
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Trojan-spy.win32.year2010-wors
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Trojan-spy.win32.year2010-wors
tak PC sa tvári normálne..ale je zase problem so scanom z RSITu vypisuje mi to chybu AutoIT error,Error:Subscript used with non-Array variable...
Re: Trojan-spy.win32.year2010-wors


Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors
nemôžem to nijako spustiť,stále vypisuje tú istú chybu...neviem,čo sa mohlo stať...ale skúsil som ho spustiť na druhom účte a tam ten scan prebehol...ak to pomôže tu je:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2010-08-17 15:16:31
Microsoft Windows 7 Professional
System drive C: has 119 GB (54%) free of 221 GB
Total RAM: 1973 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:16:44, on 17. 8. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HooTech\NetMeter\HooNetMeter.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender_gui.exe
C:\windows\Explorer.EXE
C:\windows\system32\SearchFilterHost.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Users\Lukáš\Desktop\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [IFXSPMGT] "C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Lukáš')
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [NetMeter] C:\Program Files\HooTech\NetMeter\HooNetMeter.exe (User 'Lukáš')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP SkyRoom (Hp.Skyroom.Windows.Service) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: Remote Graphics Sender Service (rgsender) - Hewlett-Packard, Inc. - c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 13241 bytes
======Scheduled tasks folder======
C:\windows\tasks\Embedded Security Backup Schedule.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-11-04 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-11-24 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-12 287800]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"NUSB3MON"=c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-21 106496]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2009-11-20 1690680]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-07-26 1713448]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [2009-11-20 363064]
"IMSS"=C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2009-11-04 111640]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-11-18 495708]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"IFXSPMGT"=C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
"acevents"=C:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-03 153640]
"accrdsub"=C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-03 400936]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-11-04 11264000]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2007-12-21 1443072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-09 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
wlnotify.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ip6fw.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLmSsp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpcdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpwd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdpipe.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdtcp.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\termservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-08-17 15:12:43 ----A---- C:\windows\system32\drivers\sptd.sys
2010-08-17 15:12:19 ----D---- C:\Program Files\DAEMON Tools Lite
2010-08-16 23:23:55 ----D---- C:\rsit
2010-08-16 21:19:23 ----SHD---- C:\$RECYCLE.BIN
2010-08-16 20:56:55 ----A---- C:\windows\MBR.exe
2010-08-16 20:56:54 ----A---- C:\windows\PEV.exe
2010-08-16 20:56:45 ----D---- C:\windows\ERDNT
2010-08-16 20:14:13 ----D---- C:\windows\system32\Wat
2010-08-16 19:06:27 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2010-08-16 19:06:26 ----D---- C:\ProgramData\Malwarebytes
2010-08-16 19:06:26 ----A---- C:\windows\system32\drivers\mbam.sys
2010-08-16 19:06:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-08-15 06:28:17 ----D---- C:\Program Files\trend micro
2010-08-15 05:25:04 ----A---- C:\windows\system32\mshtml.dll
2010-08-15 05:25:04 ----A---- C:\windows\system32\ieframe.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\wininet.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\urlmon.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\mstime.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedssync.exe
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedsbs.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\jsproxy.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\ieui.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iepeers.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iedkcs32.dll
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntoskrnl.exe
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-08-15 05:24:45 ----A---- C:\windows\system32\drivers\tcpip.sys
2010-08-15 05:24:44 ----A---- C:\windows\system32\win32k.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\rtutils.dll
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv2.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv.sys
2010-08-15 05:24:42 ----A---- C:\windows\system32\schannel.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\ir32_32.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\iccvid.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\drivers\srvnet.sys
2010-08-15 05:24:41 ----A---- C:\windows\system32\msxml3.dll
2010-08-15 04:57:06 ----D---- C:\NVIDIA
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DX9_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\d3dx10_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DCompiler_39.dll
2010-08-06 20:21:31 ----D---- C:\windows\system32\AGEIA
2010-08-06 20:21:30 ----D---- C:\Program Files\AGEIA Technologies
2010-08-03 20:43:07 ----A---- C:\windows\system32\shell32.dll
2010-08-02 09:45:04 ----D---- C:\ProgramData\LightScribe
2010-08-02 09:21:07 ----D---- C:\Program Files\Nero
2010-08-02 09:20:45 ----D---- C:\ProgramData\Nero
2010-08-02 09:20:43 ----D---- C:\Program Files\Common Files\Nero
2010-08-02 09:20:26 ----D---- C:\Program Files\Common Files\LightScribe
2010-08-02 02:24:43 ----D---- C:\windows\system32\appmgmt
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAudio2_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAPOFX1_4.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\xactengine3_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\X3DAudio1_7.dll
2010-07-26 15:11:50 ----A---- C:\windows\system32\SynTPCo4.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\SynTPAPI.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\drivers\SynTP.sys
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCtrl.dll
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCOM.dll
2010-07-26 15:00:11 ----D---- C:\ProgramData\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewusbmdm.sys
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewdcsc.sys
2010-07-25 13:11:20 ----D---- C:\Program Files\Huawei technologies
2010-07-25 01:03:50 ----D---- C:\ProgramData\NVIDIA Corporation
2010-07-22 23:08:31 ----A---- C:\windows\system32\msv1_0.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHostProxy.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHost.exe
2010-07-22 23:07:22 ----A---- C:\windows\system32\netfxperf.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\mscoree.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\dfshim.dll
2010-07-22 23:03:55 ----A---- C:\windows\system32\MRT.exe
2010-07-22 23:00:44 ----A---- C:\windows\system32\browserchoice.exe
2010-07-22 23:00:11 ----D---- C:\Program Files\MSXML 4.0
2010-07-22 22:59:11 ----A---- C:\windows\system32\lsasrv.dll
2010-07-22 22:59:11 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2010-07-22 22:59:10 ----A---- C:\windows\system32\inetcomm.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\ntdll.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\msasn1.dll
2010-07-22 22:59:04 ----A---- C:\windows\explorer.exe
2010-07-22 22:59:03 ----A---- C:\windows\system32\winlogon.exe
2010-07-22 22:59:02 ----A---- C:\windows\system32\tzres.dll
2010-07-22 22:58:58 ----A---- C:\windows\system32\drivers\fvevol.sys
2010-07-22 22:58:56 ----A---- C:\windows\system32\wmp.dll
2010-07-22 22:58:55 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2010-07-22 22:58:55 ----A---- C:\windows\system32\CertEnroll.dll
2010-07-22 22:58:54 ----A---- C:\windows\system32\winresume.exe
2010-07-22 22:58:54 ----A---- C:\windows\system32\winload.exe
2010-07-22 22:58:53 ----A---- C:\windows\system32\wmploc.DLL
2010-07-22 22:58:50 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2010-07-22 22:58:36 ----A---- C:\windows\system32\msdri.dll
2010-07-22 22:58:36 ----A---- C:\windows\system32\CPFilters.dll
2010-07-22 22:58:35 ----A---- C:\windows\system32\psisdecd.dll
2010-07-22 22:58:31 ----A---- C:\windows\system32\kernel32.dll
2010-07-22 22:58:30 ----A---- C:\windows\system32\apphelp.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\tsbyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\quartz.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msvidc32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msrle32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\mciavi32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\iyuv_32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\avifil32.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\vbscript.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\jscript.dll
2010-07-22 22:58:19 ----A---- C:\windows\system32\t2embed.dll
2010-07-22 22:58:16 ----A---- C:\windows\system32\asycfilt.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc_isv.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate.exe
2010-07-22 22:57:17 ----A---- C:\windows\system32\fontsub.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmlib.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmfd.dll
2010-07-22 22:47:42 ----D---- C:\Users\Admin\AppData\Roaming\HPQLOG
2010-07-22 22:47:30 ----D---- C:\Users\Admin\AppData\Roaming\Infineon
2010-07-22 22:47:28 ----D---- C:\Users\Admin\AppData\Roaming\translateclient
2010-07-22 22:46:57 ----D---- C:\Users\Admin\AppData\Roaming\DigitalPersona
2010-07-22 22:46:56 ----D---- C:\Users\Admin\AppData\Roaming\Identities
2010-07-22 22:46:43 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2010-07-21 23:59:45 ----A---- C:\windows\system32\msonpmon.dll
2010-07-21 23:58:32 ----D---- C:\Program Files\Microsoft Works
2010-07-21 23:58:20 ----D---- C:\Program Files\Microsoft Visual Studio
2010-07-21 23:58:20 ----D---- C:\Program Files\Common Files\DESIGNER
2010-07-21 23:58:03 ----D---- C:\windows\PCHEALTH
2010-07-21 23:58:03 ----D---- C:\Program Files\Microsoft.NET
2010-07-21 23:55:50 ----D---- C:\ProgramData\Microsoft Help
2010-07-21 23:55:50 ----D---- C:\Program Files\Microsoft Office
2010-07-21 23:55:36 ----RD---- C:\MSOCache
2010-07-21 22:51:47 ----A---- C:\windows\system32\XAudio2_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\xactengine3_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx11_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx10_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dcsx_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\D3DCompiler_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAudio2_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAPOFX1_3.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\xactengine3_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\X3DAudio1_6.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\d3dx10_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DCompiler_41.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAudio2_2.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAPOFX1_1.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DX9_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\d3dx10_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DCompiler_40.dll
2010-07-21 22:51:44 ----A---- C:\windows\system32\xactengine3_2.dll
2010-07-21 15:38:29 ----A---- C:\windows\system32\unrar.dll
2010-07-21 15:38:28 ----A---- C:\windows\avisplitter.ini
2010-07-21 15:38:26 ----A---- C:\windows\system32\yv12vfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidvfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidcore.dll
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll.manifest
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll
2010-07-21 15:38:17 ----D---- C:\Program Files\K-Lite Codec Pack
2010-07-21 15:36:12 ----D---- C:\TOTO
2010-07-21 15:36:11 ----D---- C:\slovnik
2010-07-21 15:34:42 ----D---- C:\Fraps
2010-07-21 15:33:34 ----A---- C:\windows\system32\pncrt.dll
2010-07-21 15:33:14 ----D---- C:\Program Files\FreeTime
2010-07-21 15:06:18 ----D---- C:\Program Files\CCleaner
2010-07-20 16:12:55 ----D---- C:\Program Files\HooTech
2010-07-20 15:41:31 ----D---- C:\ProgramData\ESET
2010-07-20 15:41:31 ----D---- C:\Program Files\ESET
2010-07-20 15:34:38 ----D---- C:\ProgramData\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Common Files\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Adobe
2010-07-20 15:23:02 ----D---- C:\Program Files\Translate Client
2010-07-20 15:05:38 ----D---- C:\ProgramData\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Common Files\SureThing Shared
2010-07-20 15:04:18 ----D---- C:\ProgramData\Sonic
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\Sonic Shared
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-20 15:03:53 ----D---- C:\Program Files\Common Files\Roxio Shared
2010-07-20 14:59:45 ----D---- C:\Program Files\Common Files\DigitalPersona
2010-07-20 14:59:15 ----D---- C:\Program Files\Common Files\ActivIdentity
2010-07-20 14:59:15 ----D---- C:\Program Files\ActivIdentity
2010-07-20 14:58:19 ----D---- C:\ProgramData\Infineon
2010-07-20 14:56:05 ----A---- C:\windows\system32\pdfc_port.dll
2010-07-20 14:56:04 ----D---- C:\Program Files\PDF Complete
2010-07-20 14:56:01 ----D---- C:\ProgramData\PDFC
2010-07-20 14:54:45 ----D---- C:\ProgramData\HPQLOG
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hant
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hans
2010-07-20 14:54:34 ----D---- C:\windows\system32\pt
2010-07-20 14:54:34 ----D---- C:\windows\system32\ko
2010-07-20 14:54:34 ----D---- C:\windows\system32\ja
2010-07-20 14:54:34 ----D---- C:\windows\system32\it
2010-07-20 14:54:34 ----D---- C:\windows\system32\fr
2010-07-20 14:54:34 ----D---- C:\windows\system32\es
2010-07-20 14:54:34 ----D---- C:\windows\system32\de
2010-07-20 14:54:34 ----D---- C:\windows\DPDrv
2010-07-20 14:54:32 ----D---- C:\ProgramData\Macrovision
2010-07-20 14:49:47 ----A---- C:\windows\system32\VBAR332.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSRD2X35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJTER35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJINT35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJET35.DLL
2010-07-20 14:38:17 ----A---- C:\windows\system32\drivers\cpuz134_x32.sys
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAudio2_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAPOFX1_2.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\xactengine3_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\X3DAudio1_5.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAPOFX1_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_4.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_3.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DX9_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_37.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xinput1_3.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_9.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_8.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_10.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\X3DAudio1_2.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DX9_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_34.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_7.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_6.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_5.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_32.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\D3DCompiler_33.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_4.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_3.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\x3daudio1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\d3dx9_31.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\xactengine2_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\x3daudio1_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_30.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_29.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_28.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_27.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_26.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_25.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_24.dll
2010-07-19 23:23:48 ----D---- C:\HRY
2010-07-19 23:22:28 ----D---- C:\windows\system32\URTTEMP
2010-07-19 22:59:26 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-07-19 22:45:25 ----A---- C:\windows\system32\drivers\cpuz133_x32.sys
2010-07-19 22:45:24 ----D---- C:\Program Files\CPUID
2010-07-19 22:38:44 ----D---- C:\Program Files\WinRAR
2010-07-19 22:34:04 ----D---- C:\Program Files\Mozilla Firefox
2010-07-19 22:31:02 ----N---- C:\windows\system32\MpSigStub.exe
2010-07-19 22:30:20 ----A---- C:\windows\system32\wintrust.dll
2010-07-19 22:30:19 ----A---- C:\windows\system32\cabview.dll
2010-07-19 22:16:10 ----D---- C:\Program Files\Windows Live
2010-07-19 22:16:00 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-19 22:15:46 ----D---- C:\Program Files\Microsoft Sync Framework
2010-07-19 22:15:39 ----D---- C:\Program Files\Microsoft
2010-07-19 22:15:04 ----D---- C:\Program Files\Common Files\Windows Live
======List of files/folders modified in the last 1 months======
2010-08-17 15:16:36 ----D---- C:\windows\Temp
2010-08-17 15:14:15 ----D---- C:\windows\System32
2010-08-17 15:14:03 ----D---- C:\windows\system32\config
2010-08-17 15:13:57 ----A---- C:\windows\system32\log.txt
2010-08-17 15:13:48 ----D---- C:\Windows
2010-08-17 15:12:43 ----D---- C:\windows\system32\drivers
2010-08-17 15:12:39 ----SHD---- C:\System Volume Information
2010-08-17 15:12:19 ----RD---- C:\Program Files
2010-08-16 23:11:50 ----D---- C:\windows\Microsoft.NET
2010-08-16 22:00:01 ----RSD---- C:\windows\assembly
2010-08-16 21:16:09 ----A---- C:\windows\system.ini
2010-08-16 21:16:00 ----D---- C:\windows\system32\drivers\etc
2010-08-16 21:10:25 ----D---- C:\windows\AppPatch
