Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu a pomoc s Avirou

Moderátoři: james008, JaRon, Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zamčeno
Zpráva
Autor
Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Prosím o kontrolu logu a pomoc s Avirou

#1 Příspěvek od Moody.01 »

Dobrý den!
S notebookem nemám žádný viditelný problém, přesto budu ráda, když někdo log skontroluje, zda je opravdu všechno v pořádku.

Přešla jsem ze zkušebního Nortonu na Aviru. Ta mi ale často hlásí varování: "In accordance with security guidelines, the Administrator has blocked access to file 'Q:\AUTORUN.INF'."
Jedná se o druhý oddíl (Q), na kterém je z výroby vytvořena záloha systému určena k vypálení na DVD. Ta záloha není fukční, i podle technika je tam problém se zaváděcím souborem (takže asi soubor autorun.inf ?). Pokud celý oddíl proskenuju Avirou, tak tam není žádná infekce.
Chci se tedy zeptat, jak můžu zařadit soubor do výjimky, případně co jiného s tím mám dělat?

Děkuji moc za pomoc :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by H at 2012-10-07 11:57:40
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 405 GB (89%) free of 457 GB
Total RAM: 3685 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:57:47, on 7.10.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Program Files\Lenovo Fingerprint Reader\x86\BioMonitor.exe
C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Opera\Opera.exe
C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe
C:\Program Files\trend micro\H.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: TrueSuite Browser Helper Object - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: IEPlugin - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [Dolby Advanced Audio v2] "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [Fastboot] C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
O4 - HKLM\..\Run: [Intel AppUp(SM) center] "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
O4 - HKLM\..\Run: [IntelSBA] C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\SBALaunchDelay.exe "C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\UI\IntelSmallBusinessAdvantage.exe -minimized" 60
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [TrayStatus] "C:\Program Files (x86)\TrayStatus\TrayStatus.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7M - {781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - C:\Program Files (x86)\ICQ7M\ICQ.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Device Monitor - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth Media Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
O23 - Service: Bluetooth OBEX Service - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service (BTHSSecurityMgr) - Intel(R) Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FastbootService - Lenovo - C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: TrueSuiteService (FPLService) - AuthenTec, Inc - C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HyperW7 Service (HyperW7Svc) - Lenovo Group Limited - C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe
O23 - Service: Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: ThinkVantage Virtual Camera Controller (LENOVO.TVTVCAM) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIPAppService - Symantec Corporation - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 15462 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe"
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-6aefb1c4-26f4-408a-b395-e2d618e1c94c -SystemEventPortName:HostProcess-ad972a15-630e-4d5c-8a5c-04685d31aac4 -IoCancelEventPortName:HostProcess-baae0fa5-cfd9-4bd7-b6c3-05acf7aea776 -NonStateChangingEventPortName:HostProcess-c59193bc-395c-4a78-9157-1a66902c8401 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a5d27266-3891-4fa4-9322-0fd3164a5721
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 20904912
