Worm32:Win32/Dorkbot'lnk
Napsal: 08 bře 2012 20:54
Zdravím, mám problém s tímto virem, nejspíše ho mám na flashce nebo na menším z exteráků. Nevím jak se ho zbavit, MS Essential ho sice odebere, ale za chvilku mi zas hlásí, že ho tady mám. Změní mi kompletně všechny složky na flashce/ext disku na systémový složky a vytvoří se zástupce odkazující na tyto složky. Jak se tohoto viru zbavit? Zde přikládám log. Předem díky za radu 
Logfile of random's system information tool 1.09 (written by random/random)
Run by HP at 2012-03-08 20:49:59
Microsoft Windows 7 Home Premium
System drive C: has 265 GB (90%) free of 293 GB
Total RAM: 3003 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:50:24, on 8.3.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\Ssms.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\taskhost.exe
C:\Users\HP\Desktop\RSIT.exe
C:\Program Files\trend micro\HP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Fatcth] C:\Users\HP\AppData\Roaming\Fatcth.exe
O4 - HKCU\..\RunOnce: [Microsoft Security Client] C:\Program Files\Microsoft Security Client\msseces.exe /UpdateAndQuickScan /OpenWebPageOnClose
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\aestsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\STacSV.exe
--
End of file - 8198 bytes
=========Mozilla firefox=========
ProfilePath - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\ceburbb0.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "{e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://search.centrum.cz/index.php?tool ... m-1.0.0&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\ceburbb0.default\extensions\
maps@ovi.com
{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-02 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-08-25 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-08-25 174104]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-08-25 151064]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2009-07-30 225280]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-08-13 467036]
"UpdatePRCShortCut"=C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-02 148888]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-07-23 498744]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Fatcth"=C:\Users\HP\AppData\Roaming\Fatcth.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Microsoft Security Client"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-08-13 217088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"WallpaperStyle"=2
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"msacm.siren"=sirenacm.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-03-08 20:50:00 ----D---- C:\Program Files\trend micro
2012-03-08 20:49:59 ----D---- C:\rsit
2012-03-08 19:22:43 ----D---- C:\Program Files\Microsoft Security Client
2012-03-08 18:37:59 ----A---- C:\Windows\AutoKMS.ini
2012-03-08 18:33:11 ----D---- C:\Program Files\Common Files\DESIGNER
2012-03-08 18:31:22 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-03-08 18:30:41 ----D---- C:\Program Files\Microsoft Analysis Services
2012-03-08 18:22:41 ----D---- C:\Users\HP\AppData\Roaming\WinRAR
2012-03-08 18:22:25 ----D---- C:\Program Files\WinRAR
2012-03-08 17:55:36 ----A---- C:\Windows\system32\perf-MSSQL10_50.SQLEXPRESS-sqlagtctr.dll
2012-03-08 17:55:21 ----A---- C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.51.2500.0.dll
2012-03-08 17:53:27 ----D---- C:\Windows\system32\RsFx
2012-03-08 17:46:48 ----D---- C:\Program Files\Microsoft SDKs
2012-03-08 17:46:46 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2012-03-08 17:46:28 ----D---- C:\Program Files\Microsoft Synchronization Services
2012-03-08 17:46:04 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-03-08 17:46:00 ----D---- C:\Windows\system32\1033
2012-03-08 17:38:42 ----D---- C:\Program Files\Microsoft SQL Server