2010-08-16 21:10:23 ----D---- C:\Program Files\Common Files
2010-08-16 20:17:12 ----SHD---- C:\windows\Installer
2010-08-16 20:17:09 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-08-16 20:17:08 ----D---- C:\windows\inf
2010-08-16 20:16:06 ----D---- C:\windows\Prefetch
2010-08-16 20:15:00 ----D---- C:\windows\system32\en-US
2010-08-16 20:14:17 ----D---- C:\windows\winsxs
2010-08-16 20:14:06 ----D---- C:\windows\system32\catroot
2010-08-16 19:06:26 ----D---- C:\ProgramData
2010-08-16 19:04:15 ----D---- C:\windows\debug
2010-08-15 05:31:55 ----D---- C:\windows\system32\migration
2010-08-15 05:31:55 ----D---- C:\Program Files\Internet Explorer
2010-08-15 05:24:55 ----D---- C:\windows\system32\catroot2
2010-08-15 05:17:46 ----D---- C:\windows\system32\wbem
2010-08-15 05:17:05 ----D---- C:\windows\Tasks
2010-08-15 05:17:05 ----D---- C:\windows\system32\wfp
2010-08-15 05:17:05 ----D---- C:\windows\system32\DriverStore
2010-08-15 05:17:01 ----D---- C:\windows\Help
2010-08-15 05:17:00 ----D---- C:\windows\AppCompat
2010-08-15 05:16:59 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-15 05:16:55 ----D---- C:\windows\registration
2010-08-15 05:06:54 ----D---- C:\windows\LiveKernelReports
2010-08-15 05:06:47 ----D---- C:\ProgramData\NVIDIA
2010-08-12 14:41:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-08 14:30:10 ----D---- C:\SYSTEM.SAV
2010-08-02 09:33:10 ----SD---- C:\ProgramData\Microsoft
2010-08-02 02:57:58 ----D---- C:\windows\rescache
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Sidebar
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Mail
2010-08-02 02:53:43 ----D---- C:\windows\servicing
2010-08-02 02:53:43 ----D---- C:\windows\ehome
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Photo Viewer
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Media Player
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Journal
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Defender
2010-08-02 02:53:43 ----D---- C:\Program Files\Common Files\System
2010-08-02 02:53:42 ----D---- C:\windows\system32\sysprep
2010-08-02 02:53:42 ----D---- C:\windows\system32\sl-SI
2010-08-02 02:53:42 ----D---- C:\windows\system32\oobe
2010-08-02 02:53:42 ----D---- C:\windows\system32\migwiz
2010-08-02 02:53:42 ----D---- C:\windows\PolicyDefinitions
2010-08-02 02:53:36 ----D---- C:\windows\system32\WCN
2010-08-02 02:53:30 ----D---- C:\windows\system32\hr-HR
2010-08-02 02:53:16 ----D---- C:\windows\IME
2010-08-02 02:53:14 ----D---- C:\windows\system32\winrm
2010-08-02 02:53:14 ----D---- C:\windows\system32\slmgr
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs-CZ
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs
2010-08-02 02:53:14 ----D---- C:\windows\system32\Boot
2010-08-02 02:53:05 ----D---- C:\windows\system32\drivers\cs-CZ
2010-08-02 02:53:04 ----D---- C:\windows\system32\MUI
2010-08-02 02:53:04 ----D---- C:\windows\system32\drivers\UMDF
2010-08-02 02:53:04 ----D---- C:\windows\system32\Dism
2010-08-02 02:53:02 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-08-02 02:53:01 ----D---- C:\windows\system32\com
2010-08-02 02:52:49 ----D---- C:\Program Files\DVD Maker
2010-08-02 02:52:48 ----D---- C:\windows\en-US
2010-08-02 02:52:47 ----D---- C:\windows\system32\drivers\en-US
2010-08-02 02:52:43 ----D---- C:\windows\Speech
2010-08-02 02:36:22 ----D---- C:\swsetup
2010-07-31 08:15:27 ----D---- C:\windows\Logs
2010-07-27 17:26:36 ----D---- C:\windows\system32\Tasks
2010-07-26 15:11:21 ----D---- C:\ProgramData\Hewlett-Packard
2010-07-26 15:00:56 ----D---- C:\Program Files\Hewlett-Packard
2010-07-25 13:14:43 ----D---- C:\windows\ModemLogs
2010-07-22 23:11:40 ----D---- C:\windows\system32\wdi
2010-07-22 23:11:12 ----D---- C:\windows\system32\sk-SK
2010-07-22 22:46:42 ----RD---- C:\Users
2010-07-21 23:58:29 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-21 23:58:18 ----D---- C:\windows\ShellNew
2010-07-21 23:58:08 ----RSD---- C:\windows\Fonts
2010-07-21 23:56:08 ----A---- C:\windows\win.ini
2010-07-20 15:07:16 ----D---- C:\ProgramData\Uninstall
2010-07-20 14:51:02 ----D---- C:\Program Files\Common Files\SNP2UVC
2010-07-19 22:30:46 ----D---- C:\windows\SoftwareDistribution
2010-07-19 22:17:11 ----RD---- C:\Program Files\Online Services
2010-07-19 22:12:31 ----D---- C:\windows\system32\restore
2010-07-19 21:00:09 ----D---- C:\windows\Panther
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\windows\System32\Drivers\PxHelp20.sys [2009-07-09 45200]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\windows\System32\Drivers\SafeBoot.sys [2009-11-11 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-11-11 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-11-11 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-08-17 691696]
R0 storvsc;storvsc; C:\windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 easdrv;easdrv; C:\windows\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdir;epfwtdir; C:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [2009-10-02 39712]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-11-11 40088]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-01-30 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2009-12-01 295128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 cpuz133;cpuz133; \??\C:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
R2 cpuz134;cpuz134; \??\C:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
R2 eamon;EAMON; C:\windows\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 rimmptsk;rimmptsk; C:\windows\system32\DRIVERS\rimmptsk.sys [2009-06-26 48128]
R2 rimsptsk;rimsptsk; C:\windows\system32\DRIVERS\rimsptsk.sys [2009-06-26 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\windows\system32\DRIVERS\rixdptsk.sys [2009-06-26 38400]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-08-03 1161760]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\windows\system32\DRIVERS\e1k6232.sys [2009-11-06 214696]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 Impcd;Impcd; C:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-21 58880]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-21 137728]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2009-11-12 66664]
R3 rismc32;RICOH Smart Card Reader; C:\windows\system32\DRIVERS\rismc32.sys [2009-07-21 49152]
R3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-09-18 1765168]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-11-18 420864]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-07-26 242992]
R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
R3 vpcbus;Virtual PC Host Bus Service; C:\windows\system32\DRIVERS\vpchbus.sys [2010-01-30 165376]
R3 vpcusb;USB Virtualization Connector Service; C:\windows\system32\DRIVERS\vpcusb.sys [2010-01-30 78336]
S2 rimspci;rimspci; C:\windows\system32\DRIVERS\rimspe86.sys [2009-10-27 48640]
S2 risdpcie;risdpcie; C:\windows\system32\DRIVERS\risdpe86.sys [2009-10-29 47616]
S2 rixdpcie;rixdpcie; C:\windows\system32\DRIVERS\rixdpe86.sys [2009-09-29 38912]
S3 ALSysIO;ALSysIO; \??\C:\Users\LUK~1\AppData\Local\Temp\ALSysIO.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2009-09-17 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-07-11 101376]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RTCore32;RTCore32; \??\C:\Program Files\RM Clock\RTCore32.sys []
S3 s3cap;s3cap; C:\windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe [2009-03-03 81920]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-08-03 14336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-24 300808]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-03-24 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2009-11-20 102968]
R2 HP ProtectTools Service;HP ProtectTools Service; C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-11-20 102968]
R2 Hp.Skyroom.Windows.Service;HP SkyRoom; C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [2009-11-21 124984]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-11-12 250936]
R2 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-11-11 277096]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-11-04 297984]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
R2 IFXTCS;Trusted Platform Core Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [2009-10-02 988448]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2010-06-03 129640]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PersonalSecureDriveService;Personal Secure Drive Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [2009-10-02 214304]
R2 rgsender;Remote Graphics Sender Service; c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [2009-11-19 379904]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe [2009-11-18 229458]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-05-01 229944]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-10-22 1639728]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2007-12-21 19200]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\windows\system32\flcdlock.exe [2009-11-09 362040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1343400]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2010-08-17 15:16:31
Microsoft Windows 7 Professional
System drive C: has 119 GB (54%) free of 221 GB
Total RAM: 1973 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:16:44, on 17. 8. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HooTech\NetMeter\HooNetMeter.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender_gui.exe
C:\windows\Explorer.EXE
C:\windows\system32\SearchFilterHost.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Users\Lukáš\Desktop\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [IFXSPMGT] "C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Lukáš')
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [NetMeter] C:\Program Files\HooTech\NetMeter\HooNetMeter.exe (User 'Lukáš')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP SkyRoom (Hp.Skyroom.Windows.Service) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: Remote Graphics Sender Service (rgsender) - Hewlett-Packard, Inc. - c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 13241 bytes
======Scheduled tasks folder======
C:\windows\tasks\Embedded Security Backup Schedule.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-11-04 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-11-24 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-12 287800]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"NUSB3MON"=c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-21 106496]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2009-11-20 1690680]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-07-26 1713448]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [2009-11-20 363064]
"IMSS"=C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2009-11-04 111640]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-11-18 495708]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"IFXSPMGT"=C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
"acevents"=C:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-03 153640]
"accrdsub"=C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-03 400936]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-11-04 11264000]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2007-12-21 1443072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-09 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
wlnotify.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ip6fw.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLmSsp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpcdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpwd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdpipe.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdtcp.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\termservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-08-17 15:12:43 ----A---- C:\windows\system32\drivers\sptd.sys
2010-08-17 15:12:19 ----D---- C:\Program Files\DAEMON Tools Lite
2010-08-16 23:23:55 ----D---- C:\rsit
2010-08-16 21:19:23 ----SHD---- C:\$RECYCLE.BIN
2010-08-16 20:56:55 ----A---- C:\windows\MBR.exe
2010-08-16 20:56:54 ----A---- C:\windows\PEV.exe
2010-08-16 20:56:45 ----D---- C:\windows\ERDNT
2010-08-16 20:14:13 ----D---- C:\windows\system32\Wat
2010-08-16 19:06:27 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2010-08-16 19:06:26 ----D---- C:\ProgramData\Malwarebytes
2010-08-16 19:06:26 ----A---- C:\windows\system32\drivers\mbam.sys
2010-08-16 19:06:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-08-15 06:28:17 ----D---- C:\Program Files\trend micro
2010-08-15 05:25:04 ----A---- C:\windows\system32\mshtml.dll
2010-08-15 05:25:04 ----A---- C:\windows\system32\ieframe.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\wininet.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\urlmon.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\mstime.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedssync.exe
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedsbs.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\jsproxy.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\ieui.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iepeers.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iedkcs32.dll
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntoskrnl.exe
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-08-15 05:24:45 ----A---- C:\windows\system32\drivers\tcpip.sys
2010-08-15 05:24:44 ----A---- C:\windows\system32\win32k.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\rtutils.dll
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv2.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv.sys
2010-08-15 05:24:42 ----A---- C:\windows\system32\schannel.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\ir32_32.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\iccvid.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\drivers\srvnet.sys
2010-08-15 05:24:41 ----A---- C:\windows\system32\msxml3.dll
2010-08-15 04:57:06 ----D---- C:\NVIDIA
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DX9_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\d3dx10_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DCompiler_39.dll
2010-08-06 20:21:31 ----D---- C:\windows\system32\AGEIA
2010-08-06 20:21:30 ----D---- C:\Program Files\AGEIA Technologies
2010-08-03 20:43:07 ----A---- C:\windows\system32\shell32.dll
2010-08-02 09:45:04 ----D---- C:\ProgramData\LightScribe
2010-08-02 09:21:07 ----D---- C:\Program Files\Nero
2010-08-02 09:20:45 ----D---- C:\ProgramData\Nero
2010-08-02 09:20:43 ----D---- C:\Program Files\Common Files\Nero
2010-08-02 09:20:26 ----D---- C:\Program Files\Common Files\LightScribe
2010-08-02 02:24:43 ----D---- C:\windows\system32\appmgmt
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAudio2_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAPOFX1_4.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\xactengine3_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\X3DAudio1_7.dll
2010-07-26 15:11:50 ----A---- C:\windows\system32\SynTPCo4.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\SynTPAPI.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\drivers\SynTP.sys
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCtrl.dll
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCOM.dll
2010-07-26 15:00:11 ----D---- C:\ProgramData\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewusbmdm.sys
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewdcsc.sys
2010-07-25 13:11:20 ----D---- C:\Program Files\Huawei technologies
2010-07-25 01:03:50 ----D---- C:\ProgramData\NVIDIA Corporation
2010-07-22 23:08:31 ----A---- C:\windows\system32\msv1_0.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHostProxy.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHost.exe
2010-07-22 23:07:22 ----A---- C:\windows\system32\netfxperf.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\mscoree.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\dfshim.dll
2010-07-22 23:03:55 ----A---- C:\windows\system32\MRT.exe
2010-07-22 23:00:44 ----A---- C:\windows\system32\browserchoice.exe
2010-07-22 23:00:11 ----D---- C:\Program Files\MSXML 4.0
2010-07-22 22:59:11 ----A---- C:\windows\system32\lsasrv.dll
2010-07-22 22:59:11 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2010-07-22 22:59:10 ----A---- C:\windows\system32\inetcomm.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\ntdll.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\msasn1.dll
2010-07-22 22:59:04 ----A---- C:\windows\explorer.exe
2010-07-22 22:59:03 ----A---- C:\windows\system32\winlogon.exe
2010-07-22 22:59:02 ----A---- C:\windows\system32\tzres.dll
2010-07-22 22:58:58 ----A---- C:\windows\system32\drivers\fvevol.sys
2010-07-22 22:58:56 ----A---- C:\windows\system32\wmp.dll
2010-07-22 22:58:55 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2010-07-22 22:58:55 ----A---- C:\windows\system32\CertEnroll.dll
2010-07-22 22:58:54 ----A---- C:\windows\system32\winresume.exe
2010-07-22 22:58:54 ----A---- C:\windows\system32\winload.exe
2010-07-22 22:58:53 ----A---- C:\windows\system32\wmploc.DLL
2010-07-22 22:58:50 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2010-07-22 22:58:36 ----A---- C:\windows\system32\msdri.dll
2010-07-22 22:58:36 ----A---- C:\windows\system32\CPFilters.dll
2010-07-22 22:58:35 ----A---- C:\windows\system32\psisdecd.dll
2010-07-22 22:58:31 ----A---- C:\windows\system32\kernel32.dll
2010-07-22 22:58:30 ----A---- C:\windows\system32\apphelp.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\tsbyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\quartz.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msvidc32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msrle32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\mciavi32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\iyuv_32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\avifil32.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\vbscript.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\jscript.dll
2010-07-22 22:58:19 ----A---- C:\windows\system32\t2embed.dll
2010-07-22 22:58:16 ----A---- C:\windows\system32\asycfilt.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc_isv.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate.exe
2010-07-22 22:57:17 ----A---- C:\windows\system32\fontsub.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmlib.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmfd.dll
2010-07-22 22:47:42 ----D---- C:\Users\Admin\AppData\Roaming\HPQLOG
2010-07-22 22:47:30 ----D---- C:\Users\Admin\AppData\Roaming\Infineon
2010-07-22 22:47:28 ----D---- C:\Users\Admin\AppData\Roaming\translateclient
2010-07-22 22:46:57 ----D---- C:\Users\Admin\AppData\Roaming\DigitalPersona
2010-07-22 22:46:56 ----D---- C:\Users\Admin\AppData\Roaming\Identities
