I ran KL-Detector and this was the report
Below are some file operations that were done during the monitoring process.
Review them carefully and check for suspicious files.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\SchedLgU.Txt
was modified.
C:\WINDOWS\SchedLgU.Txt
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\CONFIG\AVWIN.INI
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\wbem\Logs\wbemcore.log
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
No suspicious files were found in your hard disk
You MAY want to take a look at:
C:\WINDOWS\system32\config\
Below are some file operations that were done during the monitoring process.
Review them carefully and check for suspicious files.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\SchedLgU.Txt
was modified.
C:\WINDOWS\SchedLgU.Txt
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\CONFIG\AVWIN.INI
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\wbem\Logs\wbemcore.log
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP
was modified.
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\Tasks\User_Feed_Synchronization-{34CD53BE-07A6-4108-B6CE-D8E418EA34BA}.job
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
C:\WINDOWS\system32\config\software.LOG
was modified.
No suspicious files were found in your hard disk
You MAY want to take a look at:
C:\WINDOWS\system32\config\