2012-03-08 17:37:52 ----D---- C:\a634e0670685a941161ccbdfb077fe
2012-03-08 17:35:29 ----N---- C:\Windows\system32\MpSigStub.exe
2012-03-08 17:11:34 ----D---- C:\Users\HP\AppData\Roaming\Hewlett-Packard
2012-03-08 17:10:58 ----D---- C:\Users\HP\AppData\Roaming\Mozilla
2012-03-08 17:09:29 ----D---- C:\Program Files\Mozilla Firefox
2012-03-07 13:15:25 ----D---- C:\Windows\system32\sda
2012-03-07 07:29:17 ----D---- C:\Users\HP\AppData\Roaming\Adobe
2012-03-03 18:56:52 ----D---- C:\Windows\ehome
2012-03-03 18:54:56 ----SHD---- C:\System Volume Information
2012-03-03 11:42:26 ----D---- C:\Users\HP\AppData\Roaming\HpUpdate
2012-03-03 11:37:28 ----A---- C:\ProgramData\HPWALog.txt
2012-03-03 11:36:59 ----D---- C:\Users\HP\AppData\Roaming\Identities
2012-03-03 11:36:44 ----D---- C:\Users\HP\AppData\Roaming\hpqlog
2012-03-03 11:33:35 ----D---- C:\Users\HP\AppData\Roaming\HP TCS
2012-03-03 11:21:26 ----D---- C:\Program Files\Microsoft
2012-03-03 11:21:11 ----D---- C:\Program Files\Windows Live SkyDrive
2012-03-03 11:21:07 ----D---- C:\Program Files\Windows Live
2012-03-03 11:20:23 ----D---- C:\Program Files\Common Files\Windows Live
2012-03-03 11:18:06 ----D---- C:\Program Files\Microsoft Office Suite Activation Assistant
2012-03-03 11:17:47 ----A---- C:\Windows\system32\msonpmon.dll
2012-03-03 11:17:05 ----D---- C:\Program Files\Microsoft Works
2012-03-03 11:16:45 ----D---- C:\Windows\PCHEALTH
2012-03-03 11:16:45 ----D---- C:\Program Files\Microsoft.NET
2012-03-03 11:15:42 ----D---- C:\Windows\SHELLNEW
2012-03-03 11:15:35 ----D---- C:\ProgramData\Microsoft Help
2012-03-03 11:15:35 ----D---- C:\Program Files\Microsoft Office
2012-03-03 11:15:17 ----RHD---- C:\MSOCache
2012-03-03 11:14:53 ----D---- C:\ProgramData\Adobe
2012-03-03 11:14:51 ----D---- C:\Program Files\Common Files\Adobe
2012-03-03 11:14:51 ----D---- C:\Program Files\Adobe
2012-03-03 11:13:01 ----SD---- C:\Users\HP\AppData\Roaming\Microsoft
2012-03-03 11:13:01 ----D---- C:\Users\HP\AppData\Roaming\Media Center Programs
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Šablony
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Plocha
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Oblíbené položky
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Nabídka Start
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Dokumenty
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Data aplikací
2012-03-03 10:41:26 ----A---- C:\Windows\system32\drivers\btwl2cap.sys
2012-03-03 10:41:26 ----A---- C:\Windows\system32\drivers\btwavdt.sys
2012-03-03 10:41:25 ----A---- C:\Windows\system32\drivers\btwrchid.sys
2012-03-03 10:41:25 ----A---- C:\Windows\system32\drivers\btwaudio.sys
2012-03-03 10:41:11 ----D---- C:\Program Files\WIDCOMM
2012-03-03 10:35:28 ----D---- C:\ProgramData\Recovery
2012-03-03 10:15:29 ----D---- C:\Windows\Hewlett-Packard
2012-03-03 10:14:09 ----A---- C:\Windows\system32\bcmwlrc.dll
2012-03-03 10:14:08 ----D---- C:\Program Files\Broadcom
2012-03-03 10:13:49 ----N---- C:\Windows\system32\stapi32.dll
2012-03-03 10:13:28 ----A---- C:\Windows\system32\aestecap.dll
2012-03-03 10:13:27 ----A---- C:\Windows\system32\idtmini1.exe
2012-03-03 10:13:27 ----A---- C:\Windows\system32\AESTCom.dll
2012-03-03 10:13:27 ----A---- C:\Windows\system32\aestaren.dll
2012-03-03 10:13:27 ----A---- C:\Windows\system32\aestacap.dll
2012-03-03 10:13:26 ----A---- C:\Windows\system32\stlang.dll
2012-03-03 10:13:26 ----A---- C:\Windows\sttray.exe
2012-03-03 10:13:24 ----D---- C:\Windows\system32\SRSLabs
2012-03-03 10:13:15 ----A---- C:\Windows\system32\staco.dll
2012-03-03 10:12:00 ----A---- C:\Windows\system32\drivers\stwrt.sys
2012-03-03 10:11:59 ----A---- C:\Windows\system32\stcplx.dll
2012-03-03 10:11:59 ----A---- C:\Windows\system32\stapo.dll
2012-03-03 10:11:48 ----D---- C:\Program Files\IDT