2010-07-22 22:46:43 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2010-07-21 23:59:45 ----A---- C:\windows\system32\msonpmon.dll
2010-07-21 23:58:32 ----D---- C:\Program Files\Microsoft Works
2010-07-21 23:58:20 ----D---- C:\Program Files\Microsoft Visual Studio
2010-07-21 23:58:20 ----D---- C:\Program Files\Common Files\DESIGNER
2010-07-21 23:58:03 ----D---- C:\windows\PCHEALTH
2010-07-21 23:58:03 ----D---- C:\Program Files\Microsoft.NET
2010-07-21 23:55:50 ----D---- C:\ProgramData\Microsoft Help
2010-07-21 23:55:50 ----D---- C:\Program Files\Microsoft Office
2010-07-21 23:55:36 ----RD---- C:\MSOCache
2010-07-21 22:51:47 ----A---- C:\windows\system32\XAudio2_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\xactengine3_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx11_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx10_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dcsx_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\D3DCompiler_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAudio2_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAPOFX1_3.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\xactengine3_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\X3DAudio1_6.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\d3dx10_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DCompiler_41.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAudio2_2.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAPOFX1_1.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DX9_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\d3dx10_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DCompiler_40.dll
2010-07-21 22:51:44 ----A---- C:\windows\system32\xactengine3_2.dll
2010-07-21 15:38:29 ----A---- C:\windows\system32\unrar.dll
2010-07-21 15:38:28 ----A---- C:\windows\avisplitter.ini
2010-07-21 15:38:26 ----A---- C:\windows\system32\yv12vfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidvfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidcore.dll
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll.manifest
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll
2010-07-21 15:38:17 ----D---- C:\Program Files\K-Lite Codec Pack
2010-07-21 15:36:12 ----D---- C:\TOTO
2010-07-21 15:36:11 ----D---- C:\slovnik
2010-07-21 15:34:42 ----D---- C:\Fraps
2010-07-21 15:33:34 ----A---- C:\windows\system32\pncrt.dll
2010-07-21 15:33:14 ----D---- C:\Program Files\FreeTime
2010-07-21 15:06:18 ----D---- C:\Program Files\CCleaner
2010-07-20 16:12:55 ----D---- C:\Program Files\HooTech
2010-07-20 15:41:31 ----D---- C:\ProgramData\ESET
2010-07-20 15:41:31 ----D---- C:\Program Files\ESET
2010-07-20 15:34:38 ----D---- C:\ProgramData\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Common Files\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Adobe
2010-07-20 15:23:02 ----D---- C:\Program Files\Translate Client
2010-07-20 15:05:38 ----D---- C:\ProgramData\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Common Files\SureThing Shared
2010-07-20 15:04:18 ----D---- C:\ProgramData\Sonic
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\Sonic Shared
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-20 15:03:53 ----D---- C:\Program Files\Common Files\Roxio Shared
2010-07-20 14:59:45 ----D---- C:\Program Files\Common Files\DigitalPersona
2010-07-20 14:59:15 ----D---- C:\Program Files\Common Files\ActivIdentity
2010-07-20 14:59:15 ----D---- C:\Program Files\ActivIdentity
2010-07-20 14:58:19 ----D---- C:\ProgramData\Infineon
2010-07-20 14:56:05 ----A---- C:\windows\system32\pdfc_port.dll
2010-07-20 14:56:04 ----D---- C:\Program Files\PDF Complete
2010-07-20 14:56:01 ----D---- C:\ProgramData\PDFC
2010-07-20 14:54:45 ----D---- C:\ProgramData\HPQLOG
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hant
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hans
2010-07-20 14:54:34 ----D---- C:\windows\system32\pt
2010-07-20 14:54:34 ----D---- C:\windows\system32\ko
2010-07-20 14:54:34 ----D---- C:\windows\system32\ja
2010-07-20 14:54:34 ----D---- C:\windows\system32\it
2010-07-20 14:54:34 ----D---- C:\windows\system32\fr
2010-07-20 14:54:34 ----D---- C:\windows\system32\es
2010-07-20 14:54:34 ----D---- C:\windows\system32\de
2010-07-20 14:54:34 ----D---- C:\windows\DPDrv
2010-07-20 14:54:32 ----D---- C:\ProgramData\Macrovision
2010-07-20 14:49:47 ----A---- C:\windows\system32\VBAR332.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSRD2X35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJTER35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJINT35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJET35.DLL
2010-07-20 14:38:17 ----A---- C:\windows\system32\drivers\cpuz134_x32.sys
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAudio2_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAPOFX1_2.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\xactengine3_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\X3DAudio1_5.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAPOFX1_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_4.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_3.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DX9_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_37.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xinput1_3.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_9.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_8.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_10.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\X3DAudio1_2.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DX9_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_34.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_7.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_6.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_5.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_32.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\D3DCompiler_33.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_4.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_3.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\x3daudio1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\d3dx9_31.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\xactengine2_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\x3daudio1_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_30.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_29.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_28.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_27.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_26.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_25.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_24.dll
2010-07-19 23:23:48 ----D---- C:\HRY
2010-07-19 23:22:28 ----D---- C:\windows\system32\URTTEMP
2010-07-19 22:59:26 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-07-19 22:45:25 ----A---- C:\windows\system32\drivers\cpuz133_x32.sys
2010-07-19 22:45:24 ----D---- C:\Program Files\CPUID
2010-07-19 22:38:44 ----D---- C:\Program Files\WinRAR
2010-07-19 22:34:04 ----D---- C:\Program Files\Mozilla Firefox
2010-07-19 22:31:02 ----N---- C:\windows\system32\MpSigStub.exe
2010-07-19 22:30:20 ----A---- C:\windows\system32\wintrust.dll
2010-07-19 22:30:19 ----A---- C:\windows\system32\cabview.dll
2010-07-19 22:16:10 ----D---- C:\Program Files\Windows Live
2010-07-19 22:16:00 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-19 22:15:46 ----D---- C:\Program Files\Microsoft Sync Framework
2010-07-19 22:15:39 ----D---- C:\Program Files\Microsoft
2010-07-19 22:15:04 ----D---- C:\Program Files\Common Files\Windows Live
======List of files/folders modified in the last 1 months======
2010-08-17 15:16:36 ----D---- C:\windows\Temp
2010-08-17 15:14:15 ----D---- C:\windows\System32
2010-08-17 15:14:03 ----D---- C:\windows\system32\config
2010-08-17 15:13:57 ----A---- C:\windows\system32\log.txt
2010-08-17 15:13:48 ----D---- C:\Windows
2010-08-17 15:12:43 ----D---- C:\windows\system32\drivers
2010-08-17 15:12:39 ----SHD---- C:\System Volume Information
2010-08-17 15:12:19 ----RD---- C:\Program Files
2010-08-16 23:11:50 ----D---- C:\windows\Microsoft.NET
2010-08-16 22:00:01 ----RSD---- C:\windows\assembly
2010-08-16 21:16:09 ----A---- C:\windows\system.ini
2010-08-16 21:16:00 ----D---- C:\windows\system32\drivers\etc
2010-08-16 21:10:25 ----D---- C:\windows\AppPatch
2010-08-16 21:10:23 ----D---- C:\Program Files\Common Files
2010-08-16 20:17:12 ----SHD---- C:\windows\Installer
2010-08-16 20:17:09 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-08-16 20:17:08 ----D---- C:\windows\inf
2010-08-16 20:16:06 ----D---- C:\windows\Prefetch
2010-08-16 20:15:00 ----D---- C:\windows\system32\en-US
2010-08-16 20:14:17 ----D---- C:\windows\winsxs
2010-08-16 20:14:06 ----D---- C:\windows\system32\catroot
2010-08-16 19:06:26 ----D---- C:\ProgramData
2010-08-16 19:04:15 ----D---- C:\windows\debug
2010-08-15 05:31:55 ----D---- C:\windows\system32\migration
2010-08-15 05:31:55 ----D---- C:\Program Files\Internet Explorer
2010-08-15 05:24:55 ----D---- C:\windows\system32\catroot2
2010-08-15 05:17:46 ----D---- C:\windows\system32\wbem
2010-08-15 05:17:05 ----D---- C:\windows\Tasks
2010-08-15 05:17:05 ----D---- C:\windows\system32\wfp
2010-08-15 05:17:05 ----D---- C:\windows\system32\DriverStore
2010-08-15 05:17:01 ----D---- C:\windows\Help
2010-08-15 05:17:00 ----D---- C:\windows\AppCompat
2010-08-15 05:16:59 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-15 05:16:55 ----D---- C:\windows\registration
2010-08-15 05:06:54 ----D---- C:\windows\LiveKernelReports
2010-08-15 05:06:47 ----D---- C:\ProgramData\NVIDIA
2010-08-12 14:41:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-08 14:30:10 ----D---- C:\SYSTEM.SAV
2010-08-02 09:33:10 ----SD---- C:\ProgramData\Microsoft
2010-08-02 02:57:58 ----D---- C:\windows\rescache
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Sidebar
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Mail
2010-08-02 02:53:43 ----D---- C:\windows\servicing
2010-08-02 02:53:43 ----D---- C:\windows\ehome
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Photo Viewer
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Media Player
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Journal
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Defender
2010-08-02 02:53:43 ----D---- C:\Program Files\Common Files\System
2010-08-02 02:53:42 ----D---- C:\windows\system32\sysprep
2010-08-02 02:53:42 ----D---- C:\windows\system32\sl-SI
2010-08-02 02:53:42 ----D---- C:\windows\system32\oobe
2010-08-02 02:53:42 ----D---- C:\windows\system32\migwiz
2010-08-02 02:53:42 ----D---- C:\windows\PolicyDefinitions
2010-08-02 02:53:36 ----D---- C:\windows\system32\WCN
2010-08-02 02:53:30 ----D---- C:\windows\system32\hr-HR
2010-08-02 02:53:16 ----D---- C:\windows\IME
2010-08-02 02:53:14 ----D---- C:\windows\system32\winrm
2010-08-02 02:53:14 ----D---- C:\windows\system32\slmgr
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs-CZ
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs
2010-08-02 02:53:14 ----D---- C:\windows\system32\Boot
2010-08-02 02:53:05 ----D---- C:\windows\system32\drivers\cs-CZ
2010-08-02 02:53:04 ----D---- C:\windows\system32\MUI
2010-08-02 02:53:04 ----D---- C:\windows\system32\drivers\UMDF
2010-08-02 02:53:04 ----D---- C:\windows\system32\Dism
2010-08-02 02:53:02 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-08-02 02:53:01 ----D---- C:\windows\system32\com
2010-08-02 02:52:49 ----D---- C:\Program Files\DVD Maker
2010-08-02 02:52:48 ----D---- C:\windows\en-US
2010-08-02 02:52:47 ----D---- C:\windows\system32\drivers\en-US
2010-08-02 02:52:43 ----D---- C:\windows\Speech
2010-08-02 02:36:22 ----D---- C:\swsetup
2010-07-31 08:15:27 ----D---- C:\windows\Logs
2010-07-27 17:26:36 ----D---- C:\windows\system32\Tasks
2010-07-26 15:11:21 ----D---- C:\ProgramData\Hewlett-Packard
2010-07-26 15:00:56 ----D---- C:\Program Files\Hewlett-Packard
2010-07-25 13:14:43 ----D---- C:\windows\ModemLogs
2010-07-22 23:11:40 ----D---- C:\windows\system32\wdi
2010-07-22 23:11:12 ----D---- C:\windows\system32\sk-SK
2010-07-22 22:46:42 ----RD---- C:\Users
2010-07-21 23:58:29 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-21 23:58:18 ----D---- C:\windows\ShellNew
2010-07-21 23:58:08 ----RSD---- C:\windows\Fonts
2010-07-21 23:56:08 ----A---- C:\windows\win.ini
2010-07-20 15:07:16 ----D---- C:\ProgramData\Uninstall
2010-07-20 14:51:02 ----D---- C:\Program Files\Common Files\SNP2UVC
2010-07-19 22:30:46 ----D---- C:\windows\SoftwareDistribution
2010-07-19 22:17:11 ----RD---- C:\Program Files\Online Services
2010-07-19 22:12:31 ----D---- C:\windows\system32\restore
2010-07-19 21:00:09 ----D---- C:\windows\Panther
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\windows\System32\Drivers\PxHelp20.sys [2009-07-09 45200]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\windows\System32\Drivers\SafeBoot.sys [2009-11-11 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-11-11 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-11-11 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-08-17 691696]
R0 storvsc;storvsc; C:\windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 easdrv;easdrv; C:\windows\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdir;epfwtdir; C:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [2009-10-02 39712]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-11-11 40088]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-01-30 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2009-12-01 295128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 cpuz133;cpuz133; \??\C:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
R2 cpuz134;cpuz134; \??\C:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
R2 eamon;EAMON; C:\windows\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 rimmptsk;rimmptsk; C:\windows\system32\DRIVERS\rimmptsk.sys [2009-06-26 48128]
R2 rimsptsk;rimsptsk; C:\windows\system32\DRIVERS\rimsptsk.sys [2009-06-26 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\windows\system32\DRIVERS\rixdptsk.sys [2009-06-26 38400]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-08-03 1161760]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\windows\system32\DRIVERS\e1k6232.sys [2009-11-06 214696]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 Impcd;Impcd; C:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-21 58880]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-21 137728]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2009-11-12 66664]
R3 rismc32;RICOH Smart Card Reader; C:\windows\system32\DRIVERS\rismc32.sys [2009-07-21 49152]
R3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-09-18 1765168]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-11-18 420864]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-07-26 242992]
R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
R3 vpcbus;Virtual PC Host Bus Service; C:\windows\system32\DRIVERS\vpchbus.sys [2010-01-30 165376]
R3 vpcusb;USB Virtualization Connector Service; C:\windows\system32\DRIVERS\vpcusb.sys [2010-01-30 78336]
S2 rimspci;rimspci; C:\windows\system32\DRIVERS\rimspe86.sys [2009-10-27 48640]
S2 risdpcie;risdpcie; C:\windows\system32\DRIVERS\risdpe86.sys [2009-10-29 47616]
S2 rixdpcie;rixdpcie; C:\windows\system32\DRIVERS\rixdpe86.sys [2009-09-29 38912]
S3 ALSysIO;ALSysIO; \??\C:\Users\LUK~1\AppData\Local\Temp\ALSysIO.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2009-09-17 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-07-11 101376]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RTCore32;RTCore32; \??\C:\Program Files\RM Clock\RTCore32.sys []
S3 s3cap;s3cap; C:\windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe [2009-03-03 81920]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-08-03 14336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-24 300808]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-03-24 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2009-11-20 102968]
R2 HP ProtectTools Service;HP ProtectTools Service; C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-11-20 102968]
R2 Hp.Skyroom.Windows.Service;HP SkyRoom; C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [2009-11-21 124984]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-11-12 250936]
R2 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-11-11 277096]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-11-04 297984]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
R2 IFXTCS;Trusted Platform Core Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [2009-10-02 988448]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2010-06-03 129640]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PersonalSecureDriveService;Personal Secure Drive Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [2009-10-02 214304]
R2 rgsender;Remote Graphics Sender Service; c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [2009-11-19 379904]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe [2009-11-18 229458]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-05-01 229944]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-10-22 1639728]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2007-12-21 19200]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\windows\system32\flcdlock.exe [2009-11-09 362040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1343400]
-----------------EOF-----------------
Re: Trojan-spy.win32.year2010-wors
Můžete dát prosím screen, jakou hlášku vypisuje?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors
Aha, já myslela, že vám vypisuje pc ještě něco s tím Frameworkem.
Jak to teď vypadá, vše je v pořádku?
Jak to teď vypadá, vše je v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors
teraz to už pri každom reštarte vyzerá bez problémov,žiadna chyba ani blbosť sa nezobrazuje 

Re: Trojan-spy.win32.year2010-wors
Ještě otestujte na www.virustotal.com
c:\windows\System32\drivers\psd.sys
c:\windows\System32\drivers\psd.sys
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors

-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
Kód: Vybrat vše
Reglock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
DDS::
uStart Page = hxxp://www.bing.com
mStart Page = hxxp://www.bing.com
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors
ComboFix 10-08-17.04 - Lukáš . 08. 2010 21:59:54.2.4 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1051.18.1973.920 [GMT 2:00]
Running from: c:\users\Lukáš\Desktop\ComboFix.exe
Command switches used :: c:\users\Lukáš\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET NOD32 Antivirus 3.0 *enabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 )))))))))))))))))))))))))))))))
.