\??\C:\Windows\system32\conhost.exe "814409174-208387761674533869592549522-174419929613928345841045316279-297919988
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k WbioSvcGroup
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\CxAudMsg64.exe
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_00000248
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
WLIDSvcM.exe 2816
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
"taskhost.exe"
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Windows\system32\rundll32.exe "C:\Program Files\LENOVO\HOTKEY\hotkey.dll",InstallAudioHotkeyHook
C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.MediaKey
"C:\Windows\system32\Dwm.exe"
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
"C:\Program Files\Lenovo Fingerprint Reader\TouchControl.exe"
C:\Windows\Explorer.EXE
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Lenovo Fingerprint Reader\x86\BioMonitor.exe" -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Windows\System32\TpShocks.exe"
"C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\TrayStatus\TrayStatus.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe"
"C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Opera\Opera.exe" "http://www.element-14.com/eagle-freemium"
"C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe"
"C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files (x86)\Lenovo\System Update\SUService.exe"
"C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
taskeng.exe {7A422FDE-8674-4589-A45E-DF1107705248}
"C:\Program Files (x86)\Lenovo\message center plus\mcplaunch.exe" /start
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe" -startup
"taskhost.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\H\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avwsc.exe"

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-24 537576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}]
TrueSuite Browser Helper Object - C:\Program Files\Lenovo Fingerprint Reader\IEBHO.DLL [2012-06-07 1930088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6}]
Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll [2012-04-19 2443376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-24 193512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27 63944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-09-24 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8590886E-EC8C-43C1-A32C-E4C2B0B6395B}]
TrueSuite Browser Helper Object - C:\Program Files\Lenovo Fingerprint Reader\x86\IEBHO.dll [2012-06-07 1772904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6}]
Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll [2012-04-19 2109040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-09-24 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-06-25 170304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-06-25 398656]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-06-25 440128]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2012-03-01 564352]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2012-02-21 1654400]
"TpShocks"=TpShocks.exe []
"LENOVO.TPKNRRES"=C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [2012-06-02 290160]
""= []
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-06-19 2881336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TrayStatus"=C:\Program Files (x86)\TrayStatus\TrayStatus.exe [2011-05-18 283032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-07-27 919008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLEServicesCtrl]
C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe [2012-03-15 178960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [2012-03-27 11407120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files (x86)\ICQ7M\ICQ.exe [2012-09-05 127040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lenovo Registration]
C:\Program Files (x86)\Lenovo Registration\LenovoReg.exe [2011-07-14 4351712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^H^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk]