2012-03-03 10:11:38 ----A---- C:\Windows\system32\CSVer.dll
2012-03-03 10:10:57 ----D---- C:\Windows\SoftwareDistribution
2012-03-03 10:10:48 ----A---- C:\Windows\system32\drivers\iaStor.sys
2012-03-03 10:10:39 ----D---- C:\Program Files\Intel
2012-03-03 10:09:55 ----A---- C:\Windows\system32\RTNUninst32.dll
2012-03-03 10:09:55 ----A---- C:\Windows\system32\RtNicProp32.dll
2012-03-03 10:09:55 ----A---- C:\Windows\system32\drivers\Rt86win7.sys
2012-03-03 10:09:48 ----A---- C:\Windows\system32\RTSUSTORicon.dll
2012-03-03 10:09:38 ----D---- C:\Program Files\Realtek
2012-03-03 10:09:38 ----A---- C:\Windows\system32\RtsUStor.dll
2012-03-03 10:09:38 ----A---- C:\Windows\system32\drivers\RtsUStor.sys
2012-03-03 10:09:23 ----D---- C:\Program Files\Apoint2K
2012-03-03 10:07:50 ----D---- C:\Windows\system32\Lang
2012-03-03 10:07:49 ----A---- C:\Windows\system32\igxpun.exe
2012-03-03 10:01:19 ----D---- C:\Windows\Prefetch
2012-03-03 10:00:00 ----ASH---- C:\pagefile.sys
2012-03-03 10:00:00 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 month======
2012-03-08 20:50:17 ----D---- C:\Windows\Temp
2012-03-08 20:50:00 ----D---- C:\Program Files
2012-03-08 20:36:41 ----D---- C:\Windows\Tasks
2012-03-08 20:36:41 ----D---- C:\Windows\system32\Tasks
2012-03-08 20:36:41 ----D---- C:\Windows
2012-03-08 20:35:54 ----RSD---- C:\Windows\assembly
2012-03-08 20:35:54 ----D---- C:\Windows\Microsoft.NET
2012-03-08 20:25:41 ----D---- C:\Windows\system32\LogFiles
2012-03-08 20:23:26 ----D---- C:\Windows\system32\wdi
2012-03-08 19:23:17 ----SHD---- C:\Windows\Installer
2012-03-08 19:23:01 ----D---- C:\Windows\system32\drivers
2012-03-08 19:23:01 ----D---- C:\Windows\system32\catroot
2012-03-08 19:23:01 ----D---- C:\Windows\System32
2012-03-08 19:23:01 ----D---- C:\Windows\inf
2012-03-08 19:23:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-03-08 19:22:59 ----SD---- C:\ProgramData\Microsoft
2012-03-08 19:22:38 ----D---- C:\Windows\winsxs
2012-03-08 19:21:53 ----D---- C:\Windows\system32\config
2012-03-08 18:51:36 ----HD---- C:\ProgramData
2012-03-08 18:50:11 ----D---- C:\ProgramData\Norton
2012-03-08 18:50:10 ----D---- C:\Program Files\Common Files
2012-03-08 18:33:58 ----RSD---- C:\Windows\Fonts
2012-03-08 18:33:50 ----D---- C:\Program Files\Common Files\microsoft shared
2012-03-08 18:33:35 ----D---- C:\Program Files\MSBuild
2012-03-08 17:42:00 ----D---- C:\Windows\system32\catroot2
2012-03-08 17:33:15 ----D---- C:\Program Files\Hewlett-Packard
2012-03-08 17:29:09 ----D---- C:\Windows\Help
2012-03-08 17:26:01 ----HD---- C:\Program Files\InstallShield Installation Information
2012-03-08 17:23:27 ----D---- C:\Program Files\HP Games
2012-03-08 17:23:10 ----D---- C:\ProgramData\WildTangent
2012-03-08 17:19:19 ----D---- C:\Windows\system32\DriverStore
2012-03-08 17:05:14 ----D---- C:\Windows\Logs
2012-03-03 18:58:55 ----A---- C:\Windows\CSUP.txt
2012-03-03 18:56:53 ----D---- C:\Program Files\Microsoft Games
2012-03-03 18:56:53 ----D---- C:\Program Files\DVD Maker
2012-03-03 18:56:52 ----D---- C:\Windows\system32\wbem
2012-03-03 18:56:52 ----D---- C:\Windows\PolicyDefinitions
2012-03-03 12:31:08 ----D---- C:\Windows\system32\drivers\UMDF
2012-03-03 11:36:57 ----SHD---- C:\$Recycle.Bin
2012-03-03 11:36:50 ----D---- C:\SwSetup
2012-03-03 11:33:33 ----RD---- C:\Program Files\Online Services
2012-03-03 11:33:31 ----D---- C:\Program Files\Windows Sidebar
2012-03-03 11:32:55 ----HD---- C:\SYSTEM.SAV
2012-03-03 11:32:55 ----D---- C:\Windows\system32\restore
2012-03-03 11:32:45 ----SHD---- C:\Recovery
2012-03-03 11:32:45 ----D---- C:\Windows\system32\Recovery
2012-03-03 11:14:21 ----D---- C:\Windows\rescache
2012-03-03 11:13:00 ----RD---- C:\Users
2012-03-03 11:12:34 ----D---- C:\Program Files\Windows NT
2012-03-03 11:10:48 ----D---- C:\Windows\Panther
2012-03-03 11:05:08 ----D---- C:\Windows\system32\sysprep