2010-08-18 20:07 . 2010-08-18 20:07 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-18 20:07 . 2010-08-18 20:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-18 20:07 . 2010-08-18 20:07 -------- d-----w- c:\users\Admin\AppData\Local\temp
2010-08-17 13:12 . 2010-08-17 13:12 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-08-17 13:12 . 2010-08-17 13:12 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-08-16 21:23 . 2010-08-17 13:16 -------- d-----w- C:\rsit
2010-08-16 18:14 . 2010-08-16 18:14 -------- d-----w- c:\windows\system32\Wat
2010-08-16 17:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-16 17:06 . 2010-08-16 17:06 -------- d-----w- c:\programdata\Malwarebytes
2010-08-16 17:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-16 17:06 . 2010-08-16 17:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-15 04:28 . 2010-08-17 20:19 -------- d-----w- c:\program files\trend micro
2010-08-15 03:25 . 2010-06-30 06:25 978432 ----a-w- c:\windows\system32\wininet.dll
2010-08-15 03:24 . 2010-06-19 06:33 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-15 03:24 . 2010-06-19 06:33 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-15 03:24 . 2010-06-14 06:12 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-15 03:24 . 2010-06-19 04:07 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-08-15 03:24 . 2010-06-22 02:47 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-15 03:24 . 2010-06-22 02:47 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-15 03:24 . 2010-06-19 06:23 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-08-15 03:24 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-08-15 03:24 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-08-15 03:24 . 2010-06-22 02:47 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-15 03:24 . 2010-06-16 05:48 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-15 03:24 . 2010-06-08 06:02 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-08-15 02:57 . 2010-08-15 02:57 -------- d-----w- C:\NVIDIA
2010-08-12 12:53 . 2008-07-12 06:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-08-12 12:53 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-08-12 12:53 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-08-06 18:21 . 2010-08-15 03:17 -------- d-----w- c:\windows\system32\AGEIA
2010-08-06 18:21 . 2010-08-15 03:16 -------- d-----w- c:\program files\AGEIA Technologies
2010-08-02 07:45 . 2010-08-05 18:33 -------- d-----w- c:\programdata\LightScribe
2010-08-02 07:21 . 2010-08-02 07:34 -------- d-----w- c:\program files\Nero
2010-08-02 07:20 . 2010-08-02 07:28 -------- d-----w- c:\programdata\Nero
2010-08-02 07:20 . 2010-08-02 07:43 -------- d-----w- c:\program files\Common Files\Nero
2010-08-02 07:20 . 2010-08-02 07:20 -------- d-----w- c:\program files\Common Files\LightScribe
2010-07-29 16:28 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-07-29 16:28 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-07-29 16:28 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-07-29 16:28 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-07-26 13:11 . 2010-07-26 13:11 120104 ----a-w- c:\windows\system32\SynTPCo4.dll
2010-07-26 13:11 . 2010-07-26 13:11 242992 ----a-w- c:\windows\system32\drivers\SynTP.sys
2010-07-26 13:11 . 2010-07-26 13:11 165160 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-07-26 13:11 . 2010-07-26 13:11 210216 ----a-w- c:\windows\system32\SynCtrl.dll
2010-07-26 13:11 . 2010-07-26 13:11 173352 ----a-w- c:\windows\system32\SynCOM.dll
2010-07-26 13:00 . 2010-07-26 13:00 -------- d-----w- c:\programdata\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-07-26 12:57 . 2010-04-14 17:09 1230088 ----a-w- c:\programdata\Hewlett-Packard\HPSAUpgrade2\HpSAUpgrade.exe
2010-07-25 11:11 . 2007-07-11 09:13 101376 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2010-07-25 11:11 . 2007-07-11 09:11 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2010-07-25 11:11 . 2010-07-25 11:11 -------- d-----w- c:\program files\Huawei technologies
2010-07-24 23:03 . 2010-08-15 02:59 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-07-22 21:16 . 2010-07-22 21:16 -------- d-----w- c:\users\Admin\AppData\Local\Broadcom
2010-07-22 21:08 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-07-22 21:07 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-07-22 21:07 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-07-22 21:07 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-07-22 21:07 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-07-22 21:07 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-07-22 21:00 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-07-22 21:00 . 2010-07-22 21:00 -------- d-----w- c:\program files\MSXML 4.0
2010-07-22 20:59 . 2009-12-11 07:44 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-07-22 20:59 . 2009-12-11 07:38 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2010-07-22 20:59 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-07-22 20:59 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-07-22 20:59 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-07-22 20:59 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-07-22 20:59 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-07-22 20:59 . 2010-04-23 07:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-07-22 20:57 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-07-22 20:57 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-07-22 20:57 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-07-22 20:57 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-07-22 20:57 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-07-22 20:57 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-07-22 20:57 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-07-22 20:57 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-07-22 20:57 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-07-22 20:57 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-07-22 20:57 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-07-22 20:47 . 2010-07-22 20:47 -------- d-----w- c:\users\Admin\AppData\Roaming\HPQLOG
2010-07-22 20:47 . 2010-07-22 20:47 124664 ----a-w- c:\users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-22 20:47 . 2010-07-22 20:47 -------- d-----w- c:\users\Admin\AppData\Roaming\Infineon
2010-07-22 20:47 . 2010-08-17 13:18 -------- d-----w- c:\users\Admin\AppData\Roaming\translateclient
2010-07-22 20:47 . 2010-07-22 20:47 -------- d-----w- c:\users\Admin\AppData\Local\PDFC
2010-07-22 20:47 . 2010-08-17 13:15 -------- d-----r- c:\users\Admin\Virtual Machines
2010-07-21 22:09 . 2008-01-07 12:29 352 ---ha-w- c:\windows\nod32fixtemdono.reg
2010-07-21 21:59 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-07-21 21:59 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2010-07-21 21:58 . 2010-07-21 21:58 -------- d-----w- c:\program files\Microsoft Works
2010-07-21 21:58 . 2010-08-16 18:14 -------- d-----w- c:\program files\Microsoft.NET
2010-07-21 21:58 . 2010-07-21 21:58 -------- d-----w- c:\windows\PCHEALTH
2010-07-21 21:55 . 2010-07-21 22:00 -------- d-----w- c:\programdata\Microsoft Help
2010-07-21 21:55 . 2010-07-21 21:55 -------- d-----r- C:\MSOCache
2010-07-21 13:38 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2010-07-21 13:38 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-07-21 13:38 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-07-21 13:38 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-07-21 13:38 . 2009-10-27 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-07-21 13:38 . 2010-07-21 13:38 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-07-21 13:36 . 2010-07-21 13:36 -------- d-----w- C:\TOTO
2010-07-21 13:36 . 2010-07-21 13:36 -------- d-----w- C:\slovnik
2010-07-21 13:34 . 2010-07-22 14:18 -------- d-----w- C:\Fraps
2010-07-21 13:33 . 2010-07-21 13:33 -------- d-----w- c:\program files\FreeTime
2010-07-21 13:06 . 2010-07-21 13:06 -------- d-----w- c:\program files\CCleaner
2010-07-20 14:12 . 2010-07-20 14:12 -------- d-----w- c:\program files\HooTech
2010-07-20 13:43 . 2008-03-03 12:25 5702 ---ha-w- c:\windows\nod32restoretemdono.reg
2010-07-20 13:41 . 2010-07-21 22:09 -------- d-----w- c:\program files\ESET
2010-07-20 13:34 . 2010-07-20 13:34 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-20 13:23 . 2010-07-20 13:23 -------- d-----w- c:\program files\Translate Client
2010-07-20 13:05 . 2010-07-20 13:06 -------- d-----w- c:\programdata\Roxio
2010-07-20 13:04 . 2010-08-08 12:37 -------- d-----w- c:\program files\Roxio
2010-07-20 13:04 . 2010-07-20 13:04 -------- d-----w- c:\program files\Common Files\SureThing Shared
2010-07-20 13:04 . 2010-07-20 13:04 -------- d-----w- c:\programdata\Sonic
2010-07-20 13:04 . 2010-07-20 13:07 -------- d-----w- c:\program files\Common Files\Sonic Shared
2010-07-20 13:04 . 2010-07-20 13:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-07-20 13:03 . 2010-07-20 13:05 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-07-20 12:59 . 2010-07-20 12:59 -------- d-----w- c:\program files\Common Files\DigitalPersona
2010-07-20 12:54 . 2010-07-20 12:54 -------- d-----w- c:\windows\DPDrv
2010-07-20 12:54 . 2010-07-20 12:54 -------- d-----w- c:\programdata\Macrovision
2010-07-20 12:49 . 2010-07-20 12:49 368912 ----a-w- c:\windows\system32\VBAR332.DLL
2010-07-20 12:49 . 2010-07-20 12:49 252176 ----a-w- c:\windows\system32\MSRD2X35.DLL
2010-07-20 12:49 . 2010-07-20 12:49 24848 ----a-w- c:\windows\system32\MSJTER35.DLL
2010-07-20 12:49 . 2010-07-20 12:49 123664 ----a-w- c:\windows\system32\MSJINT35.DLL
2010-07-20 12:49 . 2010-07-20 12:49 1045776 ----a-w- c:\windows\system32\MSJET35.DLL
2010-07-20 12:38 . 2010-07-09 11:18 20328 ----a-w- c:\windows\system32\drivers\cpuz134_x32.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-18 19:50 . 2010-07-20 12:54 -------- d-----w- c:\programdata\HPQLOG
2010-08-15 03:16 . 2010-03-01 00:42 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-15 03:06 . 2010-03-01 00:42 -------- d-----w- c:\programdata\NVIDIA
2010-08-12 12:41 . 2010-01-30 18:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-11 22:34 . 2010-07-20 12:56 -------- d-----w- c:\programdata\PDFC
2010-08-02 00:53 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-08-02 00:53 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-08-02 00:53 . 2009-07-27 13:49 -------- d-----w- c:\program files\Windows Journal
2010-08-02 00:53 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Photo Viewer
2010-08-02 00:53 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Defender
2010-08-02 00:52 . 2009-07-14 04:52 -------- d-----w- c:\program files\DVD Maker
2010-07-26 13:11 . 2010-01-30 18:14 -------- d-----w- c:\programdata\Hewlett-Packard
2010-07-26 13:00 . 2010-01-30 18:04 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-22 20:46 . 2010-07-22 20:46 -------- d-----w- c:\users\Admin\AppData\Roaming\DigitalPersona
2010-07-20 13:07 . 2010-03-01 00:58 -------- d-----w- c:\programdata\Uninstall
2010-07-20 12:59 . 2010-07-20 12:59 -------- d-----w- c:\program files\Common Files\ActivIdentity
2010-07-20 12:59 . 2010-07-20 12:59 -------- d-----w- c:\program files\ActivIdentity
2010-07-20 12:58 . 2010-07-20 12:58 -------- d-----w- c:\programdata\Infineon
2010-07-20 12:56 . 2010-07-20 12:56 -------- d-----w- c:\program files\PDF Complete
2010-07-20 12:51 . 2010-03-01 00:53 -------- d-----w- c:\program files\Common Files\SNP2UVC
2010-07-19 20:14 . 2010-07-19 20:14 0 --sha-r- c:\windows\system32\drivers\103C_HP_bNB_EliteBook 8540p_Y5336AN_0U_QCND0083SBD_E582943-221_4A_I1521_SHP_V32.28_68CVD F.03_T100121_WU48-0_L41B_M1974_J250_7Intel_8652_92.40_#100130_N808610EA;80864239_(WD918EA#ARL)_XMOBILE_CN10_Z_2_G10DE0A2C.MRK
2010-07-16 11:51 . 2010-07-16 11:51 14904 ----a-w- c:\windows\Help\OEM\Scripts\LaunchHPForums.exe
2010-06-16 05:48 . 2010-08-15 03:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-15 02:16 . 2010-06-15 02:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-03 17:21 . 2010-06-03 17:21 985704 ----a-w- c:\windows\system32\nvsvc.dll
2010-06-03 17:21 . 2010-06-03 17:21 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-06-03 17:21 . 2010-06-03 17:21 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-03 17:20 . 2010-06-03 17:20 95994 ----a-w- c:\windows\system32\nvcoproc.bin
2010-06-03 17:20 . 2010-06-03 17:20 149608 ----a-w- c:\windows\system32\nv3dappshext.dll
2010-06-03 17:20 . 2010-06-03 17:20 13684840 ----a-w- c:\windows\system32\nvcpl.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"NetMeter"="c:\program files\HooTech\NetMeter\HooNetMeter.exe" [2008-12-05 577536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-25 186904]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-21 106496]
"HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" [2009-11-19 1690680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-07-26 1713448]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" [2009-11-19 363064]
"IMSS"="c:\program files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2009-11-04 111640]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-11-18 495708]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-10-23 563736]
"IFXSPMGT"="c:\program files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" [2009-10-02 1107232]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"File Sanitizer"="c:\program files\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2009-11-04 11264000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 795936]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2010-7-2 1314816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2009-11-09 09:51 75320 ----a-w- c:\windows\System32\DeviceNP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe86.sys [2009-10-26 48640]
R2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe86.sys [2009-10-29 47616]
R2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe86.sys [2009-09-28 38912]
R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-10-22 1639728]
R3 ALSysIO;ALSysIO;c:\users\LUK~1\AppData\Local\Temp\ALSysIO.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2009-11-09 362040]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
R3 RTCore32;RTCore32;c:\program files\RM Clock\RTCore32.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-08-17 691696]
S0 SafeBoot;SafeBoot;c:\windows\System32\Drivers\SafeBoot.sys [2009-11-11 110520]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
S1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys [2009-10-02 39712]
S1 RsvLock;RsvLock; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe [2009-03-03 81920]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
S2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
S2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2009-11-19 102968]
S2 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-11-19 102968]
S2 Hp.Skyroom.Windows.Service;HP SkyRoom;c:\program files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [2009-11-20 124984]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-11-12 250936]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-11-11 277096]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-11-04 297984]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
S2 rgsender;Remote Graphics Sender Service;c:\program files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [2009-11-19 379904]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k6232.sys [2009-11-06 214696]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
S3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-21 58880]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-21 137728]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-11-12 66664]
S3 rismc32;RICOH Smart Card Reader;c:\windows\system32\DRIVERS\rismc32.sys [2009-07-20 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-08-18 c:\windows\Tasks\Embedded Security Backup Schedule.job
- c:\program files\Hewlett-Packard\Embedded Security Software\SpBackupWz.exe [2009-10-02 21:38]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\03pdztpb.default\
FF - prefs.js: browser.startup.homepage - google.sk
FF - component: c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\components\dpffcli.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: >>UNKNOWN [0x83004000]<< >>UNKNOWN [0x89843000]<< >>UNKNOWN [0x8A685000]<< >>UNKNOWN [0x8A64A000]<< >>UNKNOWN [0x83414000]<< >>UNKNOWN [0x89617000]<< >>UNKNOWN [0x89A00000]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-597615714-1545844737-3701375177-1000\Software\SecuROM\License information*]
"datasecu"=hex:09,c4,b9,4a,42,99,a1,58,f9,6b,53,c7,ae,2e,03,b5,e4,fb,ec,bf,76,
ff,c6,a0,3f,b2,de,55,5d,c8,5f,d1,d8,9d,1d,dc,26,dc,0f,42,76,28,fc,f3,f4,f7,\
"rkeysecu"=hex:e7,0f,5c,17,33,67,de,2f,4e,2b,93,51,67,9f,3e,81
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\DPFPApi.DLL
.
Completion time: 2010-08-18 22:10:06
ComboFix-quarantined-files.txt 2010-08-18 20:10
Pre-Run: 124 530 462 720 bytes free
Post-Run: 124 376 797 184 bytes free
- - End Of File - - B775B708DCACD07C6BF70EA8D57B909E
Microsoft Windows 7 Professional 6.1.7600.0.1250.421.1051.18.1973.920 [GMT 2:00]
Running from: c:\users\Lukáš\Desktop\ComboFix.exe
Command switches used :: c:\users\Lukáš\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: ESET NOD32 Antivirus 3.0 *enabled* (Updated) {E5E70D32-0101-4B98-A4D6-D1D15C3BB448}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 )))))))))))))))))))))))))))))))
.