C:\PROGRA~1\MICROS~2\Office14\ONENOTEM.EXE [2010-12-21 245120]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [2012-03-07 133400]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-04-13 291608]
"RotateImage"=C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-31 55808]
"Dolby Advanced Audio v2"=C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [2011-12-21 507744]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"Fastboot"=C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [2012-01-17 1091376]
"Intel AppUp(SM) center"=C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [2012-07-12 155488]
"IntelSBA"=C:\Program Files (x86)\Intel\Intel(R) Small Business Advantage\Service\SBALaunchDelay.exe [2012-07-17 55560]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2012-09-25 386336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-10-07 11:57:40 ----D---- C:\rsit
2012-10-07 11:57:40 ----D---- C:\Program Files\trend micro
2012-10-07 11:52:31 ----D---- C:\Program Files (x86)\VS Revo Group
2012-10-05 21:09:44 ----D---- C:\Program Files (x86)\PdfMerge
2012-10-05 21:06:43 ----D---- C:\Program Files (x86)\pdfsam
2012-10-05 20:51:33 ----D---- C:\Users\H\AppData\Roaming\pdfforge
2012-10-05 20:51:31 ----A---- C:\Windows\system32\pdfcmon.dll
2012-10-05 20:51:30 ----A---- C:\Windows\SYSWOW64\MSMPIDE.DLL
2012-10-05 20:51:29 ----D---- C:\Program Files (x86)\PDFCreator
2012-10-05 20:16:01 ----D---- C:\Program Files (x86)\PdfSvg
2012-10-05 20:07:35 ----A---- C:\Windows\CITP_SearchHistory.INI
2012-10-05 19:26:09 ----A---- C:\Windows\SYSWOW64\pncrt.dll
2012-10-05 19:25:52 ----D---- C:\Program Files (x86)\FreeTime
2012-10-04 12:34:48 ----D---- C:\Users\H\AppData\Roaming\Avira
2012-10-04 12:29:26 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2012-10-04 12:29:26 ----A---- C:\Windows\system32\drivers\avipbb.sys
2012-10-04 12:29:26 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2012-10-04 12:29:25 ----D---- C:\ProgramData\Avira
2012-10-04 12:29:25 ----D---- C:\Program Files (x86)\Avira
2012-10-03 22:35:11 ----D---- C:\Program Files\AuthenTec
2012-10-02 20:14:12 ----D---- C:\Users\H\AppData\Roaming\vlc
2012-10-02 20:08:56 ----D---- C:\Program Files (x86)\VideoLAN
2012-09-26 17:35:50 ----D---- C:\Users\H\AppData\Roaming\ProfiCAD
2012-09-26 17:35:49 ----D---- C:\Program Files (x86)\ProfiCAD
2012-09-26 17:20:21 ----D---- C:\Program Files (x86)\EAGLE-6.2.0
2012-09-26 16:17:23 ----D---- C:\Program Files (x86)\MSECache
2012-09-26 09:45:47 ----A---- C:\Windows\system32\OxpsConverter.exe
2012-09-24 19:44:45 ----D---- C:\ProgramData\Sun
2012-09-24 19:44:19 ----A---- C:\Windows\SYSWOW64\npDeployJava1.dll
2012-09-24 19:44:19 ----A---- C:\Windows\SYSWOW64\javaws.exe
2012-09-24 19:44:19 ----A---- C:\Windows\SYSWOW64\deployJava1.dll
2012-09-24 19:44:07 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2012-09-24 19:44:07 ----A---- C:\Windows\SYSWOW64\javaw.exe
2012-09-24 19:44:07 ----A---- C:\Windows\SYSWOW64\java.exe
2012-09-24 19:43:56 ----D---- C:\Program Files (x86)\Java
2012-09-24 19:37:42 ----A---- C:\Windows\system32\npDeployJava1.dll
2012-09-24 19:37:42 ----A---- C:\Windows\system32\javaws.exe
2012-09-24 19:37:42 ----A---- C:\Windows\system32\deployJava1.dll
2012-09-24 19:37:34 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2012-09-24 19:37:34 ----A---- C:\Windows\system32\javaw.exe
2012-09-24 19:37:34 ----A---- C:\Windows\system32\java.exe
2012-09-24 19:37:22 ----D---- C:\Program Files\Java
2012-09-24 19:34:38 ----D---- C:\Program Files (x86)\GeoGebra
2012-09-24 19:29:55 ----D---- C:\Math Studio
2012-09-24 19:07:19 ----D---- C:\Program Files (x86)\Graph
2012-09-22 20:08:43 ----D---- C:\Program Files\Scan Tailor
2012-09-22 12:29:43 ----D---- C:\Program Files (x86)\HD Tune
2012-09-22 11:03:41 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2012-09-22 11:03:41 ----A---- C:\Windows\system32\mshtmled.dll