2012-03-03 11:04:04 ----D---- C:\ProgramData\Hewlett-Packard
2012-03-03 10:44:43 ----HD---- C:\HP
2012-03-03 10:43:47 ----D---- C:\ProgramData\Temp
2012-03-03 10:42:09 ----D---- C:\ProgramData\CyberLink
2012-03-03 10:41:20 ----SD---- C:\Windows\system32\Microsoft
2012-03-03 10:14:16 ----D---- C:\Windows\system32\zh-TW
2012-03-03 10:14:16 ----D---- C:\Windows\system32\zh-HK
2012-03-03 10:14:16 ----D---- C:\Windows\system32\zh-CN
2012-03-03 10:14:15 ----D---- C:\Windows\system32\tr-TR
2012-03-03 10:14:15 ----D---- C:\Windows\system32\th-TH
2012-03-03 10:14:15 ----D---- C:\Windows\system32\sv-SE
2012-03-03 10:14:14 ----D---- C:\Windows\system32\sl-SI
2012-03-03 10:14:14 ----D---- C:\Windows\system32\sk-SK
2012-03-03 10:14:13 ----D---- C:\Windows\system32\ru-RU
2012-03-03 10:14:13 ----D---- C:\Windows\system32\ro-RO
2012-03-03 10:14:13 ----D---- C:\Windows\system32\pt-PT
2012-03-03 10:14:13 ----D---- C:\Windows\system32\pt-BR
2012-03-03 10:14:13 ----D---- C:\Windows\system32\pl-PL
2012-03-03 10:14:12 ----D---- C:\Windows\system32\nl-NL
2012-03-03 10:14:12 ----D---- C:\Windows\system32\nb-NO
2012-03-03 10:14:12 ----D---- C:\Windows\system32\lv-LV
2012-03-03 10:14:12 ----D---- C:\Windows\system32\lt-LT
2012-03-03 10:14:12 ----D---- C:\Windows\system32\ko-KR
2012-03-03 10:14:12 ----D---- C:\Windows\system32\ja-JP
2012-03-03 10:14:12 ----D---- C:\Windows\system32\it-IT
2012-03-03 10:14:12 ----D---- C:\Windows\system32\hu-HU
2012-03-03 10:14:11 ----D---- C:\Windows\system32\hr-HR
2012-03-03 10:14:11 ----D---- C:\Windows\system32\he-IL
2012-03-03 10:14:11 ----D---- C:\Windows\system32\fr-FR
2012-03-03 10:14:11 ----D---- C:\Windows\system32\fi-FI
2012-03-03 10:14:11 ----D---- C:\Windows\system32\et-EE
2012-03-03 10:14:11 ----D---- C:\Windows\system32\es-ES
2012-03-03 10:14:11 ----D---- C:\Windows\system32\en-US
2012-03-03 10:14:10 ----D---- C:\Windows\system32\el-GR
2012-03-03 10:14:10 ----D---- C:\Windows\system32\de-DE
2012-03-03 10:14:10 ----D---- C:\Windows\system32\da-DK
2012-03-03 10:14:10 ----D---- C:\Windows\system32\cs-CZ
2012-03-03 10:14:10 ----D---- C:\Windows\system32\bg-BG
2012-03-03 10:14:10 ----D---- C:\Windows\system32\ar-SA
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKsl749e71cc;MpKsl749e71cc; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{403019BB-8AA5-469C-9CFD-157821E26B48}\MpKsl749e71cc.sys [2012-03-08 29904]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-08-21 212528]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-08-29 2661368]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-08-13 5946368]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-07-09 122880]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 185344]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt.sys [2009-08-13 409088]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-08 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 18344]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-07-17 171008]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S4 RsFx0151;RsFx0151 Driver; C:\Windows\system32\DRIVERS\RsFx0151.sys [2011-06-17 240736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\aestsrv.exe [2009-03-02 81920]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-30 582944]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2011-06-17 43040096]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2009-01-21 247152]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 97632]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\STacSV.exe [2009-08-13 221266]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-06-17 370016]
-----------------EOF-----------------

Logfile of random's system information tool 1.09 (written by random/random)
Run by HP at 2012-03-08 20:49:59
Microsoft Windows 7 Home Premium
System drive C: has 265 GB (90%) free of 293 GB
