Enormní vytěžování procesoru
Napsal: 15 bře 2010 12:49
Dobrý den.
Mám týden nový HP 6530b.
Už v průběhu víkendu "to" začalo zlobit a dnes v práci "to" zlobí těžce už od rána.
"to" = enormní vytížení procesoru 70-100%
kolem 20-30% mají servoces.exe a 2 až 3 svchost soubory.
Nerad bych si "odpálil" nový NB, umíte poradit?
Log z RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by LiborP at 2010-03-15 11:48:47
Microsoft Windows 7 Professional Service Pack 3
System drive C: has 220 GB (77%) free of 288 GB
Total RAM: 1976 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:49, on 15.3.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\UnH Solutions\Easy Go Back\EasyGoBack.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
c:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\windows\system32\conhost.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\hotkeyp2\hotkeyp.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\windows\system32\taskmgr.exe
C:\windows\system32\mmc.exe
C:\Users\LiborP\Downloads\RSIT.exe
C:\Program Files\trend micro\LiborP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [acevents] "c:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [IFXSPMGT] "c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [EasyGoBack] "C:\Program Files\UnH Solutions\Easy Go Back\EasyGoBack.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll
O20 - Winlogon Notify: DeviceNP - C:\windows\SYSTEM32\DeviceNP.dll
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - c:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AuthenTec Fingerprint Service (ATService) - AuthenTec, Inc. - c:\Program Files\Fingerprint Sensor\AtService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop Inc - C:\Users\LiborP\AppData\Local\CrossLoop\CrossLoopService.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - c:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: uvnc_service - UltraVNC - C:\Users\LiborP\AppData\Local\CrossLoop\winvnc.exe
--
End of file - 13184 bytes
======Scheduled tasks folder======
C:\windows\tasks\HPCeeScheduleForLiborP.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-07-06 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
Credential Manager for HP ProtectTools - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll [2009-07-23 98576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-07-27 288312]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-17 186904]
"acevents"=c:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-04 153640]
""= []
"accrdsub"=c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-04 400936]
"PTHOSTTR"=c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2009-07-30 354360]
"CognizanceTS"=c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [2009-07-23 24848]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-06-18 563736]
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-07-23 498744]
"IFXSPMGT"=c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-05-25 1107232]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-07-06 11227136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-30 1545512]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2009-08-03 141848]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2009-08-03 174104]
"Persistence"=C:\windows\system32\igfxpers.exe [2009-08-03 151064]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2009-07-16 1668664]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"EasyGoBack"=C:\Program Files\UnH Solutions\Easy Go Back\EasyGoBack.exe [2005-04-27 532480]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\LiborP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="c:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-06-30 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2009-07-28 216576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-15 11:47:40 ----D---- C:\Program Files\trend micro