2010-08-18 20:07 . 2010-08-18 20:07 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-08-18 20:07 . 2010-08-18 20:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-18 20:07 . 2010-08-18 20:07 -------- d-----w- c:\users\Admin\AppData\Local\temp
2010-08-17 13:12 . 2010-08-17 13:12 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-08-17 13:12 . 2010-08-17 13:12 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-08-16 21:23 . 2010-08-17 13:16 -------- d-----w- C:\rsit
2010-08-16 18:14 . 2010-08-16 18:14 -------- d-----w- c:\windows\system32\Wat
2010-08-16 17:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-16 17:06 . 2010-08-16 17:06 -------- d-----w- c:\programdata\Malwarebytes
2010-08-16 17:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-16 17:06 . 2010-08-16 17:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-15 04:28 . 2010-08-17 20:19 -------- d-----w- c:\program files\trend micro
2010-08-15 03:25 . 2010-06-30 06:25 978432 ----a-w- c:\windows\system32\wininet.dll
2010-08-15 03:24 . 2010-06-19 06:33 3955080 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-15 03:24 . 2010-06-19 06:33 3899784 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-15 03:24 . 2010-06-14 06:12 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-15 03:24 . 2010-06-19 04:07 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-08-15 03:24 . 2010-06-22 02:47 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-15 03:24 . 2010-06-22 02:47 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-15 03:24 . 2010-06-19 06:23 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-08-15 03:24 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-08-15 03:24 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-08-15 03:24 . 2010-06-22 02:47 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-08-15 03:24 . 2010-06-16 05:48 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-15 03:24 . 2010-06-08 06:02 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-08-15 02:57 . 2010-08-15 02:57 -------- d-----w- C:\NVIDIA
2010-08-12 12:53 . 2008-07-12 06:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-08-12 12:53 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-08-12 12:53 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-08-06 18:21 . 2010-08-15 03:17 -------- d-----w- c:\windows\system32\AGEIA
2010-08-06 18:21 . 2010-08-15 03:16 -------- d-----w- c:\program files\AGEIA Technologies
2010-08-02 07:45 . 2010-08-05 18:33 -------- d-----w- c:\programdata\LightScribe
2010-08-02 07:21 . 2010-08-02 07:34 -------- d-----w- c:\program files\Nero
2010-08-02 07:20 . 2010-08-02 07:28 -------- d-----w- c:\programdata\Nero
2010-08-02 07:20 . 2010-08-02 07:43 -------- d-----w- c:\program files\Common Files\Nero
2010-08-02 07:20 . 2010-08-02 07:20 -------- d-----w- c:\program files\Common Files\LightScribe
2010-07-29 16:28 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-07-29 16:28 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-07-29 16:28 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-07-29 16:28 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-07-26 13:11 . 2010-07-26 13:11 120104 ----a-w- c:\windows\system32\SynTPCo4.dll
2010-07-26 13:11 . 2010-07-26 13:11 242992 ----a-w- c:\windows\system32\drivers\SynTP.sys
2010-07-26 13:11 . 2010-07-26 13:11 165160 ----a-w- c:\windows\system32\SynTPAPI.dll
2010-07-26 13:11 . 2010-07-26 13:11 210216 ----a-w- c:\windows\system32\SynCtrl.dll
2010-07-26 13:11 . 2010-07-26 13:11 173352 ----a-w- c:\windows\system32\SynCOM.dll
2010-07-26 13:00 . 2010-07-26 13:00 -------- d-----w- c:\programdata\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-07-26 12:57 . 2010-04-14 17:09 1230088 ----a-w- c:\programdata\Hewlett-Packard\HPSAUpgrade2\HpSAUpgrade.exe
2010-07-25 11:11 . 2007-07-11 09:13 101376 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2010-07-25 11:11 . 2007-07-11 09:11 23424 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2010-07-25 11:11 . 2010-07-25 11:11 -------- d-----w- c:\program files\Huawei technologies
2010-07-24 23:03 . 2010-08-15 02:59 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-07-22 21:16 . 2010-07-22 21:16 -------- d-----w- c:\users\Admin\AppData\Local\Broadcom
2010-07-22 21:08 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-07-22 21:07 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-07-22 21:07 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-07-22 21:07 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-07-22 21:07 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-07-22 21:07 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-07-22 21:00 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-07-22 21:00 . 2010-07-22 21:00 -------- d-----w- c:\program files\MSXML 4.0
2010-07-22 20:59 . 2009-12-11 07:44 133720 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-07-22 20:59 . 2009-12-11 07:38 1037312 ----a-w- c:\windows\system32\lsasrv.dll
2010-07-22 20:59 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-07-22 20:59 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-07-22 20:59 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-07-22 20:59 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-07-22 20:59 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-07-22 20:59 . 2010-04-23 07:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-07-22 20:57 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-07-22 20:57 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-07-22 20:57 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-07-22 20:57 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-07-22 20:57 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-07-22 20:57 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-07-22 20:57 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-07-22 20:57 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-07-22 20:57 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-07-22 20:57 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-07-22 20:57 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-07-22 20:47 . 2010-07-22 20:47 -------- d-----w- c:\users\Admin\AppData\Roaming\HPQLOG
2010-07-22 20:47 . 2010-07-22 20:47 124664 ----a-w- c:\users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-22 20:47 . 2010-07-22 20:47 -------- d-----w- c:\users\Admin\AppData\Roaming\Infineon
2010-07-22 20:47 . 2010-08-17 13:18 -------- d-----w- c:\users\Admin\AppData\Roaming\translateclient
2010-07-22 20:47 . 2010-07-22 20:47 -------- d-----w- c:\users\Admin\AppData\Local\PDFC
2010-07-22 20:47 . 2010-08-17 13:15 -------- d-----r- c:\users\Admin\Virtual Machines
2010-07-21 22:09 . 2008-01-07 12:29 352 ---ha-w- c:\windows\nod32fixtemdono.reg
2010-07-21 21:59 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-07-21 21:59 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2010-07-21 21:58 . 2010-07-21 21:58 -------- d-----w- c:\program files\Microsoft Works
2010-07-21 21:58 . 2010-08-16 18:14 -------- d-----w- c:\program files\Microsoft.NET
2010-07-21 21:58 . 2010-07-21 21:58 -------- d-----w- c:\windows\PCHEALTH
2010-07-21 21:55 . 2010-07-21 22:00 -------- d-----w- c:\programdata\Microsoft Help
2010-07-21 21:55 . 2010-07-21 21:55 -------- d-----r- C:\MSOCache
2010-07-21 13:38 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2010-07-21 13:38 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-07-21 13:38 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-07-21 13:38 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-07-21 13:38 . 2009-10-27 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-07-21 13:38 . 2010-07-21 13:38 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-07-21 13:36 . 2010-07-21 13:36 -------- d-----w- C:\TOTO
2010-07-21 13:36 . 2010-07-21 13:36 -------- d-----w- C:\slovnik
2010-07-21 13:34 . 2010-07-22 14:18 -------- d-----w- C:\Fraps
2010-07-21 13:33 . 2010-07-21 13:33 -------- d-----w- c:\program files\FreeTime
2010-07-21 13:06 . 2010-07-21 13:06 -------- d-----w- c:\program files\CCleaner
2010-07-20 14:12 . 2010-07-20 14:12 -------- d-----w- c:\program files\HooTech
2010-07-20 13:43 . 2008-03-03 12:25 5702 ---ha-w- c:\windows\nod32restoretemdono.reg
2010-07-20 13:41 . 2010-07-21 22:09 -------- d-----w- c:\program files\ESET
2010-07-20 13:34 . 2010-07-20 13:34 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-20 13:23 . 2010-07-20 13:23 -------- d-----w- c:\program files\Translate Client
2010-07-20 13:05 . 2010-07-20 13:06 -------- d-----w- c:\programdata\Roxio
2010-07-20 13:04 . 2010-08-08 12:37 -------- d-----w- c:\program files\Roxio
2010-07-20 13:04 . 2010-07-20 13:04 -------- d-----w- c:\program files\Common Files\SureThing Shared
2010-07-20 13:04 . 2010-07-20 13:04 -------- d-----w- c:\programdata\Sonic
2010-07-20 13:04 . 2010-07-20 13:07 -------- d-----w- c:\program files\Common Files\Sonic Shared
2010-07-20 13:04 . 2010-07-20 13:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-07-20 13:03 . 2010-07-20 13:05 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-07-20 12:59 . 2010-07-20 12:59 -------- d-----w- c:\program files\Common Files\DigitalPersona
2010-07-20 12:54 . 2010-07-20 12:54 -------- d-----w- c:\windows\DPDrv
2010-07-20 12:54 . 2010-07-20 12:54 -------- d-----w- c:\programdata\Macrovision
2010-07-20 12:49 . 2010-07-20 12:49 368912 ----a-w- c:\windows\system32\VBAR332.DLL
2010-07-20 12:49 . 2010-07-20 12:49 252176 ----a-w- c:\windows\system32\MSRD2X35.DLL
2010-07-20 12:49 . 2010-07-20 12:49 24848 ----a-w- c:\windows\system32\MSJTER35.DLL
2010-07-20 12:49 . 2010-07-20 12:49 123664 ----a-w- c:\windows\system32\MSJINT35.DLL
2010-07-20 12:49 . 2010-07-20 12:49 1045776 ----a-w- c:\windows\system32\MSJET35.DLL
2010-07-20 12:38 . 2010-07-09 11:18 20328 ----a-w- c:\windows\system32\drivers\cpuz134_x32.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-18 19:50 . 2010-07-20 12:54 -------- d-----w- c:\programdata\HPQLOG
2010-08-15 03:16 . 2010-03-01 00:42 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-15 03:06 . 2010-03-01 00:42 -------- d-----w- c:\programdata\NVIDIA
2010-08-12 12:41 . 2010-01-30 18:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-11 22:34 . 2010-07-20 12:56 -------- d-----w- c:\programdata\PDFC
2010-08-02 00:53 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Sidebar
2010-08-02 00:53 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-08-02 00:53 . 2009-07-27 13:49 -------- d-----w- c:\program files\Windows Journal
2010-08-02 00:53 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Photo Viewer
2010-08-02 00:53 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Defender
2010-08-02 00:52 . 2009-07-14 04:52 -------- d-----w- c:\program files\DVD Maker
2010-07-26 13:11 . 2010-01-30 18:14 -------- d-----w- c:\programdata\Hewlett-Packard
2010-07-26 13:00 . 2010-01-30 18:04 -------- d-----w- c:\program files\Hewlett-Packard
2010-07-22 20:46 . 2010-07-22 20:46 -------- d-----w- c:\users\Admin\AppData\Roaming\DigitalPersona
2010-07-20 13:07 . 2010-03-01 00:58 -------- d-----w- c:\programdata\Uninstall
2010-07-20 12:59 . 2010-07-20 12:59 -------- d-----w- c:\program files\Common Files\ActivIdentity
2010-07-20 12:59 . 2010-07-20 12:59 -------- d-----w- c:\program files\ActivIdentity
2010-07-20 12:58 . 2010-07-20 12:58 -------- d-----w- c:\programdata\Infineon
2010-07-20 12:56 . 2010-07-20 12:56 -------- d-----w- c:\program files\PDF Complete
2010-07-20 12:51 . 2010-03-01 00:53 -------- d-----w- c:\program files\Common Files\SNP2UVC
2010-07-19 20:14 . 2010-07-19 20:14 0 --sha-r- c:\windows\system32\drivers\103C_HP_bNB_EliteBook 8540p_Y5336AN_0U_QCND0083SBD_E582943-221_4A_I1521_SHP_V32.28_68CVD F.03_T100121_WU48-0_L41B_M1974_J250_7Intel_8652_92.40_#100130_N808610EA;80864239_(WD918EA#ARL)_XMOBILE_CN10_Z_2_G10DE0A2C.MRK
2010-07-16 11:51 . 2010-07-16 11:51 14904 ----a-w- c:\windows\Help\OEM\Scripts\LaunchHPForums.exe
2010-06-16 05:48 . 2010-08-15 03:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-15 02:16 . 2010-06-15 02:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
2010-06-03 17:21 . 2010-06-03 17:21 985704 ----a-w- c:\windows\system32\nvsvc.dll
2010-06-03 17:21 . 2010-06-03 17:21 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-06-03 17:21 . 2010-06-03 17:21 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-06-03 17:20 . 2010-06-03 17:20 95994 ----a-w- c:\windows\system32\nvcoproc.bin
2010-06-03 17:20 . 2010-06-03 17:20 149608 ----a-w- c:\windows\system32\nv3dappshext.dll
2010-06-03 17:20 . 2010-06-03 17:20 13684840 ----a-w- c:\windows\system32\nvcpl.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"NetMeter"="c:\program files\HooTech\NetMeter\HooNetMeter.exe" [2008-12-05 577536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-11-11 287800]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-25 186904]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-11-21 106496]
"HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe" [2009-11-19 1690680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-07-26 1713448]
"HPWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" [2009-11-19 363064]
"IMSS"="c:\program files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2009-11-04 111640]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-11-18 495708]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-10-23 563736]
"IFXSPMGT"="c:\program files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" [2009-10-02 1107232]
"acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936]
"File Sanitizer"="c:\program files\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2009-11-04 11264000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-9-4 795936]
Translate Client.lnk - c:\program files\Translate Client\translateclient.exe [2010-7-2 1314816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2009-11-09 09:51 75320 ----a-w- c:\windows\System32\DeviceNP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe86.sys [2009-10-26 48640]
R2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe86.sys [2009-10-29 47616]
R2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe86.sys [2009-09-28 38912]
R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-10-22 1639728]
R3 ALSysIO;ALSysIO;c:\users\LUK~1\AppData\Local\Temp\ALSysIO.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2009-11-09 362040]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
R3 RTCore32;RTCore32;c:\program files\RM Clock\RTCore32.sys [x]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-08-17 691696]
S0 SafeBoot;SafeBoot;c:\windows\System32\Drivers\SafeBoot.sys [2009-11-11 110520]
S0 SbAlg;SbAlg; [x]
S0 SbFsLock;SbFsLock; [x]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
S1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys [2009-10-02 39712]
S1 RsvLock;RsvLock; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe [2009-03-03 81920]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
S2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
S2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
S2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2009-11-19 102968]
S2 HP ProtectTools Service;HP ProtectTools Service;c:\program files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
S2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-11-19 102968]
S2 Hp.Skyroom.Windows.Service;HP SkyRoom;c:\program files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [2009-11-20 124984]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-11-12 250936]
S2 HpFkCryptService;Drive Encryption Service;c:\program files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-11-11 277096]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-11-04 297984]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
S2 rgsender;Remote Graphics Sender Service;c:\program files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [2009-11-19 379904]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
S3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k6232.sys [2009-11-06 214696]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
S3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-21 58880]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-21 137728]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-11-12 66664]
S3 rismc32;RICOH Smart Card Reader;c:\windows\system32\DRIVERS\rismc32.sys [2009-07-20 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-08-18 c:\windows\Tasks\Embedded Security Backup Schedule.job
- c:\program files\Hewlett-Packard\Embedded Security Software\SpBackupWz.exe [2009-10-02 21:38]
.
.
------- Supplementary Scan -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Lukáš\AppData\Roaming\Mozilla\Firefox\Profiles\03pdztpb.default\
FF - prefs.js: browser.startup.homepage - google.sk
FF - component: c:\program files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\components\dpffcli.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: >>UNKNOWN [0x83004000]<< >>UNKNOWN [0x89843000]<< >>UNKNOWN [0x8A685000]<< >>UNKNOWN [0x8A64A000]<< >>UNKNOWN [0x83414000]<< >>UNKNOWN [0x89617000]<< >>UNKNOWN [0x89A00000]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-597615714-1545844737-3701375177-1000\Software\SecuROM\License information*]
"datasecu"=hex:09,c4,b9,4a,42,99,a1,58,f9,6b,53,c7,ae,2e,03,b5,e4,fb,ec,bf,76,
ff,c6,a0,3f,b2,de,55,5d,c8,5f,d1,d8,9d,1d,dc,26,dc,0f,42,76,28,fc,f3,f4,f7,\
"rkeysecu"=hex:e7,0f,5c,17,33,67,de,2f,4e,2b,93,51,67,9f,3e,81
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\DPFPApi.DLL
.
Completion time: 2010-08-18 22:10:06
ComboFix-quarantined-files.txt 2010-08-18 20:10
Pre-Run: 124 530 462 720 bytes free
Post-Run: 124 376 797 184 bytes free
- - End Of File - - B775B708DCACD07C6BF70EA8D57B909E
Re: Trojan-spy.win32.year2010-wors

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors
PC sa chová v naprostom poriadku...