Total RAM: 3003 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:50:24, on 8.3.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\Ssms.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\system32\taskhost.exe
C:\Users\HP\Desktop\RSIT.exe
C:\Program Files\trend micro\HP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... on&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [Fatcth] C:\Users\HP\AppData\Roaming\Fatcth.exe
O4 - HKCU\..\RunOnce: [Microsoft Security Client] C:\Program Files\Microsoft Security Client\msseces.exe /UpdateAndQuickScan /OpenWebPageOnClose
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\aestsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\STacSV.exe
--
End of file - 8198 bytes
=========Mozilla firefox=========
ProfilePath - C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\ceburbb0.default
prefs.js - "browser.startup.homepage" - "http://www.google.cz/"
prefs.js - "extensions.enabledItems" - "{e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1, {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" - "http://search.centrum.cz/index.php?tool ... m-1.0.0&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\ceburbb0.default\extensions\
maps@ovi.com
{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-02 41368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-08-25 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-08-25 174104]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-08-25 151064]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2009-07-30 225280]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2009-08-13 467036]
"UpdatePRCShortCut"=C:\Program Files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-02 148888]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2008-12-08 54576]
""= []
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-07-23 498744]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Fatcth"=C:\Users\HP\AppData\Roaming\Fatcth.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Microsoft Security Client"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-08-13 217088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"WallpaperStyle"=2
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"msacm.siren"=sirenacm.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-03-08 20:50:00 ----D---- C:\Program Files\trend micro
2012-03-08 20:49:59 ----D---- C:\rsit
2012-03-08 19:22:43 ----D---- C:\Program Files\Microsoft Security Client
2012-03-08 18:37:59 ----A---- C:\Windows\AutoKMS.ini
2012-03-08 18:33:11 ----D---- C:\Program Files\Common Files\DESIGNER
2012-03-08 18:31:22 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-03-08 18:30:41 ----D---- C:\Program Files\Microsoft Analysis Services
2012-03-08 18:22:41 ----D---- C:\Users\HP\AppData\Roaming\WinRAR
2012-03-08 18:22:25 ----D---- C:\Program Files\WinRAR
2012-03-08 17:55:36 ----A---- C:\Windows\system32\perf-MSSQL10_50.SQLEXPRESS-sqlagtctr.dll
2012-03-08 17:55:21 ----A---- C:\Windows\system32\perf-MSSQL$SQLEXPRESS-sqlctr10.51.2500.0.dll
2012-03-08 17:53:27 ----D---- C:\Windows\system32\RsFx
2012-03-08 17:46:48 ----D---- C:\Program Files\Microsoft SDKs
2012-03-08 17:46:46 ----D---- C:\Program Files\Microsoft Visual Studio 9.0
2012-03-08 17:46:28 ----D---- C:\Program Files\Microsoft Synchronization Services
2012-03-08 17:46:04 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2012-03-08 17:46:00 ----D---- C:\Windows\system32\1033
2012-03-08 17:38:42 ----D---- C:\Program Files\Microsoft SQL Server
2012-03-08 17:37:52 ----D---- C:\a634e0670685a941161ccbdfb077fe
2012-03-08 17:35:29 ----N---- C:\Windows\system32\MpSigStub.exe
2012-03-08 17:11:34 ----D---- C:\Users\HP\AppData\Roaming\Hewlett-Packard
2012-03-08 17:10:58 ----D---- C:\Users\HP\AppData\Roaming\Mozilla