2010-03-15 11:47:39 ----D---- C:\rsit
2010-03-15 10:20:21 ----D---- C:\ProgramData\LightScribe
2010-03-12 12:27:23 ----D---- C:\Program Files\UnH Solutions
2010-03-12 12:06:59 ----A---- C:\windows\system32\msv1_0.dll
2010-03-12 12:05:37 ----A---- C:\windows\system32\MRT.exe
2010-03-12 10:45:50 ----D---- C:\_entertainment
2010-03-11 03:32:09 ----SHD---- C:\Config.Msi
2010-03-11 03:17:19 ----A---- C:\windows\system32\browserchoice.exe
2010-03-11 03:10:27 ----D---- C:\Program Files\MSXML 4.0
2010-03-11 02:38:16 ----D---- C:\Users\LiborP\AppData\Roaming\dvdcss
2010-03-10 08:06:38 ----D---- C:\data
2010-03-10 07:56:55 ----D---- C:\Program Files\OpenVPN
2010-03-10 05:57:15 ----D---- C:\Users\LiborP\AppData\Roaming\OpenOffice.org
2010-03-10 05:48:13 ----A---- C:\windows\explorer.exe
2010-03-10 05:48:12 ----A---- C:\windows\system32\winlogon.exe
2010-03-10 05:48:07 ----A---- C:\windows\system32\msasn1.dll
2010-03-10 05:48:01 ----A---- C:\windows\system32\wmp.dll
2010-03-10 05:48:00 ----A---- C:\windows\system32\CertEnroll.dll
2010-03-10 05:47:59 ----A---- C:\windows\system32\winresume.exe
2010-03-10 05:47:59 ----A---- C:\windows\system32\winload.exe
2010-03-10 05:47:57 ----A---- C:\windows\system32\wmploc.DLL
2010-03-10 05:47:53 ----A---- C:\windows\system32\jscript.dll
2010-03-10 05:47:42 ----A---- C:\windows\system32\t2embed.dll
2010-03-10 05:47:42 ----A---- C:\windows\system32\fontsub.dll
2010-03-10 05:47:42 ----A---- C:\windows\system32\atmfd.dll
2010-03-10 05:47:34 ----N---- C:\windows\system32\MpSigStub.exe
2010-03-10 05:47:34 ----A---- C:\windows\system32\mshtml.dll
2010-03-10 05:47:33 ----A---- C:\windows\system32\ieframe.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\wininet.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\urlmon.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\msfeedsbs.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\iedkcs32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\tsbyuv.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\quartz.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\msyuv.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\msvidc32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\msrle32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\mciavi32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\iyuv_32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\avifil32.dll
2010-03-10 05:47:17 ----A---- C:\windows\system32\ntoskrnl.exe
2010-03-10 05:47:17 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-03-10 05:47:17 ----A---- C:\windows\system32\kernel32.dll
2010-03-10 05:47:17 ----A---- C:\windows\system32\apphelp.dll
2010-03-10 05:47:15 ----A---- C:\windows\system32\tzres.dll
2010-03-10 05:09:27 ----D---- C:\__eBRÁNA
2010-03-10 05:09:24 ----A---- C:\windows\myClean.bat
2010-03-09 23:20:36 ----D---- C:\windows\SoftwareDistribution
2010-03-09 23:19:45 ----D---- C:\windows\system32\Lang
2010-03-09 23:19:44 ----A---- C:\windows\system32\igxpun.exe
2010-03-09 23:19:36 ----D---- C:\Program Files\Synaptics
2010-03-09 23:18:14 ----D---- C:\windows\Prefetch
2010-03-09 20:36:16 ----D---- C:\Program Files\Vypínač na dobrou noc
2010-03-09 20:21:54 ----D---- C:\hotkeyp2
2010-03-09 20:18:58 ----D---- C:\Users\LiborP\AppData\Roaming\vlc
2010-03-09 20:18:28 ----D---- C:\Program Files\VideoLAN
2010-03-09 20:10:28 ----D---- C:\Program Files\OpenOffice.org 3
2010-03-09 18:52:52 ----A---- C:\windows\system32\msonpmon.dll
2010-03-09 18:51:55 ----D---- C:\Program Files\Microsoft Works
2010-03-09 18:50:51 ----D---- C:\Program Files\Microsoft Visual Studio
