Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Logfile of random's system information tool 1.09 (written by random/random)
- Run by Daniela at 2013-05-07 22:01:17
- Microsoft Windows 7 Home Premium Service Pack 1
- System drive C: has 205 GB (71%) free of 288 GB
- Total RAM: 1979 MB (43% free)
- Logfile of Trend Micro HijackThis v2.0.4
- Scan saved at 22:01:21, on 7. 5. 2013
- Platform: Windows 7 SP1 (WinNT 6.00.3505)
- MSIE: Internet Explorer v10.0 (10.00.9200.16537)
- Boot mode: Normal
- Running processes:
- C:\ProgramData\DatacardService\DCSHelper.exe
- C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
- C:\Users\Daniela\AppData\Roaming\QipGuard\QipGuard.exe
- C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
- C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- C:\Program Files (x86)\Opera\opera.exe
- C:\Users\Daniela\AppData\Local\Opera\Opera\temporary_downloads\RSIT.exe
- C:\Program Files (x86)\trend micro\Daniela.exe
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- R3 - URLSearchHook: (no name) - - (no file)
- F2 - REG:system.ini: UserInit=userinit.exe
- O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
- O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
- O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
- O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
- O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
- O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
- O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
- O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
- O4 - HKLM\..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
- O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
- O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
- O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\Daniela\AppData\Roaming\QipGuard\QipGuard.exe /p
- O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
- O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
- O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
- O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
- O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
- O4 - Startup: My_AutoWarkey_Script.lnk = C:\Program Files (x86)\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
- O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
- O9 - Extra button: Pridať do blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
- O9 - Extra 'Tools' menuitem: &Pridať do blogu v programe Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
- O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
- O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
- O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
- O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
- O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
- O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
- O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
- O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
- O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
- O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
- O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
- O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
- O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
- O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
- O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
- O23 - Service: DCService.exe - Unknown owner - C:\ProgramData\DatacardService\DCService.exe
- O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
- O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
- O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
- O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
- O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
- O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
- O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
- O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
- O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
- O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
- O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
- O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
- O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: QipGuard - QIP.ru - C:\Program Files (x86)\QipGuard\QipGuard.exe
- O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
- O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
- O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
- O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
- O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
- O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
- O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
- O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
- O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
- O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
- --
- End of file - 11194 bytes
- ======Scheduled tasks folder======
- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
- C:\Windows\tasks\HPCeeScheduleForDaniela.job
- =========Mozilla firefox=========
- ProfilePath - C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\rf8t6gmc.default
- prefs.js - "browser.startup.homepage" - "http://www.centrum.sk/"
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
- "Description"=Adobe® Flash® Player 11.4.402.265 Plugin
- "Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
- "Description"=Adobe Shockwave Player
- "Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
- "Description"=Google Earth in your browser
- "Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.17.2]
- "Description"=Java™ Deployment Toolkit
- "Path"=C:\Windows\SysWOW64\npDeployJava1.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2]
- "Description"=Oracle® Next Generation Java™ Plug-In
- "Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
- "Description"=
- "Path"=disabled
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
- "Description"=Ag Player Plugin
- "Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416]
- "Description"=WLPG Install MIME type
- "Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
- "Description"=This plugin detects and launches Pando Media Booster
- "Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
- "Description"=Google Update
- "Path"=C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
- "Description"=Google Update
- "Path"=C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
- "Description"=Veetle TV Core