tu je log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2010-08-18 22:31:43
Microsoft Windows 7 Professional
System drive C: has 119 GB (54%) free of 221 GB
Total RAM: 1973 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:31:51, on 18. 8. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HooTech\NetMeter\HooNetMeter.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender_gui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Lukáš\Desktop\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [IFXSPMGT] "C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Lukáš')
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [NetMeter] C:\Program Files\HooTech\NetMeter\HooNetMeter.exe (User 'Lukáš')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP SkyRoom (Hp.Skyroom.Windows.Service) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: Remote Graphics Sender Service (rgsender) - Hewlett-Packard, Inc. - c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 13296 bytes
======Scheduled tasks folder======
C:\windows\tasks\Embedded Security Backup Schedule.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-11-04 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-11-24 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-12 287800]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"NUSB3MON"=c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-21 106496]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2009-11-20 1690680]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-07-26 1713448]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [2009-11-20 363064]
"IMSS"=C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2009-11-04 111640]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-11-18 495708]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"IFXSPMGT"=C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
"acevents"=C:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-03 153640]
"accrdsub"=C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-03 400936]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-11-04 11264000]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2007-12-21 1443072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-09 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ip6fw.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLmSsp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpcdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpwd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdpipe.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdtcp.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\termservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-08-18 22:30:05 ----D---- C:\rsit
2010-08-18 22:10:10 ----SHD---- C:\$RECYCLE.BIN
2010-08-18 22:10:08 ----D---- C:\windows\temp
2010-08-17 15:12:43 ----A---- C:\windows\system32\drivers\sptd.sys
2010-08-17 15:12:19 ----D---- C:\Program Files\DAEMON Tools Lite
2010-08-16 20:14:13 ----D---- C:\windows\system32\Wat
2010-08-16 19:06:27 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2010-08-16 19:06:26 ----D---- C:\ProgramData\Malwarebytes
2010-08-16 19:06:26 ----A---- C:\windows\system32\drivers\mbam.sys
2010-08-16 19:06:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-08-15 06:28:17 ----D---- C:\Program Files\trend micro
2010-08-15 05:25:04 ----A---- C:\windows\system32\mshtml.dll
2010-08-15 05:25:04 ----A---- C:\windows\system32\ieframe.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\wininet.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\urlmon.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\mstime.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedssync.exe
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedsbs.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\jsproxy.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\ieui.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iepeers.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iedkcs32.dll
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntoskrnl.exe
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-08-15 05:24:45 ----A---- C:\windows\system32\drivers\tcpip.sys
2010-08-15 05:24:44 ----A---- C:\windows\system32\win32k.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\rtutils.dll
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv2.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv.sys
2010-08-15 05:24:42 ----A---- C:\windows\system32\schannel.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\ir32_32.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\iccvid.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\drivers\srvnet.sys
2010-08-15 05:24:41 ----A---- C:\windows\system32\msxml3.dll
2010-08-15 04:57:06 ----D---- C:\NVIDIA
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DX9_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\d3dx10_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DCompiler_39.dll
2010-08-06 20:21:31 ----D---- C:\windows\system32\AGEIA
2010-08-06 20:21:30 ----D---- C:\Program Files\AGEIA Technologies
2010-08-03 20:43:07 ----A---- C:\windows\system32\shell32.dll
2010-08-02 09:45:04 ----D---- C:\ProgramData\LightScribe
2010-08-02 09:21:07 ----D---- C:\Program Files\Nero
2010-08-02 09:20:45 ----D---- C:\ProgramData\Nero
2010-08-02 09:20:43 ----D---- C:\Program Files\Common Files\Nero
2010-08-02 09:20:26 ----D---- C:\Program Files\Common Files\LightScribe
2010-08-02 02:24:43 ----D---- C:\windows\system32\appmgmt
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAudio2_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAPOFX1_4.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\xactengine3_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\X3DAudio1_7.dll
2010-07-26 15:11:50 ----A---- C:\windows\system32\SynTPCo4.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\SynTPAPI.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\drivers\SynTP.sys
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCtrl.dll
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCOM.dll
2010-07-26 15:00:11 ----D---- C:\ProgramData\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewusbmdm.sys
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewdcsc.sys
2010-07-25 13:11:20 ----D---- C:\Program Files\Huawei technologies
2010-07-25 01:03:50 ----D---- C:\ProgramData\NVIDIA Corporation
2010-07-22 23:08:31 ----A---- C:\windows\system32\msv1_0.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHostProxy.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHost.exe
2010-07-22 23:07:22 ----A---- C:\windows\system32\netfxperf.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\mscoree.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\dfshim.dll
2010-07-22 23:03:55 ----A---- C:\windows\system32\MRT.exe
2010-07-22 23:00:44 ----A---- C:\windows\system32\browserchoice.exe
2010-07-22 23:00:11 ----D---- C:\Program Files\MSXML 4.0
2010-07-22 22:59:11 ----A---- C:\windows\system32\lsasrv.dll
2010-07-22 22:59:11 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2010-07-22 22:59:10 ----A---- C:\windows\system32\inetcomm.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\ntdll.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\msasn1.dll
2010-07-22 22:59:04 ----A---- C:\windows\explorer.exe
2010-07-22 22:59:03 ----A---- C:\windows\system32\winlogon.exe
2010-07-22 22:59:02 ----A---- C:\windows\system32\tzres.dll
2010-07-22 22:58:58 ----A---- C:\windows\system32\drivers\fvevol.sys
2010-07-22 22:58:56 ----A---- C:\windows\system32\wmp.dll
2010-07-22 22:58:55 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2010-07-22 22:58:55 ----A---- C:\windows\system32\CertEnroll.dll
2010-07-22 22:58:54 ----A---- C:\windows\system32\winresume.exe
2010-07-22 22:58:54 ----A---- C:\windows\system32\winload.exe
2010-07-22 22:58:53 ----A---- C:\windows\system32\wmploc.DLL
2010-07-22 22:58:50 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2010-07-22 22:58:36 ----A---- C:\windows\system32\msdri.dll
2010-07-22 22:58:36 ----A---- C:\windows\system32\CPFilters.dll
2010-07-22 22:58:35 ----A---- C:\windows\system32\psisdecd.dll
2010-07-22 22:58:31 ----A---- C:\windows\system32\kernel32.dll
2010-07-22 22:58:30 ----A---- C:\windows\system32\apphelp.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\tsbyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\quartz.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msvidc32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msrle32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\mciavi32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\iyuv_32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\avifil32.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\vbscript.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\jscript.dll
2010-07-22 22:58:19 ----A---- C:\windows\system32\t2embed.dll
2010-07-22 22:58:16 ----A---- C:\windows\system32\asycfilt.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc_isv.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate.exe
2010-07-22 22:57:17 ----A---- C:\windows\system32\fontsub.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmlib.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmfd.dll
2010-07-22 22:47:42 ----D---- C:\Users\Admin\AppData\Roaming\HPQLOG
2010-07-22 22:47:30 ----D---- C:\Users\Admin\AppData\Roaming\Infineon
2010-07-22 22:47:28 ----D---- C:\Users\Admin\AppData\Roaming\translateclient
2010-07-22 22:46:57 ----D---- C:\Users\Admin\AppData\Roaming\DigitalPersona
2010-07-22 22:46:56 ----D---- C:\Users\Admin\AppData\Roaming\Identities
2010-07-22 22:46:43 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2010-07-21 23:59:45 ----A---- C:\windows\system32\msonpmon.dll
2010-07-21 23:58:32 ----D---- C:\Program Files\Microsoft Works
2010-07-21 23:58:20 ----D---- C:\Program Files\Microsoft Visual Studio
2010-07-21 23:58:20 ----D---- C:\Program Files\Common Files\DESIGNER
2010-07-21 23:58:03 ----D---- C:\windows\PCHEALTH
2010-07-21 23:58:03 ----D---- C:\Program Files\Microsoft.NET
2010-07-21 23:55:50 ----D---- C:\ProgramData\Microsoft Help
2010-07-21 23:55:50 ----D---- C:\Program Files\Microsoft Office
2010-07-21 23:55:36 ----RD---- C:\MSOCache
2010-07-21 22:51:47 ----A---- C:\windows\system32\XAudio2_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\xactengine3_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx11_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx10_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dcsx_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\D3DCompiler_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAudio2_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAPOFX1_3.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\xactengine3_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\X3DAudio1_6.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\d3dx10_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DCompiler_41.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAudio2_2.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAPOFX1_1.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DX9_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\d3dx10_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DCompiler_40.dll
2010-07-21 22:51:44 ----A---- C:\windows\system32\xactengine3_2.dll
2010-07-21 15:38:29 ----A---- C:\windows\system32\unrar.dll
2010-07-21 15:38:28 ----A---- C:\windows\avisplitter.ini
2010-07-21 15:38:26 ----A---- C:\windows\system32\yv12vfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidvfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidcore.dll
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll.manifest
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll
2010-07-21 15:38:17 ----D---- C:\Program Files\K-Lite Codec Pack
2010-07-21 15:36:12 ----D---- C:\TOTO
2010-07-21 15:36:11 ----D---- C:\slovnik
2010-07-21 15:34:42 ----D---- C:\Fraps
2010-07-21 15:33:34 ----A---- C:\windows\system32\pncrt.dll
2010-07-21 15:33:14 ----D---- C:\Program Files\FreeTime
2010-07-21 15:06:18 ----D---- C:\Program Files\CCleaner
2010-07-20 16:12:55 ----D---- C:\Program Files\HooTech
2010-07-20 15:41:31 ----D---- C:\ProgramData\ESET
2010-07-20 15:41:31 ----D---- C:\Program Files\ESET
2010-07-20 15:34:38 ----D---- C:\ProgramData\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Common Files\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Adobe
2010-07-20 15:23:02 ----D---- C:\Program Files\Translate Client
2010-07-20 15:05:38 ----D---- C:\ProgramData\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Common Files\SureThing Shared
2010-07-20 15:04:18 ----D---- C:\ProgramData\Sonic
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\Sonic Shared
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-20 15:03:53 ----D---- C:\Program Files\Common Files\Roxio Shared
2010-07-20 14:59:45 ----D---- C:\Program Files\Common Files\DigitalPersona
2010-07-20 14:59:15 ----D---- C:\Program Files\Common Files\ActivIdentity
2010-07-20 14:59:15 ----D---- C:\Program Files\ActivIdentity
2010-07-20 14:58:19 ----D---- C:\ProgramData\Infineon
2010-07-20 14:56:05 ----A---- C:\windows\system32\pdfc_port.dll
2010-07-20 14:56:04 ----D---- C:\Program Files\PDF Complete
2010-07-20 14:56:01 ----D---- C:\ProgramData\PDFC
2010-07-20 14:54:45 ----D---- C:\ProgramData\HPQLOG
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hant
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hans
2010-07-20 14:54:34 ----D---- C:\windows\system32\pt
2010-07-20 14:54:34 ----D---- C:\windows\system32\ko
2010-07-20 14:54:34 ----D---- C:\windows\system32\ja
2010-07-20 14:54:34 ----D---- C:\windows\system32\it
2010-07-20 14:54:34 ----D---- C:\windows\system32\fr
2010-07-20 14:54:34 ----D---- C:\windows\system32\es
2010-07-20 14:54:34 ----D---- C:\windows\system32\de
2010-07-20 14:54:34 ----D---- C:\windows\DPDrv
2010-07-20 14:54:32 ----D---- C:\ProgramData\Macrovision
2010-07-20 14:49:47 ----A---- C:\windows\system32\VBAR332.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSRD2X35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJTER35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJINT35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJET35.DLL
2010-07-20 14:38:17 ----A---- C:\windows\system32\drivers\cpuz134_x32.sys
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAudio2_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAPOFX1_2.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\xactengine3_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\X3DAudio1_5.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAPOFX1_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_4.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_3.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DX9_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_37.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xinput1_3.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_9.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_8.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_10.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\X3DAudio1_2.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DX9_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_34.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_7.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_6.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_5.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_32.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\D3DCompiler_33.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_4.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_3.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\x3daudio1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\d3dx9_31.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\xactengine2_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\x3daudio1_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_30.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_29.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_28.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_27.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_26.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_25.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_24.dll
2010-07-19 23:23:48 ----D---- C:\HRY
2010-07-19 23:22:28 ----D---- C:\windows\system32\URTTEMP
2010-07-19 22:59:26 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-07-19 22:45:25 ----A---- C:\windows\system32\drivers\cpuz133_x32.sys
2010-07-19 22:45:24 ----D---- C:\Program Files\CPUID
2010-07-19 22:38:44 ----D---- C:\Program Files\WinRAR
2010-07-19 22:34:04 ----D---- C:\Program Files\Mozilla Firefox
2010-07-19 22:31:02 ----N---- C:\windows\system32\MpSigStub.exe
2010-07-19 22:30:20 ----A---- C:\windows\system32\wintrust.dll
2010-07-19 22:30:19 ----A---- C:\windows\system32\cabview.dll
2010-07-19 22:16:10 ----D---- C:\Program Files\Windows Live
2010-07-19 22:16:00 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-19 22:15:46 ----D---- C:\Program Files\Microsoft Sync Framework
2010-07-19 22:15:39 ----D---- C:\Program Files\Microsoft
2010-07-19 22:15:04 ----D---- C:\Program Files\Common Files\Windows Live
======List of files/folders modified in the last 1 months======
2010-08-18 22:31:51 ----D---- C:\windows\Prefetch
2010-08-18 22:28:22 ----D---- C:\windows\System32
2010-08-18 22:28:14 ----D---- C:\windows\system32\config
2010-08-18 22:28:09 ----A---- C:\windows\system32\log.txt
2010-08-18 22:28:01 ----D---- C:\Windows
2010-08-18 22:21:48 ----D---- C:\windows\system32\drivers
2010-08-18 22:07:25 ----A---- C:\windows\system.ini
2010-08-18 22:03:12 ----D---- C:\windows\AppPatch
2010-08-18 22:03:10 ----D---- C:\Program Files\Common Files
2010-08-17 15:36:26 ----D---- C:\windows\Microsoft.NET
2010-08-17 15:36:25 ----RSD---- C:\windows\assembly
2010-08-17 15:12:39 ----SHD---- C:\System Volume Information
2010-08-17 15:12:19 ----RD---- C:\Program Files
2010-08-16 21:16:00 ----D---- C:\windows\system32\drivers\etc
2010-08-16 20:17:12 ----SHD---- C:\windows\Installer
2010-08-16 20:17:09 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-08-16 20:17:08 ----D---- C:\windows\inf
2010-08-16 20:15:00 ----D---- C:\windows\system32\en-US
2010-08-16 20:14:17 ----D---- C:\windows\winsxs
2010-08-16 20:14:06 ----D---- C:\windows\system32\catroot
2010-08-16 19:06:26 ----D---- C:\ProgramData
2010-08-16 19:04:15 ----D---- C:\windows\debug
2010-08-15 05:31:55 ----D---- C:\windows\system32\migration
2010-08-15 05:31:55 ----D---- C:\Program Files\Internet Explorer
2010-08-15 05:24:55 ----D---- C:\windows\system32\catroot2
2010-08-15 05:17:46 ----D---- C:\windows\system32\wbem
2010-08-15 05:17:05 ----D---- C:\windows\Tasks
2010-08-15 05:17:05 ----D---- C:\windows\system32\wfp
2010-08-15 05:17:05 ----D---- C:\windows\system32\DriverStore
2010-08-15 05:17:01 ----D---- C:\windows\Help
2010-08-15 05:17:00 ----D---- C:\windows\AppCompat
2010-08-15 05:16:59 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-15 05:16:55 ----D---- C:\windows\registration
2010-08-15 05:06:54 ----D---- C:\windows\LiveKernelReports
2010-08-15 05:06:47 ----D---- C:\ProgramData\NVIDIA
2010-08-12 14:41:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-08 14:30:10 ----D---- C:\SYSTEM.SAV
2010-08-02 09:33:10 ----SD---- C:\ProgramData\Microsoft
2010-08-02 02:57:58 ----D---- C:\windows\rescache
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Sidebar
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Mail
2010-08-02 02:53:43 ----D---- C:\windows\servicing
2010-08-02 02:53:43 ----D---- C:\windows\ehome
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Photo Viewer
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Media Player
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Journal
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Defender
2010-08-02 02:53:43 ----D---- C:\Program Files\Common Files\System
2010-08-02 02:53:42 ----D---- C:\windows\system32\sysprep
2010-08-02 02:53:42 ----D---- C:\windows\system32\sl-SI
2010-08-02 02:53:42 ----D---- C:\windows\system32\oobe
2010-08-02 02:53:42 ----D---- C:\windows\system32\migwiz
2010-08-02 02:53:42 ----D---- C:\windows\PolicyDefinitions