2010-03-09 18:50:51 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-09 18:50:20 ----D---- C:\Program Files\Microsoft.NET
2010-03-09 18:48:54 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-03-09 18:48:16 ----D---- C:\Program Files\Microsoft Office
2010-03-09 18:47:38 ----RHD---- C:\MSOCache
2010-03-09 18:41:38 ----D---- C:\Users\LiborP\AppData\Roaming\Mozilla
2010-03-09 18:41:29 ----D---- C:\Program Files\Mozilla Firefox
2010-03-09 18:39:25 ----D---- C:\Users\LiborP\AppData\Roaming\skypePM
2010-03-09 18:36:24 ----D---- C:\Users\LiborP\AppData\Roaming\Skype
2010-03-09 18:35:57 ----D---- C:\Program Files\Common Files\Skype
2010-03-09 18:35:56 ----RD---- C:\Program Files\Skype
2010-03-09 18:35:51 ----D---- C:\ProgramData\Skype
2010-03-09 17:50:37 ----D---- C:\ProgramData\Avira
2010-03-09 17:50:37 ----D---- C:\Program Files\Avira
2010-03-09 17:45:28 ----D---- C:\totalcmd
2010-03-09 16:46:56 ----D---- C:\Users\LiborP\AppData\Roaming\Macromedia
2010-03-09 16:46:52 ----D---- C:\Users\LiborP\AppData\Roaming\Adobe
2010-03-09 16:45:58 ----D---- C:\Users\LiborP\AppData\Roaming\Hewlett-Packard
2010-03-09 16:45:20 ----D---- C:\Users\LiborP\AppData\Roaming\Identities
2010-03-09 16:41:25 ----D---- C:\Users\LiborP\AppData\Roaming\HP TCS
2010-03-09 16:38:05 ----D---- C:\Program Files\Microsoft
2010-03-09 16:37:45 ----D---- C:\Program Files\Windows Live SkyDrive
2010-03-09 16:37:29 ----D---- C:\Program Files\Windows Live
2010-03-09 16:36:36 ----D---- C:\Program Files\Common Files\Windows Live
2010-03-09 16:36:13 ----D---- C:\windows\HPQ
2010-03-09 16:36:00 ----N---- C:\windows\system32\agrsmdel.exe
2010-03-09 16:36:00 ----N---- C:\windows\system32\agrsco64.dll
2010-03-09 16:35:58 ----D---- C:\Program Files\LSI SoftModem
2010-03-09 16:35:48 ----D---- C:\windows\Options
2010-03-09 16:35:43 ----D---- C:\Program Files\HP Webcam Application
2010-03-09 16:35:17 ----A---- C:\windows\system32\rsnp2uvc.dll
2010-03-09 16:35:17 ----A---- C:\windows\snuvcdsm.exe
2010-03-09 16:35:16 ----D---- C:\Program Files\Common Files\SNP2UVC
2010-03-09 16:35:16 ----A---- C:\windows\system32\csnp2uvc.dll
2010-03-09 16:35:16 ----A---- C:\windows\snp2uvc.ini
2010-03-09 16:34:28 ----D---- C:\ProgramData\SonicFocus
2010-03-09 16:34:28 ----D---- C:\Program Files\Analog Devices
2010-03-09 16:33:50 ----D---- C:\Users\LiborP\AppData\Roaming\InstallShield
2010-03-09 16:32:50 ----D---- C:\Program Files\WIDCOMM
2010-03-09 16:31:21 ----D---- C:\Users\LiborP\AppData\Roaming\hpqLog
2010-03-09 16:29:41 ----A---- C:\windows\system32\TVWizudlg.exe
2010-03-09 16:29:41 ----A---- C:\windows\system32\igfxtvcx.dll
2010-03-09 16:29:39 ----D---- C:\Users\LiborP\AppData\Roaming\Infineon
2010-03-09 16:29:22 ----SD---- C:\Users\LiborP\AppData\Roaming\Microsoft
======List of files/folders modified in the last 1 months======
2010-03-15 11:48:47 ----D---- C:\windows\Temp
2010-03-15 11:47:40 ----RD---- C:\Program Files
2010-03-15 10:41:21 ----SD---- C:\ProgramData\Microsoft
2010-03-15 10:20:21 ----HD---- C:\ProgramData
2010-03-14 20:53:41 ----D---- C:\windows\system32\config
2010-03-14 12:26:42 ----D---- C:\windows\System32
2010-03-14 12:26:42 ----D---- C:\windows\inf
2010-03-14 12:26:42 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-03-14 12:23:33 ----D---- C:\windows\system32\wdi
2010-03-14 12:22:38 ----D---- C:\ProgramData\hpqLog
2010-03-14 12:15:58 ----D---- C:\windows\winsxs
2010-03-14 12:05:46 ----SHD---- C:\windows\Installer
2010-03-14 12:05:25 ----D---- C:\ProgramData\Microsoft Help
2010-03-14 12:05:19 ----RSD---- C:\windows\assembly
2010-03-14 12:03:49 ----RSD---- C:\windows\Fonts
2010-03-14 12:03:44 ----D---- C:\Program Files\Common Files\microsoft shared
2010-03-14 12:01:53 ----A---- C:\windows\win.ini