2012-03-08 17:09:29 ----D---- C:\Program Files\Mozilla Firefox
2012-03-07 13:15:25 ----D---- C:\Windows\system32\sda
2012-03-07 07:29:17 ----D---- C:\Users\HP\AppData\Roaming\Adobe
2012-03-03 18:56:52 ----D---- C:\Windows\ehome
2012-03-03 18:54:56 ----SHD---- C:\System Volume Information
2012-03-03 11:42:26 ----D---- C:\Users\HP\AppData\Roaming\HpUpdate
2012-03-03 11:37:28 ----A---- C:\ProgramData\HPWALog.txt
2012-03-03 11:36:59 ----D---- C:\Users\HP\AppData\Roaming\Identities
2012-03-03 11:36:44 ----D---- C:\Users\HP\AppData\Roaming\hpqlog
2012-03-03 11:33:35 ----D---- C:\Users\HP\AppData\Roaming\HP TCS
2012-03-03 11:21:26 ----D---- C:\Program Files\Microsoft
2012-03-03 11:21:11 ----D---- C:\Program Files\Windows Live SkyDrive
2012-03-03 11:21:07 ----D---- C:\Program Files\Windows Live
2012-03-03 11:20:23 ----D---- C:\Program Files\Common Files\Windows Live
2012-03-03 11:18:06 ----D---- C:\Program Files\Microsoft Office Suite Activation Assistant
2012-03-03 11:17:47 ----A---- C:\Windows\system32\msonpmon.dll
2012-03-03 11:17:05 ----D---- C:\Program Files\Microsoft Works
2012-03-03 11:16:45 ----D---- C:\Windows\PCHEALTH
2012-03-03 11:16:45 ----D---- C:\Program Files\Microsoft.NET
2012-03-03 11:15:42 ----D---- C:\Windows\SHELLNEW
2012-03-03 11:15:35 ----D---- C:\ProgramData\Microsoft Help
2012-03-03 11:15:35 ----D---- C:\Program Files\Microsoft Office
2012-03-03 11:15:17 ----RHD---- C:\MSOCache
2012-03-03 11:14:53 ----D---- C:\ProgramData\Adobe
2012-03-03 11:14:51 ----D---- C:\Program Files\Common Files\Adobe
2012-03-03 11:14:51 ----D---- C:\Program Files\Adobe
2012-03-03 11:13:01 ----SD---- C:\Users\HP\AppData\Roaming\Microsoft
2012-03-03 11:13:01 ----D---- C:\Users\HP\AppData\Roaming\Media Center Programs
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Šablony
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Plocha
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Oblíbené položky
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Nabídka Start
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Dokumenty
2012-03-03 11:12:34 ----SHD---- C:\ProgramData\Data aplikací
2012-03-03 10:41:26 ----A---- C:\Windows\system32\drivers\btwl2cap.sys
2012-03-03 10:41:26 ----A---- C:\Windows\system32\drivers\btwavdt.sys
2012-03-03 10:41:25 ----A---- C:\Windows\system32\drivers\btwrchid.sys
2012-03-03 10:41:25 ----A---- C:\Windows\system32\drivers\btwaudio.sys
2012-03-03 10:41:11 ----D---- C:\Program Files\WIDCOMM
2012-03-03 10:35:28 ----D---- C:\ProgramData\Recovery
2012-03-03 10:15:29 ----D---- C:\Windows\Hewlett-Packard
2012-03-03 10:14:09 ----A---- C:\Windows\system32\bcmwlrc.dll
2012-03-03 10:14:08 ----D---- C:\Program Files\Broadcom
2012-03-03 10:13:49 ----N---- C:\Windows\system32\stapi32.dll
2012-03-03 10:13:28 ----A---- C:\Windows\system32\aestecap.dll
2012-03-03 10:13:27 ----A---- C:\Windows\system32\idtmini1.exe
2012-03-03 10:13:27 ----A---- C:\Windows\system32\AESTCom.dll
2012-03-03 10:13:27 ----A---- C:\Windows\system32\aestaren.dll
2012-03-03 10:13:27 ----A---- C:\Windows\system32\aestacap.dll
2012-03-03 10:13:26 ----A---- C:\Windows\system32\stlang.dll
2012-03-03 10:13:26 ----A---- C:\Windows\sttray.exe
2012-03-03 10:13:24 ----D---- C:\Windows\system32\SRSLabs
2012-03-03 10:13:15 ----A---- C:\Windows\system32\staco.dll
2012-03-03 10:12:00 ----A---- C:\Windows\system32\drivers\stwrt.sys
2012-03-03 10:11:59 ----A---- C:\Windows\system32\stcplx.dll
2012-03-03 10:11:59 ----A---- C:\Windows\system32\stapo.dll
2012-03-03 10:11:48 ----D---- C:\Program Files\IDT
2012-03-03 10:11:38 ----A---- C:\Windows\system32\CSVer.dll
2012-03-03 10:10:57 ----D---- C:\Windows\SoftwareDistribution
2012-03-03 10:10:48 ----A---- C:\Windows\system32\drivers\iaStor.sys
2012-03-03 10:10:39 ----D---- C:\Program Files\Intel
2012-03-03 10:09:55 ----A---- C:\Windows\system32\RTNUninst32.dll