2010-08-02 02:53:36 ----D---- C:\windows\system32\WCN
2010-08-02 02:53:30 ----D---- C:\windows\system32\hr-HR
2010-08-02 02:53:16 ----D---- C:\windows\IME
2010-08-02 02:53:14 ----D---- C:\windows\system32\winrm
2010-08-02 02:53:14 ----D---- C:\windows\system32\slmgr
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs-CZ
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs
2010-08-02 02:53:14 ----D---- C:\windows\system32\Boot
2010-08-02 02:53:05 ----D---- C:\windows\system32\drivers\cs-CZ
2010-08-02 02:53:04 ----D---- C:\windows\system32\MUI
2010-08-02 02:53:04 ----D---- C:\windows\system32\drivers\UMDF
2010-08-02 02:53:04 ----D---- C:\windows\system32\Dism
2010-08-02 02:53:02 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-08-02 02:53:01 ----D---- C:\windows\system32\com
2010-08-02 02:52:49 ----D---- C:\Program Files\DVD Maker
2010-08-02 02:52:48 ----D---- C:\windows\en-US
2010-08-02 02:52:47 ----D---- C:\windows\system32\drivers\en-US
2010-08-02 02:52:43 ----D---- C:\windows\Speech
2010-08-02 02:36:22 ----D---- C:\swsetup
2010-07-31 08:15:27 ----D---- C:\windows\Logs
2010-07-27 17:26:36 ----D---- C:\windows\system32\Tasks
2010-07-26 15:11:21 ----D---- C:\ProgramData\Hewlett-Packard
2010-07-26 15:00:56 ----D---- C:\Program Files\Hewlett-Packard
2010-07-25 13:14:43 ----D---- C:\windows\ModemLogs
2010-07-22 23:11:40 ----D---- C:\windows\system32\wdi
2010-07-22 23:11:12 ----D---- C:\windows\system32\sk-SK
2010-07-22 22:46:42 ----RD---- C:\Users
2010-07-21 23:58:29 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-21 23:58:18 ----D---- C:\windows\ShellNew
2010-07-21 23:58:08 ----RSD---- C:\windows\Fonts
2010-07-21 23:56:08 ----A---- C:\windows\win.ini
2010-07-20 15:07:16 ----D---- C:\ProgramData\Uninstall
2010-07-20 14:51:02 ----D---- C:\Program Files\Common Files\SNP2UVC
2010-07-19 22:30:46 ----D---- C:\windows\SoftwareDistribution
2010-07-19 22:17:11 ----RD---- C:\Program Files\Online Services
2010-07-19 22:12:31 ----D---- C:\windows\system32\restore
2010-07-19 21:00:09 ----D---- C:\windows\Panther
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\windows\System32\Drivers\PxHelp20.sys [2009-07-09 45200]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\windows\System32\Drivers\SafeBoot.sys [2009-11-11 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-11-11 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-11-11 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-08-17 691696]
R0 storvsc;storvsc; C:\windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 easdrv;easdrv; C:\windows\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdir;epfwtdir; C:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [2009-10-02 39712]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-11-11 40088]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-01-30 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2009-12-01 295128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 cpuz133;cpuz133; \??\C:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
R2 cpuz134;cpuz134; \??\C:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
R2 eamon;EAMON; C:\windows\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 rimmptsk;rimmptsk; C:\windows\system32\DRIVERS\rimmptsk.sys [2009-06-26 48128]
R2 rimsptsk;rimsptsk; C:\windows\system32\DRIVERS\rimsptsk.sys [2009-06-26 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\windows\system32\DRIVERS\rixdptsk.sys [2009-06-26 38400]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-08-03 1161760]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\windows\system32\DRIVERS\e1k6232.sys [2009-11-06 214696]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 Impcd;Impcd; C:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-21 58880]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-21 137728]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2009-11-12 66664]
R3 rismc32;RICOH Smart Card Reader; C:\windows\system32\DRIVERS\rismc32.sys [2009-07-21 49152]
R3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-09-18 1765168]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-11-18 420864]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-07-26 242992]
R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
R3 vpcbus;Virtual PC Host Bus Service; C:\windows\system32\DRIVERS\vpchbus.sys [2010-01-30 165376]
R3 vpcusb;USB Virtualization Connector Service; C:\windows\system32\DRIVERS\vpcusb.sys [2010-01-30 78336]
S2 rimspci;rimspci; C:\windows\system32\DRIVERS\rimspe86.sys [2009-10-27 48640]
S2 risdpcie;risdpcie; C:\windows\system32\DRIVERS\risdpe86.sys [2009-10-29 47616]
S2 rixdpcie;rixdpcie; C:\windows\system32\DRIVERS\rixdpe86.sys [2009-09-29 38912]
S3 ALSysIO;ALSysIO; \??\C:\Users\LUK~1\AppData\Local\Temp\ALSysIO.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2009-09-17 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-07-11 101376]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RTCore32;RTCore32; \??\C:\Program Files\RM Clock\RTCore32.sys []
S3 s3cap;s3cap; C:\windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe [2009-03-03 81920]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-08-03 14336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-24 300808]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-03-24 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2009-11-20 102968]
R2 HP ProtectTools Service;HP ProtectTools Service; C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-11-20 102968]
R2 Hp.Skyroom.Windows.Service;HP SkyRoom; C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [2009-11-21 124984]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-11-12 250936]
R2 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-11-11 277096]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-11-04 297984]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
R2 IFXTCS;Trusted Platform Core Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [2009-10-02 988448]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2010-06-03 129640]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PersonalSecureDriveService;Personal Secure Drive Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [2009-10-02 214304]
R2 rgsender;Remote Graphics Sender Service; c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [2009-11-19 379904]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe [2009-11-18 229458]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-05-01 229944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-10-22 1639728]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2007-12-21 19200]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\windows\system32\flcdlock.exe [2009-11-09 362040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1343400]
-----------------EOF-----------------

tu je log:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Admin at 2010-08-18 22:31:43
Microsoft Windows 7 Professional
System drive C: has 119 GB (54%) free of 221 GB
Total RAM: 1973 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:31:51, on 18. 8. 2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HooTech\NetMeter\HooNetMeter.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsender_gui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\coreshredder.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Translate Client\translateclient.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\Users\Lukáš\Desktop\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: HP ProtectTools Security Manager Extension - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden
O4 - HKLM\..\Run: [IMSS] "C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [IFXSPMGT] "C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [acevents] "C:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Lukáš')
O4 - HKUS\S-1-5-21-597615714-1545844737-3701375177-1000\..\Run: [NetMeter] C:\Program Files\HooTech\NetMeter\HooNetMeter.exe (User 'Lukáš')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Translate Client.lnk = C:\Program Files\Translate Client\translateclient.exe
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O20 - Winlogon Notify: DeviceNP - DeviceNP.dll (file missing)
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: @C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - C:\windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP SkyRoom (Hp.Skyroom.Windows.Service) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\windows\system32\nvvsvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: Remote Graphics Sender Service (rgsender) - Hewlett-Packard, Inc. - c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
--
End of file - 13296 bytes
======Scheduled tasks folder======
C:\windows\tasks\Embedded Security Backup Schedule.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-11-04 117248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{395610AE-C624-4f58-B89E-23733EA00F9A}]
HP ProtectTools Security Manager Extension - C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpOtsPluginIe8.dll [2009-11-24 1471752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14 92504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v sieti Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-11-12 287800]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-08-25 186904]
"NUSB3MON"=c:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2009-11-21 106496]
"HPPowerAssistant"=C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2009-11-20 1690680]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-07-26 1713448]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [2009-11-20 363064]
"IMSS"=C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2009-11-04 111640]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-11-18 495708]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-10-23 563736]
"IFXSPMGT"=C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
"acevents"=C:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-03 153640]
"accrdsub"=C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-03 400936]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-11-04 11264000]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2007-12-21 1443072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Translate Client.lnk - C:\Program Files\Translate Client\translateclient.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-11-09 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=DPPassFilter
scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ip6fw.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NtLmSsp]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpcdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpwd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdpipe.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdtcp.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\termservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-08-18 22:30:05 ----D---- C:\rsit
2010-08-18 22:10:10 ----SHD---- C:\$RECYCLE.BIN
2010-08-18 22:10:08 ----D---- C:\windows\temp
2010-08-17 15:12:43 ----A---- C:\windows\system32\drivers\sptd.sys
2010-08-17 15:12:19 ----D---- C:\Program Files\DAEMON Tools Lite
2010-08-16 20:14:13 ----D---- C:\windows\system32\Wat
2010-08-16 19:06:27 ----A---- C:\windows\system32\drivers\mbamswissarmy.sys
2010-08-16 19:06:26 ----D---- C:\ProgramData\Malwarebytes
2010-08-16 19:06:26 ----A---- C:\windows\system32\drivers\mbam.sys
2010-08-16 19:06:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-08-15 06:28:17 ----D---- C:\Program Files\trend micro
2010-08-15 05:25:04 ----A---- C:\windows\system32\mshtml.dll
2010-08-15 05:25:04 ----A---- C:\windows\system32\ieframe.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\wininet.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\urlmon.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\mstime.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedssync.exe
2010-08-15 05:25:03 ----A---- C:\windows\system32\msfeedsbs.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\jsproxy.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\ieui.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iepeers.dll
2010-08-15 05:25:03 ----A---- C:\windows\system32\iedkcs32.dll
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntoskrnl.exe
2010-08-15 05:24:46 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-08-15 05:24:45 ----A---- C:\windows\system32\drivers\tcpip.sys
2010-08-15 05:24:44 ----A---- C:\windows\system32\win32k.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\rtutils.dll
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv2.sys
2010-08-15 05:24:43 ----A---- C:\windows\system32\drivers\srv.sys
2010-08-15 05:24:42 ----A---- C:\windows\system32\schannel.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\ir32_32.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\iccvid.dll
2010-08-15 05:24:42 ----A---- C:\windows\system32\drivers\srvnet.sys
2010-08-15 05:24:41 ----A---- C:\windows\system32\msxml3.dll
2010-08-15 04:57:06 ----D---- C:\NVIDIA
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DX9_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\d3dx10_39.dll
2010-08-12 14:53:01 ----A---- C:\windows\system32\D3DCompiler_39.dll
2010-08-06 20:21:31 ----D---- C:\windows\system32\AGEIA
2010-08-06 20:21:30 ----D---- C:\Program Files\AGEIA Technologies
2010-08-03 20:43:07 ----A---- C:\windows\system32\shell32.dll
2010-08-02 09:45:04 ----D---- C:\ProgramData\LightScribe
2010-08-02 09:21:07 ----D---- C:\Program Files\Nero
2010-08-02 09:20:45 ----D---- C:\ProgramData\Nero
2010-08-02 09:20:43 ----D---- C:\Program Files\Common Files\Nero
2010-08-02 09:20:26 ----D---- C:\Program Files\Common Files\LightScribe
2010-08-02 02:24:43 ----D---- C:\windows\system32\appmgmt
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAudio2_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\XAPOFX1_4.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\xactengine3_6.dll
2010-07-29 18:28:51 ----A---- C:\windows\system32\X3DAudio1_7.dll
2010-07-26 15:11:50 ----A---- C:\windows\system32\SynTPCo4.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\SynTPAPI.dll
2010-07-26 15:11:49 ----A---- C:\windows\system32\drivers\SynTP.sys
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCtrl.dll
2010-07-26 15:11:47 ----A---- C:\windows\system32\SynCOM.dll
2010-07-26 15:00:11 ----D---- C:\ProgramData\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewusbmdm.sys
2010-07-25 13:11:48 ----A---- C:\windows\system32\drivers\ewdcsc.sys
2010-07-25 13:11:20 ----D---- C:\Program Files\Huawei technologies
2010-07-25 01:03:50 ----D---- C:\ProgramData\NVIDIA Corporation
2010-07-22 23:08:31 ----A---- C:\windows\system32\msv1_0.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHostProxy.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\PresentationHost.exe
2010-07-22 23:07:22 ----A---- C:\windows\system32\netfxperf.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\mscoree.dll
2010-07-22 23:07:22 ----A---- C:\windows\system32\dfshim.dll
2010-07-22 23:03:55 ----A---- C:\windows\system32\MRT.exe
2010-07-22 23:00:44 ----A---- C:\windows\system32\browserchoice.exe
2010-07-22 23:00:11 ----D---- C:\Program Files\MSXML 4.0
2010-07-22 22:59:11 ----A---- C:\windows\system32\lsasrv.dll
2010-07-22 22:59:11 ----A---- C:\windows\system32\drivers\ksecpkg.sys
2010-07-22 22:59:10 ----A---- C:\windows\system32\inetcomm.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\ntdll.dll
2010-07-22 22:59:06 ----A---- C:\windows\system32\msasn1.dll
2010-07-22 22:59:04 ----A---- C:\windows\explorer.exe
2010-07-22 22:59:03 ----A---- C:\windows\system32\winlogon.exe
2010-07-22 22:59:02 ----A---- C:\windows\system32\tzres.dll
2010-07-22 22:58:58 ----A---- C:\windows\system32\drivers\fvevol.sys
2010-07-22 22:58:56 ----A---- C:\windows\system32\wmp.dll
2010-07-22 22:58:55 ----A---- C:\windows\system32\drivers\dxgkrnl.sys
2010-07-22 22:58:55 ----A---- C:\windows\system32\CertEnroll.dll
2010-07-22 22:58:54 ----A---- C:\windows\system32\winresume.exe
2010-07-22 22:58:54 ----A---- C:\windows\system32\winload.exe
2010-07-22 22:58:53 ----A---- C:\windows\system32\wmploc.DLL
2010-07-22 22:58:50 ----A---- C:\windows\system32\drivers\mrxsmb10.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb20.sys
2010-07-22 22:58:49 ----A---- C:\windows\system32\drivers\mrxsmb.sys
2010-07-22 22:58:36 ----A---- C:\windows\system32\msdri.dll
2010-07-22 22:58:36 ----A---- C:\windows\system32\CPFilters.dll
2010-07-22 22:58:35 ----A---- C:\windows\system32\psisdecd.dll
2010-07-22 22:58:31 ----A---- C:\windows\system32\kernel32.dll
2010-07-22 22:58:30 ----A---- C:\windows\system32\apphelp.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\tsbyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\quartz.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msyuv.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msvidc32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\msrle32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\mciavi32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\iyuv_32.dll
2010-07-22 22:58:28 ----A---- C:\windows\system32\avifil32.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\vbscript.dll
2010-07-22 22:58:27 ----A---- C:\windows\system32\jscript.dll
2010-07-22 22:58:19 ----A---- C:\windows\system32\t2embed.dll
2010-07-22 22:58:16 ----A---- C:\windows\system32\asycfilt.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc_isv.dll
2010-07-22 22:57:19 ----A---- C:\windows\system32\secproc.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp_isv.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\secproc_ssp.dll
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_ssp.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate_isv.exe
2010-07-22 22:57:18 ----A---- C:\windows\system32\RMActivate.exe
2010-07-22 22:57:17 ----A---- C:\windows\system32\fontsub.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmlib.dll
2010-07-22 22:57:17 ----A---- C:\windows\system32\atmfd.dll
2010-07-22 22:47:42 ----D---- C:\Users\Admin\AppData\Roaming\HPQLOG
2010-07-22 22:47:30 ----D---- C:\Users\Admin\AppData\Roaming\Infineon
2010-07-22 22:47:28 ----D---- C:\Users\Admin\AppData\Roaming\translateclient
2010-07-22 22:46:57 ----D---- C:\Users\Admin\AppData\Roaming\DigitalPersona
2010-07-22 22:46:56 ----D---- C:\Users\Admin\AppData\Roaming\Identities
2010-07-22 22:46:43 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2010-07-21 23:59:45 ----A---- C:\windows\system32\msonpmon.dll
2010-07-21 23:58:32 ----D---- C:\Program Files\Microsoft Works
2010-07-21 23:58:20 ----D---- C:\Program Files\Microsoft Visual Studio
2010-07-21 23:58:20 ----D---- C:\Program Files\Common Files\DESIGNER
2010-07-21 23:58:03 ----D---- C:\windows\PCHEALTH
2010-07-21 23:58:03 ----D---- C:\Program Files\Microsoft.NET
2010-07-21 23:55:50 ----D---- C:\ProgramData\Microsoft Help
2010-07-21 23:55:50 ----D---- C:\Program Files\Microsoft Office
2010-07-21 23:55:36 ----RD---- C:\MSOCache
2010-07-21 22:51:47 ----A---- C:\windows\system32\XAudio2_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\xactengine3_5.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx11_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dx10_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\d3dcsx_42.dll
2010-07-21 22:51:47 ----A---- C:\windows\system32\D3DCompiler_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAudio2_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\XAPOFX1_3.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\xactengine3_4.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\X3DAudio1_6.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_42.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DX9_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\d3dx10_41.dll
2010-07-21 22:51:46 ----A---- C:\windows\system32\D3DCompiler_41.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAudio2_2.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\XAPOFX1_1.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DX9_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\d3dx10_40.dll
2010-07-21 22:51:45 ----A---- C:\windows\system32\D3DCompiler_40.dll
2010-07-21 22:51:44 ----A---- C:\windows\system32\xactengine3_2.dll