2010-03-14 12:00:25 ----SHD---- C:\System Volume Information
2010-03-12 12:07:01 ----D---- C:\windows\system32\catroot
2010-03-12 12:05:41 ----D---- C:\windows\debug
2010-03-11 11:38:12 ----D---- C:\windows\rescache
2010-03-11 07:45:26 ----D---- C:\windows\system32\catroot2
2010-03-11 06:50:31 ----D---- C:\windows\Microsoft.NET
2010-03-11 05:18:26 ----D---- C:\windows\system32\drivers
2010-03-11 05:18:26 ----D---- C:\windows\system32\Boot
2010-03-11 05:18:26 ----D---- C:\windows\ehome
2010-03-11 05:18:26 ----D---- C:\Windows
2010-03-11 05:18:26 ----D---- C:\Program Files\Windows Media Player
2010-03-11 05:18:24 ----D---- C:\Program Files\Internet Explorer
2010-03-11 05:18:23 ----D---- C:\windows\system32\cs-CZ
2010-03-11 05:18:20 ----D---- C:\windows\servicing
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Sidebar
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Photo Viewer
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Mail
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Journal
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Defender
2010-03-11 05:18:20 ----D---- C:\Program Files\Common Files\System
2010-03-11 05:18:19 ----D---- C:\windows\PolicyDefinitions
2010-03-11 05:18:19 ----D---- C:\windows\en-US
2010-03-11 05:18:18 ----D---- C:\windows\system32\winrm
2010-03-11 05:18:18 ----D---- C:\windows\system32\sysprep
2010-03-11 05:18:18 ----D---- C:\windows\system32\slmgr
2010-03-11 05:18:18 ----D---- C:\windows\system32\oobe
2010-03-11 05:18:18 ----D---- C:\windows\system32\migwiz
2010-03-11 05:18:18 ----D---- C:\windows\system32\en
2010-03-11 05:18:17 ----D---- C:\windows\system32\en-US
2010-03-11 05:18:13 ----D---- C:\windows\system32\sl-SI
2010-03-11 05:18:10 ----D---- C:\windows\system32\WCN
2010-03-11 05:18:09 ----D---- C:\windows\system32\DriverStore
2010-03-11 05:18:09 ----D---- C:\windows\system32\Dism
2010-03-11 05:18:08 ----D---- C:\windows\system32\wbem
2010-03-11 05:18:08 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-03-11 05:17:58 ----D---- C:\windows\system32\sk-SK
2010-03-11 05:17:49 ----D---- C:\windows\system32\ro-RO
2010-03-11 05:17:39 ----D---- C:\windows\system32\lv-LV
2010-03-11 05:17:29 ----D---- C:\windows\system32\lt-LT
2010-03-11 05:17:19 ----D---- C:\windows\system32\hr-HR
2010-03-11 05:17:08 ----D---- C:\windows\system32\et-EE
2010-03-11 05:16:59 ----D---- C:\windows\system32\bg-BG
2010-03-11 05:16:45 ----D---- C:\Program Files\DVD Maker
2010-03-11 05:16:38 ----D---- C:\windows\Speech
2010-03-10 17:51:54 ----D---- C:\windows\Logs
2010-03-10 17:46:25 ----D---- C:\windows\system32\Tasks
2010-03-10 17:46:24 ----D---- C:\windows\Tasks
2010-03-09 19:37:42 ----D---- C:\windows\system32\LogFiles
2010-03-09 18:55:16 ----D---- C:\ProgramData\PDFC
2010-03-09 18:51:41 ----D---- C:\Program Files\MSBuild
2010-03-09 18:50:51 ----D---- C:\Program Files\Common Files
2010-03-09 18:50:47 ----D---- C:\windows\ShellNew
2010-03-09 16:45:17 ----SHD---- C:\$Recycle.Bin
2010-03-09 16:43:49 ----D---- C:\ProgramData\Hewlett-Packard
2010-03-09 16:40:56 ----D---- C:\swsetup
2010-03-09 16:40:56 ----AHD---- C:\SYSTEM.SAV
2010-03-09 16:35:42 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-09 16:35:23 ----D---- C:\windows\twain_32
2010-03-09 16:33:39 ----D---- C:\Program Files\Hewlett-Packard
2010-03-09 16:31:46 ----D---- C:\windows\Panther
2010-03-09 16:29:39 ----D---- C:\Program Files\Intel
2010-03-09 16:29:21 ----RD---- C:\Users
2010-03-09 16:27:14 ----D---- C:\windows\system32\restore
Mám týden nový HP 6530b.
Už v průběhu víkendu "to" začalo zlobit a dnes v práci "to" zlobí těžce už od rána.
"to" = enormní vytížení procesoru 70-100%
kolem 20-30% mají servoces.exe a 2 až 3 svchost soubory.
Nerad bych si "odpálil" nový NB, umíte poradit?
