Program Files\Crazy Machines - New Challenges 2011-01-20 15:37:27 ----D---- C:\Users\Filip\AppData\Roaming\Hamachi 2011-01-20 15:30:28 ----DC---- C:\windows\system32\DRVSTORE 2011-01-17 14:12:25 ----D---- C:\windows\system32\CodeIntegrity 2011-01-17 14:12:25 ----D---- C:\windows\servicing 2011-01-17 14:12:10 ----D---- C:\Users\Filip\AppData\Roaming\Scirra 2011-01-17 14:12:08 ----D---- C:\Users\Filip\AppData\Roaming\GRETECH 2011-01-17 14:12:03 ----D---- C:\ProgramData\Spybot - Search & Destroy 2011-01-17 14:12:02 ----D---- C:\Program Files\HyperCam 3 2011-01-17 14:12:00 ----D---- C:\Program Files\Common Files\Solveig Multimedia 2011-01-17 14:11:33 ----D---- C:\windows\system32\NetworkList 2011-01-17 14:10:51 ----D---- C:\Users\Filip\AppData\Roaming\Zeon 2011-01-17 14:10:50 ----D---- C:\Users\Filip\AppData\Roaming\Opera 2011-01-17 14:10:50 ----D---- C:\Users\Filip\AppData\Roaming\Nero 2011-01-17 14:10:50 ----D---- C:\Users\Filip\AppData\Roaming\Mozilla 2011-01-17 14:10:47 ----D---- C:\Users\Filip\AppData\Roaming\Macromedia 2011-01-17 14:10:47 ----D---- C:\Users\Filip\AppData\Roaming\FLEXnet 2011-01-17 14:10:47 ----D---- C:\Users\Filip\AppData\Roaming\COWON 2011-01-17 14:10:46 ----D---- C:\Users\Filip\AppData\Roaming\Corel 2011-01-17 14:10:46 ----D---- C:\Users\Filip\AppData\Roaming\Adobe 2011-01-16 13:45:36 ----D---- C:\windows\system32\LogFiles 2011-01-12 20:06:54 ----D---- C:\windows\debug 2011-01-12 14:35:34 ----A---- C:\windows\system32\MRT.exe 2011-01-12 14:35:26 ----D---- C:\ProgramData\Microsoft Help 2011-01-04 15:06:59 ----D---- C:\ProgramData\Hewlett-Packard ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-01-08 331288] R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648] R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-11-21 436792] R1 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2010-10-24 165264] R1 MpKsl8d91ea3f;MpKsl8d91ea3f; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E5B25CE7-467F-4E5D-8743-A751013E333C}\MpKsl8d91ea3f.sys [2011-02-02 28752] R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128] R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl [2008-06-27 61424] R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-07-13 1035776] R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816] R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696] R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880] R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2010-01-07 86056] R3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2010-01-07 108072] R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2010-01-07 29472] R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2010-01-07 18472] R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-07-16 15872] R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2010-01-25 6282240] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\windows\system32\drivers\IntcHdmi.sys [2009-07-09 122880] R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392] R3 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144] R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536] R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt86win7.sys [2010-06-23 275048] R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\windows\system32\DRIVERS\rtl8192se.sys [2010-01-29 997408] R3 rtsuvc;HP Webcam [2 MP Fixed]; C:\windows\system32\DRIVERS\rtsuvc.sys [2010-01-30 73344] R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2010-01-29 423424] R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-06-04 1303728] R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 14336] S1 MpKsl99321856;MpKsl99321856; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{4B63D148-2672-4F9B-8EEE-CCFA4A611F34}\MpKsl99321856.sys [] S2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704] S3 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720] S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888] S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704] S3 EagleNT;EagleNT; \??\C:\windows\system32\drivers\EagleNT.sys [] S3 esihdrv;esihdrv; \??\C:\Users\Filip\AppData\Local\Temp\esihdrv.sys [] S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2010-09-23 39272] S3 hamachi;Hamachi Network Interface; C:\windows\system32\DRIVERS\hamachi.sys [2011-01-17 25280] S3 msloop;Microsoft Loopback Adapter Driver; C:\windows\system32\DRIVERS\loop.sys [2009-07-14 5632] S3 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368] S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304] S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\windows\system32\DRIVERS\VBoxNetAdp.sys [2009-12-17 99152] S3 VBoxNetFlt;VBoxNetFlt Service; C:\windows\system32\DRIVERS\VBoxNetFlt.sys [] S3 VBoxUSB;VirtualBox USB; C:\windows\System32\Drivers\VBoxUSB.sys [2009-12-17 31824] S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328] S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\aestsrv.exe [2009-03-03 81920] R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-12-29 595232] R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2009-10-15 120832] R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-01-28 265272] R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2010-01-08 354840] R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2010-01-22 73728] R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736] R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864] R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2010-01-12 635416] R2 PDFProFiltSrv;PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-11-03 134944] R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\windows\system32\IoctlSvc.exe [2006-12-19 81920] R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136] R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe [2010-01-29 229458] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464] R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-12-17 230968] R3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352] S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-06-11 136120] S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888] S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-11-19 1343400] S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] -----------------EOF-----------------