2010-07-21 15:38:29 ----A---- C:\windows\system32\unrar.dll
2010-07-21 15:38:28 ----A---- C:\windows\avisplitter.ini
2010-07-21 15:38:26 ----A---- C:\windows\system32\yv12vfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidvfw.dll
2010-07-21 15:38:25 ----A---- C:\windows\system32\xvidcore.dll
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll.manifest
2010-07-21 15:38:20 ----A---- C:\windows\system32\ff_vfw.dll
2010-07-21 15:38:17 ----D---- C:\Program Files\K-Lite Codec Pack
2010-07-21 15:36:12 ----D---- C:\TOTO
2010-07-21 15:36:11 ----D---- C:\slovnik
2010-07-21 15:34:42 ----D---- C:\Fraps
2010-07-21 15:33:34 ----A---- C:\windows\system32\pncrt.dll
2010-07-21 15:33:14 ----D---- C:\Program Files\FreeTime
2010-07-21 15:06:18 ----D---- C:\Program Files\CCleaner
2010-07-20 16:12:55 ----D---- C:\Program Files\HooTech
2010-07-20 15:41:31 ----D---- C:\ProgramData\ESET
2010-07-20 15:41:31 ----D---- C:\Program Files\ESET
2010-07-20 15:34:38 ----D---- C:\ProgramData\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Common Files\Adobe
2010-07-20 15:34:34 ----D---- C:\Program Files\Adobe
2010-07-20 15:23:02 ----D---- C:\Program Files\Translate Client
2010-07-20 15:05:38 ----D---- C:\ProgramData\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Roxio
2010-07-20 15:04:55 ----D---- C:\Program Files\Common Files\SureThing Shared
2010-07-20 15:04:18 ----D---- C:\ProgramData\Sonic
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\Sonic Shared
2010-07-20 15:04:05 ----D---- C:\Program Files\Common Files\PX Storage Engine
2010-07-20 15:03:53 ----D---- C:\Program Files\Common Files\Roxio Shared
2010-07-20 14:59:45 ----D---- C:\Program Files\Common Files\DigitalPersona
2010-07-20 14:59:15 ----D---- C:\Program Files\Common Files\ActivIdentity
2010-07-20 14:59:15 ----D---- C:\Program Files\ActivIdentity
2010-07-20 14:58:19 ----D---- C:\ProgramData\Infineon
2010-07-20 14:56:05 ----A---- C:\windows\system32\pdfc_port.dll
2010-07-20 14:56:04 ----D---- C:\Program Files\PDF Complete
2010-07-20 14:56:01 ----D---- C:\ProgramData\PDFC
2010-07-20 14:54:45 ----D---- C:\ProgramData\HPQLOG
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hant
2010-07-20 14:54:34 ----D---- C:\windows\system32\zh-Hans
2010-07-20 14:54:34 ----D---- C:\windows\system32\pt
2010-07-20 14:54:34 ----D---- C:\windows\system32\ko
2010-07-20 14:54:34 ----D---- C:\windows\system32\ja
2010-07-20 14:54:34 ----D---- C:\windows\system32\it
2010-07-20 14:54:34 ----D---- C:\windows\system32\fr
2010-07-20 14:54:34 ----D---- C:\windows\system32\es
2010-07-20 14:54:34 ----D---- C:\windows\system32\de
2010-07-20 14:54:34 ----D---- C:\windows\DPDrv
2010-07-20 14:54:32 ----D---- C:\ProgramData\Macrovision
2010-07-20 14:49:47 ----A---- C:\windows\system32\VBAR332.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSRD2X35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJTER35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJINT35.DLL
2010-07-20 14:49:47 ----A---- C:\windows\system32\MSJET35.DLL
2010-07-20 14:38:17 ----A---- C:\windows\system32\drivers\cpuz134_x32.sys
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAudio2_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\XAPOFX1_2.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\xactengine3_3.dll
2010-07-19 23:32:19 ----A---- C:\windows\system32\X3DAudio1_5.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAudio2_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\XAPOFX1_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_1.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\xactengine3_0.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_4.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\X3DAudio1_3.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DX9_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\d3dx10_37.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_38.dll
2010-07-19 23:32:18 ----A---- C:\windows\system32\D3DCompiler_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xinput1_3.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_9.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_8.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\xactengine2_10.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\X3DAudio1_2.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DX9_37.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx9_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\d3dx10_34.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_36.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_35.dll
2010-07-19 23:32:17 ----A---- C:\windows\system32\D3DCompiler_34.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_7.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_6.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\xactengine2_5.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx9_32.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10_33.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\d3dx10.dll
2010-07-19 23:32:16 ----A---- C:\windows\system32\D3DCompiler_33.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xinput1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_4.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_3.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_2.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\xactengine2_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\x3daudio1_1.dll
2010-07-19 23:32:15 ----A---- C:\windows\system32\d3dx9_31.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\xactengine2_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\x3daudio1_0.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_30.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_29.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_28.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_27.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_26.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_25.dll
2010-07-19 23:32:13 ----A---- C:\windows\system32\d3dx9_24.dll
2010-07-19 23:23:48 ----D---- C:\HRY
2010-07-19 23:22:28 ----D---- C:\windows\system32\URTTEMP
2010-07-19 22:59:26 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-07-19 22:45:25 ----A---- C:\windows\system32\drivers\cpuz133_x32.sys
2010-07-19 22:45:24 ----D---- C:\Program Files\CPUID
2010-07-19 22:38:44 ----D---- C:\Program Files\WinRAR
2010-07-19 22:34:04 ----D---- C:\Program Files\Mozilla Firefox
2010-07-19 22:31:02 ----N---- C:\windows\system32\MpSigStub.exe
2010-07-19 22:30:20 ----A---- C:\windows\system32\wintrust.dll
2010-07-19 22:30:19 ----A---- C:\windows\system32\cabview.dll
2010-07-19 22:16:10 ----D---- C:\Program Files\Windows Live
2010-07-19 22:16:00 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-19 22:15:46 ----D---- C:\Program Files\Microsoft Sync Framework
2010-07-19 22:15:39 ----D---- C:\Program Files\Microsoft
2010-07-19 22:15:04 ----D---- C:\Program Files\Common Files\Windows Live
======List of files/folders modified in the last 1 months======
2010-08-18 22:31:51 ----D---- C:\windows\Prefetch
2010-08-18 22:28:22 ----D---- C:\windows\System32
2010-08-18 22:28:14 ----D---- C:\windows\system32\config
2010-08-18 22:28:09 ----A---- C:\windows\system32\log.txt
2010-08-18 22:28:01 ----D---- C:\Windows
2010-08-18 22:21:48 ----D---- C:\windows\system32\drivers
2010-08-18 22:07:25 ----A---- C:\windows\system.ini
2010-08-18 22:03:12 ----D---- C:\windows\AppPatch
2010-08-18 22:03:10 ----D---- C:\Program Files\Common Files
2010-08-17 15:36:26 ----D---- C:\windows\Microsoft.NET
2010-08-17 15:36:25 ----RSD---- C:\windows\assembly
2010-08-17 15:12:39 ----SHD---- C:\System Volume Information
2010-08-17 15:12:19 ----RD---- C:\Program Files
2010-08-16 21:16:00 ----D---- C:\windows\system32\drivers\etc
2010-08-16 20:17:12 ----SHD---- C:\windows\Installer
2010-08-16 20:17:09 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-08-16 20:17:08 ----D---- C:\windows\inf
2010-08-16 20:15:00 ----D---- C:\windows\system32\en-US
2010-08-16 20:14:17 ----D---- C:\windows\winsxs
2010-08-16 20:14:06 ----D---- C:\windows\system32\catroot
2010-08-16 19:06:26 ----D---- C:\ProgramData
2010-08-16 19:04:15 ----D---- C:\windows\debug
2010-08-15 05:31:55 ----D---- C:\windows\system32\migration
2010-08-15 05:31:55 ----D---- C:\Program Files\Internet Explorer
2010-08-15 05:24:55 ----D---- C:\windows\system32\catroot2
2010-08-15 05:17:46 ----D---- C:\windows\system32\wbem
2010-08-15 05:17:05 ----D---- C:\windows\Tasks
2010-08-15 05:17:05 ----D---- C:\windows\system32\wfp
2010-08-15 05:17:05 ----D---- C:\windows\system32\DriverStore
2010-08-15 05:17:01 ----D---- C:\windows\Help
2010-08-15 05:17:00 ----D---- C:\windows\AppCompat
2010-08-15 05:16:59 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-15 05:16:55 ----D---- C:\windows\registration
2010-08-15 05:06:54 ----D---- C:\windows\LiveKernelReports
2010-08-15 05:06:47 ----D---- C:\ProgramData\NVIDIA
2010-08-12 14:41:11 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-08 14:30:10 ----D---- C:\SYSTEM.SAV
2010-08-02 09:33:10 ----SD---- C:\ProgramData\Microsoft
2010-08-02 02:57:58 ----D---- C:\windows\rescache
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Sidebar
2010-08-02 02:53:44 ----D---- C:\Program Files\Windows Mail
2010-08-02 02:53:43 ----D---- C:\windows\servicing
2010-08-02 02:53:43 ----D---- C:\windows\ehome
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Photo Viewer
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Media Player
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Journal
2010-08-02 02:53:43 ----D---- C:\Program Files\Windows Defender
2010-08-02 02:53:43 ----D---- C:\Program Files\Common Files\System
2010-08-02 02:53:42 ----D---- C:\windows\system32\sysprep
2010-08-02 02:53:42 ----D---- C:\windows\system32\sl-SI
2010-08-02 02:53:42 ----D---- C:\windows\system32\oobe
2010-08-02 02:53:42 ----D---- C:\windows\system32\migwiz
2010-08-02 02:53:42 ----D---- C:\windows\PolicyDefinitions
2010-08-02 02:53:36 ----D---- C:\windows\system32\WCN
2010-08-02 02:53:30 ----D---- C:\windows\system32\hr-HR
2010-08-02 02:53:16 ----D---- C:\windows\IME
2010-08-02 02:53:14 ----D---- C:\windows\system32\winrm
2010-08-02 02:53:14 ----D---- C:\windows\system32\slmgr
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs-CZ
2010-08-02 02:53:14 ----D---- C:\windows\system32\cs
2010-08-02 02:53:14 ----D---- C:\windows\system32\Boot
2010-08-02 02:53:05 ----D---- C:\windows\system32\drivers\cs-CZ
2010-08-02 02:53:04 ----D---- C:\windows\system32\MUI
2010-08-02 02:53:04 ----D---- C:\windows\system32\drivers\UMDF
2010-08-02 02:53:04 ----D---- C:\windows\system32\Dism
2010-08-02 02:53:02 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-08-02 02:53:01 ----D---- C:\windows\system32\com
2010-08-02 02:52:49 ----D---- C:\Program Files\DVD Maker
2010-08-02 02:52:48 ----D---- C:\windows\en-US
2010-08-02 02:52:47 ----D---- C:\windows\system32\drivers\en-US
2010-08-02 02:52:43 ----D---- C:\windows\Speech
2010-08-02 02:36:22 ----D---- C:\swsetup
2010-07-31 08:15:27 ----D---- C:\windows\Logs
2010-07-27 17:26:36 ----D---- C:\windows\system32\Tasks
2010-07-26 15:11:21 ----D---- C:\ProgramData\Hewlett-Packard
2010-07-26 15:00:56 ----D---- C:\Program Files\Hewlett-Packard
2010-07-25 13:14:43 ----D---- C:\windows\ModemLogs
2010-07-22 23:11:40 ----D---- C:\windows\system32\wdi
2010-07-22 23:11:12 ----D---- C:\windows\system32\sk-SK
2010-07-22 22:46:42 ----RD---- C:\Users
2010-07-21 23:58:29 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-21 23:58:18 ----D---- C:\windows\ShellNew
2010-07-21 23:58:08 ----RSD---- C:\windows\Fonts
2010-07-21 23:56:08 ----A---- C:\windows\win.ini
2010-07-20 15:07:16 ----D---- C:\ProgramData\Uninstall
2010-07-20 14:51:02 ----D---- C:\Program Files\Common Files\SNP2UVC
2010-07-19 22:30:46 ----D---- C:\windows\SoftwareDistribution
2010-07-19 22:17:11 ----RD---- C:\Program Files\Online Services
2010-07-19 22:12:31 ----D---- C:\windows\system32\restore
2010-07-19 21:00:09 ----D---- C:\windows\Panther
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aic78xx;aic78xx; C:\windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2009-07-08 25656]
R0 iaStor;Intel RAID Controller; C:\windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 pciide;pciide; C:\windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
R0 PxHelp20;PxHelp20; C:\windows\System32\Drivers\PxHelp20.sys [2009-07-09 45200]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 SafeBoot;SafeBoot; C:\windows\System32\Drivers\SafeBoot.sys [2009-11-11 110520]
R0 SbAlg;SbAlg; C:\windows\system32\drivers\SbAlg.sys [2009-11-11 51800]
R0 SbFsLock;SbFsLock; C:\windows\system32\drivers\SbFsLock.sys [2009-11-11 13256]
R0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-08-17 691696]
R0 storvsc;storvsc; C:\windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 easdrv;easdrv; C:\windows\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdir;epfwtdir; C:\windows\system32\DRIVERS\epfwtdir.sys [2007-12-21 33800]
R1 PersonalSecureDrive;PersonalSecureDrive; C:\windows\System32\drivers\psd.sys [2009-10-02 39712]
R1 RsvLock;RsvLock; C:\windows\system32\drivers\RsvLock.sys [2009-11-11 40088]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\windows\system32\DRIVERS\vpcnfltr.sys [2010-01-30 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\windows\system32\drivers\vpcvmm.sys [2009-12-01 295128]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R2 cpuz133;cpuz133; \??\C:\windows\system32\drivers\cpuz133_x32.sys [2010-05-11 20072]
R2 cpuz134;cpuz134; \??\C:\windows\system32\drivers\cpuz134_x32.sys [2010-07-09 20328]
R2 eamon;EAMON; C:\windows\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 Parvdm;Parvdm; C:\windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 rimmptsk;rimmptsk; C:\windows\system32\DRIVERS\rimmptsk.sys [2009-06-26 48128]
R2 rimsptsk;rimsptsk; C:\windows\system32\DRIVERS\rimsptsk.sys [2009-06-26 44544]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\windows\system32\DRIVERS\rixdptsk.sys [2009-06-26 38400]
R3 Accelerometer;HP Accelerometer; C:\windows\system32\DRIVERS\Accelerometer.sys [2009-07-08 33848]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\AGRSM.sys [2009-08-03 1161760]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K; C:\windows\system32\DRIVERS\e1k6232.sys [2009-11-06 214696]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2009-09-17 41088]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2009-04-29 15872]
R3 Impcd;Impcd; C:\windows\system32\DRIVERS\Impcd.sys [2009-10-26 125696]
R3 NETw5s32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit; C:\windows\system32\DRIVERS\NETw5s32.sys [2010-01-13 6755840]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2009-11-21 58880]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2009-11-21 137728]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\windows\system32\drivers\nvhda32v.sys [2009-11-12 66664]
R3 rismc32;RICOH Smart Card Reader; C:\windows\system32\DRIVERS\rismc32.sys [2009-07-21 49152]
R3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2009-09-18 1765168]
R3 STHDA;IDT High Definition Audio CODEC; C:\windows\system32\DRIVERS\stwrt.sys [2009-11-18 420864]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-07-26 242992]
R3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 30720]
R3 vpcbus;Virtual PC Host Bus Service; C:\windows\system32\DRIVERS\vpchbus.sys [2010-01-30 165376]
R3 vpcusb;USB Virtualization Connector Service; C:\windows\system32\DRIVERS\vpcusb.sys [2010-01-30 78336]
S2 rimspci;rimspci; C:\windows\system32\DRIVERS\rimspe86.sys [2009-10-27 48640]
S2 risdpcie;risdpcie; C:\windows\system32\DRIVERS\risdpe86.sys [2009-10-29 47616]
S2 rixdpcie;rixdpcie; C:\windows\system32\DRIVERS\rixdpe86.sys [2009-09-29 38912]
S3 ALSysIO;ALSysIO; \??\C:\Users\LUK~1\AppData\Local\Temp\ALSysIO.sys []
S3 amdagp;AMD AGP Bus Filter Driver; C:\windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BthEnum;Bluetooth Request Block Driver; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-09-17 86056]
S3 btwavdt;Bluetooth AVDT; C:\windows\system32\drivers\btwavdt.sys [2009-09-17 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-09-17 29472]
S3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-09-17 18472]
S3 DAMDrv;DAMDrv; C:\windows\system32\DRIVERS\DAMDrv.sys [2009-10-21 32312]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-07-11 101376]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RTCore32;RTCore32; \??\C:\Program Files\RM Clock\RTCore32.sys []
S3 s3cap;s3cap; C:\windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ac.sharedstore;ActivIdentity Shared Store Service; C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe [2009-06-03 207400]
R2 AESTFilters;Andrea ST Filters Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\aestsrv.exe [2009-03-03 81920]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [2009-08-03 14336]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-09-04 595232]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\windows\System32\svchost.exe [2009-07-14 20992]
R2 DpHost;@C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe,-128; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [2009-11-24 300808]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2010-03-24 121344]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2009-11-20 102968]
R2 HP ProtectTools Service;HP ProtectTools Service; C:\Program Files\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe [2009-11-18 36864]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2009-11-20 102968]
R2 Hp.Skyroom.Windows.Service;HP SkyRoom; C:\Program Files\Hewlett-Packard\HP SkyRoom\Hp.Skyroom.Windows.Service.exe [2009-11-21 124984]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; c:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2009-11-12 250936]
R2 HpFkCryptService;Drive Encryption Service; C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [2009-11-11 277096]
R2 HPFSService;File Sanitizer for HP ProtectTools; C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe [2009-11-04 297984]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2009-07-08 26168]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-08-25 354840]
R2 IFXSpMgtSrv;Security Platform Management Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-10-02 1107232]
R2 IFXTCS;Trusted Platform Core Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe [2009-10-02 988448]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2009-11-04 268824]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2010-06-03 129640]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files\PDF Complete\pdfsvc.exe [2009-10-23 635416]
R2 PersonalSecureDriveService;Personal Secure Drive Service; C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe [2009-10-02 214304]
R2 rgsender;Remote Graphics Sender Service; c:\Program Files\Hewlett-Packard\HP SkyRoom\remote graphics sender\rgsendersvc.exe [2009-11-19 379904]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 STacSV;Audio Service; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_1fb74af29935fce6\STacSV.exe [2009-11-18 229458]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-11-04 2320920]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-05-01 229944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2009-10-22 1639728]
S3 AppMgmt;@appmgmts.dll,-3250; C:\windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2007-12-21 19200]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing; C:\windows\system32\flcdlock.exe [2009-11-09 362040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1343400]
-----------------EOF-----------------
Re: Trojan-spy.win32.year2010-wors


- Klikněte na "Do a system scan only"
- U řádku
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
- Dejte fajfku do čtverečku a zmáčkněte Fix checked

Kód: Vybrat vše
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.
Pokud nejsou problémy, je to vše

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Trojan-spy.win32.year2010-wors
ok,urobil som to..reštartoval PC a všetko vyzerá byť ok..
veľmi pekne ti ďakujem za obrovskú pomoc a za vyčerpávajúci návod...

veľmi pekne ti ďakujem za obrovskú pomoc a za vyčerpávajúci návod...