Log z RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by LiborP at 2010-03-15 11:48:47
Microsoft Windows 7 Professional Service Pack 3
System drive C: has 220 GB (77%) free of 288 GB
Total RAM: 1976 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:49, on 15.3.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\windows\system32\taskhost.exe
c:\Program Files\Hewlett-Packard\IAM\Bin\AsGHost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\windows\system32\igfxsrvc.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\UnH Solutions\Easy Go Back\EasyGoBack.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
c:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\windows\system32\conhost.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\hotkeyp2\hotkeyp.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\windows\system32\taskmgr.exe
C:\windows\system32\mmc.exe
C:\Users\LiborP\Downloads\RSIT.exe
C:\Program Files\trend micro\LiborP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [acevents] "c:\Program Files\ActivIdentity\ActivClient\acevents.exe"
O4 - HKLM\..\Run: [accrdsub] "c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [IFXSPMGT] "c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
O4 - HKLM\..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe /tray
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [EasyGoBack] "C:\Program Files\UnH Solutions\Easy Go Back\EasyGoBack.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll
O20 - Winlogon Notify: DeviceNP - C:\windows\SYSTEM32\DeviceNP.dll
O23 - Service: ActivIdentity Shared Store Service (ac.sharedstore) - ActivIdentity - c:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\windows\system32\AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: AuthenTec Fingerprint Service (ATService) - AuthenTec, Inc. - c:\Program Files\Fingerprint Sensor\AtService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop Inc - C:\Users\LiborP\AppData\Local\CrossLoop\CrossLoopService.exe
O23 - Service: HP ProtectTools Device Locking / Auditing (FLCDLOCK) - Hewlett-Packard Ltd - c:\Windows\system32\flcdlock.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - McAfee, Inc. - c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard - C:\windows\system32\Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - c:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: uvnc_service - UltraVNC - C:\Users\LiborP\AppData\Local\CrossLoop\winvnc.exe
--
End of file - 13184 bytes
======Scheduled tasks folder======
C:\windows\tasks\HPCeeScheduleForLiborP.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3134413B-49B4-425C-98A5-893C1F195601}]
File Sanitizer for HP ProtectTools - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll [2009-07-06 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DF21F1DB-80C6-11D3-9483-B03D0EC10000}]
Credential Manager for HP ProtectTools - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll [2009-07-23 98576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0BF43445-2F28-4351-9252-17FE6E806AA0}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2009-07-27 288312]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-17 186904]
"acevents"=c:\Program Files\ActivIdentity\ActivClient\acevents.exe [2009-06-04 153640]
""= []
"accrdsub"=c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe [2009-06-04 400936]
"PTHOSTTR"=c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE [2009-07-30 354360]
"CognizanceTS"=c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll [2009-07-23 24848]
"PDF Complete"=C:\Program Files\PDF Complete\pdfsty.exe [2009-06-18 563736]
"WirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-07-23 498744]
"IFXSPMGT"=c:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe [2009-05-25 1107232]
"File Sanitizer"=C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe [2009-07-06 11227136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-07-30 1545512]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2009-08-03 141848]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2009-08-03 174104]