2012-09-22 11:03:40 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2012-09-22 11:03:40 ----A---- C:\Windows\SYSWOW64\ieui.dll
2012-09-22 11:03:39 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2012-09-22 11:03:39 ----A---- C:\Windows\system32\ieUnatt.exe
2012-09-22 11:03:39 ----A---- C:\Windows\system32\ieui.dll
2012-09-22 11:03:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2012-09-22 11:03:38 ----A---- C:\Windows\SYSWOW64\url.dll
2012-09-22 11:03:38 ----A---- C:\Windows\system32\url.dll
2012-09-22 11:03:37 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2012-09-22 11:03:37 ----A---- C:\Windows\system32\urlmon.dll
2012-09-22 11:03:37 ----A---- C:\Windows\system32\msfeeds.dll
2012-09-22 11:03:37 ----A---- C:\Windows\system32\jscript9.dll
2012-09-22 11:03:36 ----A---- C:\Windows\SYSWOW64\wininet.dll
2012-09-22 11:03:36 ----A---- C:\Windows\system32\wininet.dll
2012-09-22 11:03:35 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2012-09-22 11:03:35 ----A---- C:\Windows\SYSWOW64\jscript.dll
2012-09-22 11:03:35 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2012-09-22 11:03:35 ----A---- C:\Windows\system32\vbscript.dll
2012-09-22 11:03:35 ----A---- C:\Windows\system32\jsproxy.dll
2012-09-22 11:03:35 ----A---- C:\Windows\system32\jscript.dll
2012-09-22 11:03:35 ----A---- C:\Windows\system32\iertutil.dll
2012-09-22 11:03:34 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2012-09-22 11:03:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2012-09-22 11:03:32 ----A---- C:\Windows\system32\mshtml.dll
2012-09-22 11:03:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2012-09-22 11:03:31 ----A---- C:\Windows\system32\ieframe.dll
2012-09-21 14:25:20 ----D---- C:\ProgramData\TrueSuite
2012-09-16 19:48:42 ----D---- C:\Users\H\AppData\Roaming\Canon
2012-09-16 19:48:30 ----D---- C:\Windows\system32\Macromed
2012-09-16 19:45:12 ----D---- C:\Program Files (x86)\Canon
2012-09-15 10:27:52 ----D---- C:\Program Files (x86)\Keepinhead
2012-09-13 21:27:36 ----D---- C:\Program Files (x86)\Lavalys
2012-09-13 21:12:17 ----D---- C:\PC TRANSLATOR DEMO
2012-09-13 21:12:11 ----D---- C:\Users\H\AppData\Roaming\LangSoft
2012-09-13 21:12:11 ----D---- C:\ProgramData\LangSoft
2012-09-13 19:39:35 ----D---- C:\ProgramData\Advanced Chemistry Development
2012-09-13 19:39:11 ----D---- C:\ACDFREE10
2012-09-13 19:36:24 ----D---- C:\Users\H\AppData\Roaming\bkchem
2012-09-13 11:47:03 ----D---- C:\Program Files (x86)\TrayStatus
2012-09-12 22:09:47 ----D---- C:\Users\H\AppData\Roaming\IrfanView
2012-09-12 22:09:47 ----D---- C:\Program Files (x86)\IrfanView
2012-09-11 22:04:59 ----D---- C:\Windows\PCHEALTH
2012-09-11 21:56:04 ----A---- C:\Windows\SYSWOW64\d3d10level9.dll
2012-09-11 21:56:04 ----A---- C:\Windows\system32\d3d10level9.dll
2012-09-11 21:56:03 ----A---- C:\Windows\system32\drivers\RNDISMP.sys
2012-09-11 21:56:03 ----A---- C:\Windows\system32\drivers\ndis.sys
2012-09-11 21:56:02 ----A---- C:\Windows\system32\drivers\tcpip.sys
2012-09-11 21:56:02 ----A---- C:\Windows\system32\drivers\netio.sys
2012-09-11 21:56:02 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2012-09-11 21:50:53 ----D---- C:\Program Files\Common Files\DESIGNER
2012-09-11 21:48:41 ----D---- C:\Program Files\Microsoft Analysis Services
2012-09-11 21:48:41 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2012-09-11 21:48:18 ----D---- C:\Program Files\Microsoft Office
2012-09-11 21:47:57 ----RHD---- C:\MSOCache
2012-09-11 21:37:04 ----D---- C:\Users\H\AppData\Roaming\TP
2012-09-11 20:44:15 ----D---- C:\Users\H\AppData\Roaming\Template
2012-09-11 20:04:53 ----D---- C:\Program Files (x86)\Microsoft Works
2012-09-11 20:04:47 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2012-09-10 20:00:41 ----D---- C:\Users\H\AppData\Roaming\codeblocks
2012-09-10 20:00:25 ----D---- C:\Program Files (x86)\CodeBlocks
2012-09-10 17:41:15 ----A---- C:\Windows\SYSWOW64\libusb0.dll
2012-09-10 17:41:15 ----A---- C:\Windows\system32\libusb0.dll