- "Path"=C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
- "Description"=Veetle TV Player
- "Path"=C:\Program Files (x86)\Veetle\Player\npvlc.dll
- [HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
- "Description"=Handles PDFs in-place in Firefox
- "Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
- C:\Program Files (x86)\Mozilla Firefox\extensions\
- {972ce4c6-7e08-4474-a285-3208198ce6fd}
- C:\Program Files (x86)\Mozilla Firefox\components\
- binary.manifest
- browsercomps.dll
- C:\Program Files (x86)\Mozilla Firefox\searchplugins\
- amazondotcom.xml
- bing.xml
- eBay.xml
- google.xml
- twitter.xml
- wikipedia.xml
- yahoo.xml
- C:\Users\Daniela\AppData\Roaming\Mozilla\Firefox\Profiles\rf8t6gmc.default\extensions\
- {2458abc0-f443-11dd-87af-0800200c9a66}
- {b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- ======Registry dump======
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
- Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
- Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
- Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-03-06 461216]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
- Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
- Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17 3855520]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
- Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-03-06 170912]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- "HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2010-07-02 602680]
- "Easybits Recovery"=C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [2010-06-02 61112]
- "GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
- "B2C_AGENT"=C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe [2012-03-28 404568]
- "Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
- "SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
- "LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-05-19 2736128]
- "QIP Internet Guardian"=C:\Users\Daniela\AppData\Roaming\QipGuard\QipGuard.exe [2011-02-01 187776]
- "DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
- C:\Users\Daniela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
- My_AutoWarkey_Script.lnk - C:\Program Files (x86)\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
- WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
- "{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2010-08-14 52920]
- "UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"= []
- "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
- "SecurityProviders"=credssp.dll
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
- "DisableLockWorkstation"=0
- "DisableTaskMgr"=0
- "DisableChangePassword"=0
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
- "ConsentPromptBehaviorAdmin"=5
- "ConsentPromptBehaviorUser"=3
- "EnableUIADesktopToggle"=0
- "dontdisplaylastusername"=0
- "legalnoticecaption"=
- "legalnoticetext"=
- "shutdownwithoutlogon"=1
- "undockwithoutlogon"=1
- "HideFastUserSwitching"=0
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
- "NoActiveDesktop"=1
- "NoActiveDesktopChanges"=1
- "ForceActiveDesktopOn"=0
- "EnableShellExecuteHooks"=1
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
- [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
- "vidc.mrle"=msrle32.dll
- "vidc.msvc"=msvidc32.dll
- "msacm.imaadpcm"=imaadp32.acm
- "msacm.msg711"=msg711.acm
- "msacm.msgsm610"=msgsm32.acm
- "msacm.msadpcm"=msadp32.acm
- "midimapper"=midimap.dll
- "wavemapper"=msacm32.drv
- "vidc.uyvy"=msyuv.dll
- "vidc.yuy2"=msyuv.dll
- "vidc.yvyu"=msyuv.dll
- "vidc.iyuv"=iyuv_32.dll
- "vidc.i420"=iyuv_32.dll
- "vidc.yvu9"=tsbyuv.dll
- "msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
- "vidc.cvid"=iccvid.dll
- "wave"=wdmaud.drv
- "midi"=wdmaud.drv
- "mixer"=wdmaud.drv
- "aux"=wdmaud.drv
- "msacm.siren"=sirenacm.dll
- "msacm.vorbis"=vorbis.acm
- ======File associations======
- .js - edit - C:\Windows\System32\Notepad.exe %1
- .js - open - C:\Windows\System32\WScript.exe "%1" %*
- ======List of files/folders created in the last 1 month======
- 2013-05-07 18:56:24 ----A---- C:\AdwCleaner[S2].txt
- 2013-05-07 17:27:34 ----A---- C:\AdwCleaner[S1].txt
- 2013-05-07 17:24:37 ----A---- C:\AdwCleaner[R1].txt
- 2013-05-07 17:12:09 ----D---- C:\Program Files (x86)\trend micro
- 2013-05-07 17:12:08 ----D---- C:\rsit
- 2013-05-07 17:07:39 ----D---- C:\Windows\pss
- 2013-05-07 13:52:55 ----A---- C:\Windows\wininit.ini
- 2013-05-06 17:35:18 ----AD---- C:\Kaspersky Rescue Disk 10.0
- 2013-04-22 17:37:48 ----D---- C:\Program Files (x86)\Mozilla Firefox
- 2013-04-10 22:30:00 ----A---- C:\Windows\SysWOW64\ieui.dll
- 2013-04-10 22:29:57 ----A---- C:\Windows\SysWOW64\iesetup.dll
- 2013-04-10 22:29:56 ----A---- C:\Windows\SysWOW64\RegisterIEPKEYs.exe
- 2013-04-10 22:29:56 ----A---- C:\Windows\SysWOW64\msfeeds.dll
- 2013-04-10 22:29:56 ----A---- C:\Windows\SysWOW64\iesysprep.dll
- 2013-04-10 22:29:56 ----A---- C:\Windows\SysWOW64\iernonce.dll
- 2013-04-10 22:29:55 ----A---- C:\Windows\SysWOW64\iertutil.dll
- 2013-04-10 22:29:52 ----A---- C:\Windows\SysWOW64\urlmon.dll
- 2013-04-10 22:29:51 ----A---- C:\Windows\SysWOW64\jscript.dll
- 2013-04-10 22:29:49 ----A---- C:\Windows\SysWOW64\jscript9.dll
- 2013-04-10 22:29:47 ----A---- C:\Windows\SysWOW64\jsproxy.dll
- 2013-04-10 22:29:46 ----A---- C:\Windows\SysWOW64\wininet.dll
- 2013-04-10 22:29:41 ----A---- C:\Windows\SysWOW64\ieframe.dll
- 2013-04-10 22:29:34 ----A---- C:\Windows\SysWOW64\mshtml.dll
- 2013-04-10 21:04:02 ----A---- C:\Windows\SysWOW64\mstscax.dll
- 2013-04-10 21:04:00 ----A---- C:\Windows\SysWOW64\aaclient.dll
- 2013-04-10 21:03:59 ----A---- C:\Windows\SysWOW64\tsgqec.dll
- 2013-04-10 21:03:42 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
- 2013-04-10 21:03:41 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
- 2013-04-10 21:03:39 ----A---- C:\Windows\SysWOW64\apisetschema.dll
- ======List of files/folders modified in the last 1 month======
- 2013-05-07 22:01:22 ----D---- C:\Windows\Prefetch
- 2013-05-07 22:01:21 ----D---- C:\Windows\Temp
- 2013-05-07 19:13:30 ----D---- C:\Windows\System32
- 2013-05-07 19:13:23 ----D---- C:\Windows\inf
- 2013-05-07 18:56:51 ----D---- C:\Program Files (x86)
- 2013-05-07 18:56:45 ----HD---- C:\ProgramData
- 2013-05-07 18:49:29 ----D---- C:\Program Files (x86)\Opera
- 2013-05-07 18:45:47 ----A---- C:\Windows\SysWOW64\lgAxconfig.ini
- 2013-05-07 17:58:21 ----AD---- C:\Windows