"Persistence"=C:\windows\system32\igfxpers.exe [2009-08-03 151064]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2009-05-18 1314816]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\soundmax.exe [2009-05-18 3866624]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2009-07-16 1668664]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-06-17 2363392]
"EasyGoBack"=C:\Program Files\UnH Solutions\Easy Go Back\EasyGoBack.exe [2005-04-27 532480]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\LiborP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.2.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="c:\PROGRA~1\HEWLET~1\IAM\bin\APSHook.dll "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DeviceNP]
C:\windows\system32\DeviceNP.dll [2009-06-30 75320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2009-07-28 216576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ASWLNPkg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2010-03-15 11:47:40 ----D---- C:\Program Files\trend micro
2010-03-15 11:47:39 ----D---- C:\rsit
2010-03-15 10:20:21 ----D---- C:\ProgramData\LightScribe
2010-03-12 12:27:23 ----D---- C:\Program Files\UnH Solutions
2010-03-12 12:06:59 ----A---- C:\windows\system32\msv1_0.dll
2010-03-12 12:05:37 ----A---- C:\windows\system32\MRT.exe
2010-03-12 10:45:50 ----D---- C:\_entertainment
2010-03-11 03:32:09 ----SHD---- C:\Config.Msi
2010-03-11 03:17:19 ----A---- C:\windows\system32\browserchoice.exe
2010-03-11 03:10:27 ----D---- C:\Program Files\MSXML 4.0
2010-03-11 02:38:16 ----D---- C:\Users\LiborP\AppData\Roaming\dvdcss
2010-03-10 08:06:38 ----D---- C:\data
2010-03-10 07:56:55 ----D---- C:\Program Files\OpenVPN
2010-03-10 05:57:15 ----D---- C:\Users\LiborP\AppData\Roaming\OpenOffice.org
2010-03-10 05:48:13 ----A---- C:\windows\explorer.exe
2010-03-10 05:48:12 ----A---- C:\windows\system32\winlogon.exe
2010-03-10 05:48:07 ----A---- C:\windows\system32\msasn1.dll
2010-03-10 05:48:01 ----A---- C:\windows\system32\wmp.dll
2010-03-10 05:48:00 ----A---- C:\windows\system32\CertEnroll.dll
2010-03-10 05:47:59 ----A---- C:\windows\system32\winresume.exe
2010-03-10 05:47:59 ----A---- C:\windows\system32\winload.exe
2010-03-10 05:47:57 ----A---- C:\windows\system32\wmploc.DLL
2010-03-10 05:47:53 ----A---- C:\windows\system32\jscript.dll
2010-03-10 05:47:42 ----A---- C:\windows\system32\t2embed.dll
2010-03-10 05:47:42 ----A---- C:\windows\system32\fontsub.dll
2010-03-10 05:47:42 ----A---- C:\windows\system32\atmfd.dll
2010-03-10 05:47:34 ----N---- C:\windows\system32\MpSigStub.exe
2010-03-10 05:47:34 ----A---- C:\windows\system32\mshtml.dll
2010-03-10 05:47:33 ----A---- C:\windows\system32\ieframe.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\wininet.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\urlmon.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\msfeedsbs.dll
2010-03-10 05:47:31 ----A---- C:\windows\system32\iedkcs32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\tsbyuv.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\quartz.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\msyuv.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\msvidc32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\msrle32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\mciavi32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\iyuv_32.dll
2010-03-10 05:47:18 ----A---- C:\windows\system32\avifil32.dll
2010-03-10 05:47:17 ----A---- C:\windows\system32\ntoskrnl.exe
2010-03-10 05:47:17 ----A---- C:\windows\system32\ntkrnlpa.exe
2010-03-10 05:47:17 ----A---- C:\windows\system32\kernel32.dll
2010-03-10 05:47:17 ----A---- C:\windows\system32\apphelp.dll
2010-03-10 05:47:15 ----A---- C:\windows\system32\tzres.dll
2010-03-10 05:09:27 ----D---- C:\__eBRÁNA
2010-03-10 05:09:24 ----A---- C:\windows\myClean.bat
2010-03-09 23:20:36 ----D---- C:\windows\SoftwareDistribution