2012-09-10 17:41:15 ----A---- C:\Windows\system32\drivers\libusb0.sys
2012-09-08 18:05:04 ----D---- C:\Users\H\AppData\Roaming\Exent Technologies
2012-09-08 10:30:42 ----D---- C:\ProgramData\FarmFrenzy3_Madagascar

======List of files/folders modified in the last 1 month======

2012-10-07 11:57:48 ----D---- C:\Windows\Temp
2012-10-07 11:57:47 ----D---- C:\Windows\Prefetch
2012-10-07 11:57:40 ----RD---- C:\Program Files
2012-10-07 11:52:31 ----RD---- C:\Program Files (x86)
2012-10-07 11:35:26 ----D---- C:\Windows\system32\config
2012-10-07 11:31:00 ----D---- C:\Windows\System32
2012-10-07 11:31:00 ----D---- C:\Windows\inf
2012-10-07 11:31:00 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-10-07 11:27:32 ----A---- C:\Windows\SYSWOW64\log.txt
2012-10-07 11:24:51 ----D---- C:\Windows
2012-10-06 21:07:27 ----D---- C:\Windows\rescache
2012-10-06 14:56:37 ----SD---- C:\Users\H\AppData\Roaming\Microsoft
2012-10-05 21:09:44 ----SHD---- C:\Windows\Installer
2012-10-05 21:09:31 ----SHD---- C:\System Volume Information
2012-10-05 20:51:31 ----D---- C:\Windows\SysWOW64
2012-10-05 18:47:02 ----D---- C:\Program Files\MyDefrag v4.3.1
2012-10-05 09:44:10 ----D---- C:\Users\H\AppData\Roaming\ICQ
2012-10-04 18:04:48 ----D---- C:\Windows\system32\wdi
2012-10-04 12:29:29 ----D---- C:\Windows\system32\catroot
2012-10-04 12:29:26 ----D---- C:\Windows\system32\drivers
2012-10-04 12:29:25 ----HD---- C:\ProgramData
2012-10-04 12:28:40 ----D---- C:\Windows\SoftwareDistribution
2012-10-04 12:21:02 ----D---- C:\ProgramData\Norton
2012-10-04 12:19:52 ----D---- C:\Windows\system32\Tasks
2012-10-04 12:19:52 ----D---- C:\Program Files\Common Files
2012-10-04 09:19:19 ----D---- C:\Windows\pss
2012-10-03 22:45:05 ----D---- C:\Windows\system32\WinBioPlugIns
2012-10-03 22:45:05 ----D---- C:\Windows\system32\drivers\UMDF
2012-10-03 22:35:07 ----D---- C:\Windows\system32\DriverStore
2012-10-02 19:02:26 ----D---- C:\ProgramData\Adobe
2012-10-02 19:02:22 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-09-29 10:57:47 ----D---- C:\Program Files\CCleaner
2012-09-29 10:56:24 ----D---- C:\Program Files (x86)\Google
2012-09-29 10:55:56 ----D---- C:\Windows\Tasks
2012-09-28 09:51:28 ----RD---- C:\DATA
2012-09-26 18:15:58 ----D---- C:\Windows\winsxs
2012-09-26 16:18:19 ----D---- C:\Program Files (x86)\Microsoft Office
2012-09-26 09:44:57 ----D---- C:\Windows\system32\catroot2
2012-09-24 19:44:45 ----D---- C:\Program Files (x86)\Common Files
2012-09-22 11:22:03 ----D---- C:\Windows\SYSWOW64\migration
2012-09-22 11:22:03 ----D---- C:\Program Files (x86)\Internet Explorer
2012-09-22 11:22:02 ----D---- C:\Windows\system32\migration
2012-09-22 11:22:01 ----D---- C:\Program Files\Internet Explorer
2012-09-18 23:20:33 ----D---- C:\swshare
2012-09-17 18:06:04 ----A---- C:\Windows\win.ini
2012-09-17 18:03:41 ----RSD---- C:\Windows\assembly
2012-09-17 16:51:50 ----A---- C:\Windows\ODBC.INI
2012-09-17 16:51:04 ----D---- C:\Windows\ShellNew
2012-09-17 16:48:05 ----D---- C:\Windows\system
2012-09-16 19:49:32 ----RSD---- C:\Windows\Media
2012-09-16 19:49:29 ----D---- C:\Windows\twain_32
2012-09-15 21:34:12 ----D---- C:\Users\H\AppData\Roaming\PSpad
2012-09-15 10:27:57 ----D---- C:\Windows\Speech
2012-09-11 22:36:51 ----D---- C:\Windows\debug
2012-09-11 22:33:58 ----D---- C:\ProgramData\Microsoft Help
2012-09-11 22:19:25 ----D---- C:\Windows\Microsoft.NET
2012-09-11 22:00:08 ----A---- C:\Windows\system32\MRT.exe
2012-09-11 21:50:56 ----RSD---- C:\Windows\Fonts
2012-09-11 21:50:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-09-11 21:50:32 ----SD---- C:\ProgramData\Microsoft
2012-09-11 21:50:32 ----D---- C:\Program Files (x86)\Microsoft.NET
2012-09-11 21:13:56 ----D---- C:\Program Files\Common Files\System
2012-09-11 20:44:14 ----D---- C:\Windows\system32\FxsTmp
2012-09-11 20:05:03 ----D---- C:\Windows\IME
2012-09-10 22:12:27 ----D---- C:\Program Files\Windows Sidebar
2012-09-10 22:12:27 ----D---- C:\Program Files\Windows Mail