- 2013-05-07 14:58:27 ----D---- C:\Users\Daniela\AppData\Roaming\DAEMON Tools Pro
- 2013-05-07 14:58:27 ----D---- C:\Users\Daniela\AppData\Roaming\DAEMON Tools Lite
- 2013-05-07 14:58:20 ----D---- C:\Users\Daniela\AppData\Roaming\uTorrent
- 2013-05-07 14:58:20 ----D---- C:\Users\Daniela\AppData\Roaming\Skype
- 2013-05-07 14:57:55 ----D---- C:\Windows\Panther
- 2013-05-07 14:57:55 ----D---- C:\Windows\ModemLogs
- 2013-05-07 14:57:55 ----D---- C:\Windows\Minidump
- 2013-05-07 14:57:55 ----D---- C:\Windows\Logs
- 2013-05-07 14:57:55 ----D---- C:\Windows\debug
- 2013-05-07 14:00:20 ----RD---- C:\Program Files
- 2013-05-07 06:40:42 ----D---- C:\Windows\winsxs
- 2013-05-07 06:22:12 ----SHD---- C:\System Volume Information
- 2013-05-06 21:03:43 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
- 2013-05-06 15:31:14 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
- 2013-04-29 21:20:09 ----D---- C:\Program Files (x86)\Mozilla Firefox.bak
- 2013-04-22 12:00:44 ----D---- C:\Users\Daniela\AppData\Roaming\vlc
- 2013-04-11 15:14:04 ----D---- C:\Windows\SysWOW64
- 2013-04-11 15:14:02 ----D---- C:\Program Files (x86)\Internet Explorer
- 2013-04-10 22:31:17 ----SHD---- C:\Windows\Installer
- 2013-04-10 22:31:07 ----D---- C:\ProgramData\Microsoft Help
- ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
- R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys []
- R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
- R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
- R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
- R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
- R2 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
- R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
- R2 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
- R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys []
- R3 BTMUSB;Motorola Bluetooth Radio Service; C:\Windows\System32\Drivers\btmusb.sys []
- R3 Epfwndis;Eset Personal Firewall; C:\Windows\system32\DRIVERS\Epfwndis.sys []
- R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys []
- R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
- R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
- R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys []
- R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys []
- R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
- S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys []
- S3 Andbus;LGE Android Platform Composite USB Device; C:\Windows\system32\DRIVERS\lgandbus64.sys []
- S3 AndDiag;LGE Android Platform USB Serial Port; C:\Windows\system32\DRIVERS\lganddiag64.sys []
- S3 AndGps;LGE Android Platform USB GPS NMEA Port; C:\Windows\system32\DRIVERS\lgandgps64.sys []
- S3 ANDModem;LGE Android Platform USB Modem; C:\Windows\system32\DRIVERS\lgandmodem64.sys []
- S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys []
- S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys []
- S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys []
- S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys []
- S3 BTMCOM;Bluetooth Serial Port; C:\Windows\System32\Drivers\btmcom.sys []
- S3 busenum;SteelBusSvc; C:\Windows\system32\DRIVERS\SteelBus64.sys []
- S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys []
- S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys []
- S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
- S3 KMWDFILTER;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys []
- S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys []
- S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
- S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys []
- S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
- S3 SAlphamHid;SteelHIDSvc; C:\Windows\system32\DRIVERS\SAlpham64.sys []
- S3 sdbus;sdbus; C:\Windows\system32\drivers\sdbus.sys []
- S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS []
- S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS []
- S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS []
- S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
- S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []
- ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
- R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
- R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
- R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
- R2 DCService.exe;DCService.exe; C:\ProgramData\DatacardService\DCService.exe [2010-05-08 229376]
- R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144]
- R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\System32\ezSharedSvcHost.exe [2010-04-23 514232]
- R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
- R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
- R2 QipGuard;QipGuard; C:\Program Files (x86)\QipGuard\QipGuard.exe [2011-02-01 187776]
- R2 RtVOsdService;RtVOsdService Installer; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [2010-04-19 315392]
- R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
- R3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
- R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-08-17 1028096]
- R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-03-28 799800]
- S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
- S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
- S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-18 136176]
- S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
- S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
- S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2011-01-12 42360]
- S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-08-17 647680]
- S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-18 136176]
- S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
- S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-04-22 115608]
- S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
- S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
- S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
- S4 msvsmon90;Visual Studio 2008 Remote Debugger; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [2008-07-29 4737024]
- S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
- S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
- S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
- -----------------EOF-----------------
Advertisement
Add Comment
Please, Sign In to add comment