2010-03-09 23:19:45 ----D---- C:\windows\system32\Lang
2010-03-09 23:19:44 ----A---- C:\windows\system32\igxpun.exe
2010-03-09 23:19:36 ----D---- C:\Program Files\Synaptics
2010-03-09 23:18:14 ----D---- C:\windows\Prefetch
2010-03-09 20:36:16 ----D---- C:\Program Files\Vypínač na dobrou noc
2010-03-09 20:21:54 ----D---- C:\hotkeyp2
2010-03-09 20:18:58 ----D---- C:\Users\LiborP\AppData\Roaming\vlc
2010-03-09 20:18:28 ----D---- C:\Program Files\VideoLAN
2010-03-09 20:10:28 ----D---- C:\Program Files\OpenOffice.org 3
2010-03-09 18:52:52 ----A---- C:\windows\system32\msonpmon.dll
2010-03-09 18:51:55 ----D---- C:\Program Files\Microsoft Works
2010-03-09 18:50:51 ----D---- C:\Program Files\Microsoft Visual Studio
2010-03-09 18:50:51 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-09 18:50:20 ----D---- C:\Program Files\Microsoft.NET
2010-03-09 18:48:54 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-03-09 18:48:16 ----D---- C:\Program Files\Microsoft Office
2010-03-09 18:47:38 ----RHD---- C:\MSOCache
2010-03-09 18:41:38 ----D---- C:\Users\LiborP\AppData\Roaming\Mozilla
2010-03-09 18:41:29 ----D---- C:\Program Files\Mozilla Firefox
2010-03-09 18:39:25 ----D---- C:\Users\LiborP\AppData\Roaming\skypePM
2010-03-09 18:36:24 ----D---- C:\Users\LiborP\AppData\Roaming\Skype
2010-03-09 18:35:57 ----D---- C:\Program Files\Common Files\Skype
2010-03-09 18:35:56 ----RD---- C:\Program Files\Skype
2010-03-09 18:35:51 ----D---- C:\ProgramData\Skype
2010-03-09 17:50:37 ----D---- C:\ProgramData\Avira
2010-03-09 17:50:37 ----D---- C:\Program Files\Avira
2010-03-09 17:45:28 ----D---- C:\totalcmd
2010-03-09 16:46:56 ----D---- C:\Users\LiborP\AppData\Roaming\Macromedia
2010-03-09 16:46:52 ----D---- C:\Users\LiborP\AppData\Roaming\Adobe
2010-03-09 16:45:58 ----D---- C:\Users\LiborP\AppData\Roaming\Hewlett-Packard
2010-03-09 16:45:20 ----D---- C:\Users\LiborP\AppData\Roaming\Identities
2010-03-09 16:41:25 ----D---- C:\Users\LiborP\AppData\Roaming\HP TCS
2010-03-09 16:38:05 ----D---- C:\Program Files\Microsoft
2010-03-09 16:37:45 ----D---- C:\Program Files\Windows Live SkyDrive
2010-03-09 16:37:29 ----D---- C:\Program Files\Windows Live
2010-03-09 16:36:36 ----D---- C:\Program Files\Common Files\Windows Live
2010-03-09 16:36:13 ----D---- C:\windows\HPQ
2010-03-09 16:36:00 ----N---- C:\windows\system32\agrsmdel.exe
2010-03-09 16:36:00 ----N---- C:\windows\system32\agrsco64.dll
2010-03-09 16:35:58 ----D---- C:\Program Files\LSI SoftModem
2010-03-09 16:35:48 ----D---- C:\windows\Options
2010-03-09 16:35:43 ----D---- C:\Program Files\HP Webcam Application
2010-03-09 16:35:17 ----A---- C:\windows\system32\rsnp2uvc.dll
2010-03-09 16:35:17 ----A---- C:\windows\snuvcdsm.exe
2010-03-09 16:35:16 ----D---- C:\Program Files\Common Files\SNP2UVC
2010-03-09 16:35:16 ----A---- C:\windows\system32\csnp2uvc.dll
2010-03-09 16:35:16 ----A---- C:\windows\snp2uvc.ini
2010-03-09 16:34:28 ----D---- C:\ProgramData\SonicFocus
2010-03-09 16:34:28 ----D---- C:\Program Files\Analog Devices
2010-03-09 16:33:50 ----D---- C:\Users\LiborP\AppData\Roaming\InstallShield
2010-03-09 16:32:50 ----D---- C:\Program Files\WIDCOMM
2010-03-09 16:31:21 ----D---- C:\Users\LiborP\AppData\Roaming\hpqLog
2010-03-09 16:29:41 ----A---- C:\windows\system32\TVWizudlg.exe
2010-03-09 16:29:41 ----A---- C:\windows\system32\igfxtvcx.dll
2010-03-09 16:29:39 ----D---- C:\Users\LiborP\AppData\Roaming\Infineon
2010-03-09 16:29:22 ----SD---- C:\Users\LiborP\AppData\Roaming\Microsoft
======List of files/folders modified in the last 1 months======
2010-03-15 11:48:47 ----D---- C:\windows\Temp
2010-03-15 11:47:40 ----RD---- C:\Program Files
2010-03-15 10:41:21 ----SD---- C:\ProgramData\Microsoft
2010-03-15 10:20:21 ----HD---- C:\ProgramData
2010-03-14 20:53:41 ----D---- C:\windows\system32\config
2010-03-14 12:26:42 ----D---- C:\windows\System32
2010-03-14 12:26:42 ----D---- C:\windows\inf
2010-03-14 12:26:42 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-03-14 12:23:33 ----D---- C:\windows\system32\wdi