2012-03-03 10:09:55 ----A---- C:\Windows\system32\RtNicProp32.dll
2012-03-03 10:09:55 ----A---- C:\Windows\system32\drivers\Rt86win7.sys
2012-03-03 10:09:48 ----A---- C:\Windows\system32\RTSUSTORicon.dll
2012-03-03 10:09:38 ----D---- C:\Program Files\Realtek
2012-03-03 10:09:38 ----A---- C:\Windows\system32\RtsUStor.dll
2012-03-03 10:09:38 ----A---- C:\Windows\system32\drivers\RtsUStor.sys
2012-03-03 10:09:23 ----D---- C:\Program Files\Apoint2K
2012-03-03 10:07:50 ----D---- C:\Windows\system32\Lang
2012-03-03 10:07:49 ----A---- C:\Windows\system32\igxpun.exe
2012-03-03 10:01:19 ----D---- C:\Windows\Prefetch
2012-03-03 10:00:00 ----ASH---- C:\pagefile.sys
2012-03-03 10:00:00 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 month======
2012-03-08 20:50:17 ----D---- C:\Windows\Temp
2012-03-08 20:50:00 ----D---- C:\Program Files
2012-03-08 20:36:41 ----D---- C:\Windows\Tasks
2012-03-08 20:36:41 ----D---- C:\Windows\system32\Tasks
2012-03-08 20:36:41 ----D---- C:\Windows
2012-03-08 20:35:54 ----RSD---- C:\Windows\assembly
2012-03-08 20:35:54 ----D---- C:\Windows\Microsoft.NET
2012-03-08 20:25:41 ----D---- C:\Windows\system32\LogFiles
2012-03-08 20:23:26 ----D---- C:\Windows\system32\wdi
2012-03-08 19:23:17 ----SHD---- C:\Windows\Installer
2012-03-08 19:23:01 ----D---- C:\Windows\system32\drivers
2012-03-08 19:23:01 ----D---- C:\Windows\system32\catroot
2012-03-08 19:23:01 ----D---- C:\Windows\System32
2012-03-08 19:23:01 ----D---- C:\Windows\inf
2012-03-08 19:23:01 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-03-08 19:22:59 ----SD---- C:\ProgramData\Microsoft
2012-03-08 19:22:38 ----D---- C:\Windows\winsxs
2012-03-08 19:21:53 ----D---- C:\Windows\system32\config
2012-03-08 18:51:36 ----HD---- C:\ProgramData
2012-03-08 18:50:11 ----D---- C:\ProgramData\Norton
2012-03-08 18:50:10 ----D---- C:\Program Files\Common Files
2012-03-08 18:33:58 ----RSD---- C:\Windows\Fonts
2012-03-08 18:33:50 ----D---- C:\Program Files\Common Files\microsoft shared
2012-03-08 18:33:35 ----D---- C:\Program Files\MSBuild
2012-03-08 17:42:00 ----D---- C:\Windows\system32\catroot2
2012-03-08 17:33:15 ----D---- C:\Program Files\Hewlett-Packard
2012-03-08 17:29:09 ----D---- C:\Windows\Help
2012-03-08 17:26:01 ----HD---- C:\Program Files\InstallShield Installation Information
2012-03-08 17:23:27 ----D---- C:\Program Files\HP Games
2012-03-08 17:23:10 ----D---- C:\ProgramData\WildTangent
2012-03-08 17:19:19 ----D---- C:\Windows\system32\DriverStore
2012-03-08 17:05:14 ----D---- C:\Windows\Logs
2012-03-03 18:58:55 ----A---- C:\Windows\CSUP.txt
2012-03-03 18:56:53 ----D---- C:\Program Files\Microsoft Games
2012-03-03 18:56:53 ----D---- C:\Program Files\DVD Maker
2012-03-03 18:56:52 ----D---- C:\Windows\system32\wbem
2012-03-03 18:56:52 ----D---- C:\Windows\PolicyDefinitions
2012-03-03 12:31:08 ----D---- C:\Windows\system32\drivers\UMDF
2012-03-03 11:36:57 ----SHD---- C:\$Recycle.Bin
2012-03-03 11:36:50 ----D---- C:\SwSetup
2012-03-03 11:33:33 ----RD---- C:\Program Files\Online Services
2012-03-03 11:33:31 ----D---- C:\Program Files\Windows Sidebar
2012-03-03 11:32:55 ----HD---- C:\SYSTEM.SAV
2012-03-03 11:32:55 ----D---- C:\Windows\system32\restore
2012-03-03 11:32:45 ----SHD---- C:\Recovery
2012-03-03 11:32:45 ----D---- C:\Windows\system32\Recovery
2012-03-03 11:14:21 ----D---- C:\Windows\rescache
2012-03-03 11:13:00 ----RD---- C:\Users
2012-03-03 11:12:34 ----D---- C:\Program Files\Windows NT
2012-03-03 11:10:48 ----D---- C:\Windows\Panther
2012-03-03 11:05:08 ----D---- C:\Windows\system32\sysprep
2012-03-03 11:04:04 ----D---- C:\ProgramData\Hewlett-Packard
2012-03-03 10:44:43 ----HD---- C:\HP
2012-03-03 10:43:47 ----D---- C:\ProgramData\Temp
2012-03-03 10:42:09 ----D---- C:\ProgramData\CyberLink
2012-03-03 10:41:20 ----SD---- C:\Windows\system32\Microsoft
2012-03-03 10:14:16 ----D---- C:\Windows\system32\zh-TW