2010-03-14 12:22:38 ----D---- C:\ProgramData\hpqLog
2010-03-14 12:15:58 ----D---- C:\windows\winsxs
2010-03-14 12:05:46 ----SHD---- C:\windows\Installer
2010-03-14 12:05:25 ----D---- C:\ProgramData\Microsoft Help
2010-03-14 12:05:19 ----RSD---- C:\windows\assembly
2010-03-14 12:03:49 ----RSD---- C:\windows\Fonts
2010-03-14 12:03:44 ----D---- C:\Program Files\Common Files\microsoft shared
2010-03-14 12:01:53 ----A---- C:\windows\win.ini
2010-03-14 12:00:25 ----SHD---- C:\System Volume Information
2010-03-12 12:07:01 ----D---- C:\windows\system32\catroot
2010-03-12 12:05:41 ----D---- C:\windows\debug
2010-03-11 11:38:12 ----D---- C:\windows\rescache
2010-03-11 07:45:26 ----D---- C:\windows\system32\catroot2
2010-03-11 06:50:31 ----D---- C:\windows\Microsoft.NET
2010-03-11 05:18:26 ----D---- C:\windows\system32\drivers
2010-03-11 05:18:26 ----D---- C:\windows\system32\Boot
2010-03-11 05:18:26 ----D---- C:\windows\ehome
2010-03-11 05:18:26 ----D---- C:\Windows
2010-03-11 05:18:26 ----D---- C:\Program Files\Windows Media Player
2010-03-11 05:18:24 ----D---- C:\Program Files\Internet Explorer
2010-03-11 05:18:23 ----D---- C:\windows\system32\cs-CZ
2010-03-11 05:18:20 ----D---- C:\windows\servicing
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Sidebar
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Photo Viewer
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Mail
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Journal
2010-03-11 05:18:20 ----D---- C:\Program Files\Windows Defender
2010-03-11 05:18:20 ----D---- C:\Program Files\Common Files\System
2010-03-11 05:18:19 ----D---- C:\windows\PolicyDefinitions
2010-03-11 05:18:19 ----D---- C:\windows\en-US
2010-03-11 05:18:18 ----D---- C:\windows\system32\winrm
2010-03-11 05:18:18 ----D---- C:\windows\system32\sysprep
2010-03-11 05:18:18 ----D---- C:\windows\system32\slmgr
2010-03-11 05:18:18 ----D---- C:\windows\system32\oobe
2010-03-11 05:18:18 ----D---- C:\windows\system32\migwiz
2010-03-11 05:18:18 ----D---- C:\windows\system32\en
2010-03-11 05:18:17 ----D---- C:\windows\system32\en-US
2010-03-11 05:18:13 ----D---- C:\windows\system32\sl-SI
2010-03-11 05:18:10 ----D---- C:\windows\system32\WCN
2010-03-11 05:18:09 ----D---- C:\windows\system32\DriverStore
2010-03-11 05:18:09 ----D---- C:\windows\system32\Dism
2010-03-11 05:18:08 ----D---- C:\windows\system32\wbem
2010-03-11 05:18:08 ----D---- C:\windows\system32\Printing_Admin_Scripts
2010-03-11 05:17:58 ----D---- C:\windows\system32\sk-SK
2010-03-11 05:17:49 ----D---- C:\windows\system32\ro-RO
2010-03-11 05:17:39 ----D---- C:\windows\system32\lv-LV
2010-03-11 05:17:29 ----D---- C:\windows\system32\lt-LT
2010-03-11 05:17:19 ----D---- C:\windows\system32\hr-HR
2010-03-11 05:17:08 ----D---- C:\windows\system32\et-EE
2010-03-11 05:16:59 ----D---- C:\windows\system32\bg-BG
2010-03-11 05:16:45 ----D---- C:\Program Files\DVD Maker
2010-03-11 05:16:38 ----D---- C:\windows\Speech
2010-03-10 17:51:54 ----D---- C:\windows\Logs
2010-03-10 17:46:25 ----D---- C:\windows\system32\Tasks
2010-03-10 17:46:24 ----D---- C:\windows\Tasks
2010-03-09 19:37:42 ----D---- C:\windows\system32\LogFiles
2010-03-09 18:55:16 ----D---- C:\ProgramData\PDFC
2010-03-09 18:51:41 ----D---- C:\Program Files\MSBuild
2010-03-09 18:50:51 ----D---- C:\Program Files\Common Files
2010-03-09 18:50:47 ----D---- C:\windows\ShellNew
2010-03-09 16:45:17 ----SHD---- C:\$Recycle.Bin
2010-03-09 16:43:49 ----D---- C:\ProgramData\Hewlett-Packard
2010-03-09 16:40:56 ----D---- C:\swsetup
2010-03-09 16:40:56 ----AHD---- C:\SYSTEM.SAV
2010-03-09 16:35:42 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-09 16:35:23 ----D---- C:\windows\twain_32
2010-03-09 16:33:39 ----D---- C:\Program Files\Hewlett-Packard
2010-03-09 16:31:46 ----D---- C:\windows\Panther
2010-03-09 16:29:39 ----D---- C:\Program Files\Intel
2010-03-09 16:29:21 ----RD---- C:\Users
2010-03-09 16:27:14 ----D---- C:\windows\system32\restore