2012-03-03 10:14:16 ----D---- C:\Windows\system32\zh-HK
2012-03-03 10:14:16 ----D---- C:\Windows\system32\zh-CN
2012-03-03 10:14:15 ----D---- C:\Windows\system32\tr-TR
2012-03-03 10:14:15 ----D---- C:\Windows\system32\th-TH
2012-03-03 10:14:15 ----D---- C:\Windows\system32\sv-SE
2012-03-03 10:14:14 ----D---- C:\Windows\system32\sl-SI
2012-03-03 10:14:14 ----D---- C:\Windows\system32\sk-SK
2012-03-03 10:14:13 ----D---- C:\Windows\system32\ru-RU
2012-03-03 10:14:13 ----D---- C:\Windows\system32\ro-RO
2012-03-03 10:14:13 ----D---- C:\Windows\system32\pt-PT
2012-03-03 10:14:13 ----D---- C:\Windows\system32\pt-BR
2012-03-03 10:14:13 ----D---- C:\Windows\system32\pl-PL
2012-03-03 10:14:12 ----D---- C:\Windows\system32\nl-NL
2012-03-03 10:14:12 ----D---- C:\Windows\system32\nb-NO
2012-03-03 10:14:12 ----D---- C:\Windows\system32\lv-LV
2012-03-03 10:14:12 ----D---- C:\Windows\system32\lt-LT
2012-03-03 10:14:12 ----D---- C:\Windows\system32\ko-KR
2012-03-03 10:14:12 ----D---- C:\Windows\system32\ja-JP
2012-03-03 10:14:12 ----D---- C:\Windows\system32\it-IT
2012-03-03 10:14:12 ----D---- C:\Windows\system32\hu-HU
2012-03-03 10:14:11 ----D---- C:\Windows\system32\hr-HR
2012-03-03 10:14:11 ----D---- C:\Windows\system32\he-IL
2012-03-03 10:14:11 ----D---- C:\Windows\system32\fr-FR
2012-03-03 10:14:11 ----D---- C:\Windows\system32\fi-FI
2012-03-03 10:14:11 ----D---- C:\Windows\system32\et-EE
2012-03-03 10:14:11 ----D---- C:\Windows\system32\es-ES
2012-03-03 10:14:11 ----D---- C:\Windows\system32\en-US
2012-03-03 10:14:10 ----D---- C:\Windows\system32\el-GR
2012-03-03 10:14:10 ----D---- C:\Windows\system32\de-DE
2012-03-03 10:14:10 ----D---- C:\Windows\system32\da-DK
2012-03-03 10:14:10 ----D---- C:\Windows\system32\cs-CZ
2012-03-03 10:14:10 ----D---- C:\Windows\system32\bg-BG
2012-03-03 10:14:10 ----D---- C:\Windows\system32\ar-SA
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-08-07 330264]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKsl749e71cc;MpKsl749e71cc; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{403019BB-8AA5-469C-9CFD-157821E26B48}\MpKsl749e71cc.sys [2012-03-08 29904]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2009-08-21 212528]
R3 BCM43XX;Ovladač síťového adaptéru Broadcom 802.11; C:\Windows\system32\DRIVERS\bcmwl6.sys [2009-08-29 2661368]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-08-13 5946368]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-07-09 122880]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 185344]
R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt.sys [2009-08-13 409088]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-08 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 18344]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x32.sys [2009-07-13 347264]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-07-17 171008]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 84992]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S4 RsFx0151;RsFx0151 Driver; C:\Windows\system32\DRIVERS\RsFx0151.sys [2011-06-17 240736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\aestsrv.exe [2009-03-02 81920]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-30 582944]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2011-06-17 43040096]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2009-01-21 247152]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2010-04-03 267616]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2010-04-03 97632]
R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\STacSV.exe [2009-08-13 221266]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2009-04-30 229944]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 44896]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-06-17 370016]
-----------------EOF-----------------