2012-09-10 22:12:26 ----D---- C:\Program Files\Windows Photo Viewer
2012-09-10 22:12:26 ----D---- C:\Program Files\Windows Media Player
2012-09-10 22:12:26 ----D---- C:\Program Files\Windows Journal
2012-09-10 22:12:26 ----D---- C:\Program Files\DVD Maker
2012-09-10 22:12:25 ----D---- C:\Program Files\Windows Defender
2012-09-10 22:12:25 ----D---- C:\Program Files (x86)\Windows Sidebar
2012-09-10 22:12:25 ----D---- C:\Program Files (x86)\Windows Media Player
2012-09-10 22:12:25 ----D---- C:\Program Files (x86)\Windows Mail
2012-09-10 22:12:24 ----D---- C:\Windows\SYSWOW64\winrm
2012-09-10 22:12:24 ----D---- C:\Windows\SYSWOW64\migwiz
2012-09-10 22:12:24 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2012-09-10 22:12:24 ----D---- C:\Program Files (x86)\Windows Defender
2012-09-10 22:12:23 ----D---- C:\Windows\SYSWOW64\slmgr
2012-09-10 22:12:23 ----D---- C:\Windows\SYSWOW64\en-US
2012-09-10 22:12:23 ----D---- C:\Windows\SYSWOW64\en
2012-09-10 22:12:23 ----D---- C:\Windows\SYSWOW64\drivers\en-US
2012-09-10 22:12:05 ----D---- C:\Windows\SYSWOW64\WCN
2012-09-10 22:12:05 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2012-09-10 22:12:05 ----D---- C:\Windows\SYSWOW64\DriverStore
2012-09-10 22:12:05 ----D---- C:\Windows\SYSWOW64\Dism
2012-09-10 22:12:04 ----D---- C:\Windows\system32\migwiz
2012-09-10 22:12:04 ----D---- C:\Windows\en-US
2012-09-10 22:12:03 ----D---- C:\Windows\system32\winrm
2012-09-10 22:12:03 ----D---- C:\Windows\system32\slmgr
2012-09-10 22:12:03 ----D---- C:\Windows\system32\en
2012-09-10 22:12:03 ----D---- C:\Windows\system32\Boot
2012-09-10 22:12:02 ----D---- C:\Windows\system32\en-US
2012-09-10 22:11:44 ----D---- C:\Windows\system32\WCN
2012-09-10 22:11:44 ----D---- C:\Windows\system32\drivers\en-US
2012-09-10 22:11:44 ----D---- C:\Windows\system32\Dism
2012-09-10 22:11:42 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2012-09-10 21:22:36 ----D---- C:\Windows\Logs
2012-09-10 17:37:11 ----D---- C:\Program Files (x86)\eXtreme Burner - AVR
2012-09-09 18:49:56 ----D---- C:\Program Files (x86)\ICQ7M
2012-09-08 10:30:13 ----D---- C:\Program Files (x86)\Free Ride Games

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 Fastboot;Fastboot; C:\Windows\System32\DRIVERS\Fastboot.sys [2012-01-17 70416]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-12-23 568600]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-04-13 19224]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 Shockprf;Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [2011-12-29 147784]
R0 TPDIGIMN;TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [2011-12-29 25416]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2012-10-01 129576]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2012-09-24 27800]
R1 PHCORE;PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [2012-03-27 33344]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2012-05-15 19784]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2012-09-13 99248]
R3 5U877;5U877; C:\Windows\system32\DRIVERS\5U877.sys [2012-03-28 216704]
R3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter; C:\Windows\system32\DRIVERS\AMPPAL.sys [2012-01-09 195584]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2012-03-08 1602688]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2012-04-11 42280]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-06-25 14760096]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2012-06-21 331264]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-04-13 356632]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-04-13 789272]
R3 iwdbus;IWD Bus Enumerator; C:\Windows\system32\DRIVERS\iwdbus.sys [2011-12-21 25496]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2011-11-10 60184]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\Netwsw00.sys [2012-02-20 11471872]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2011-12-26 40248]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RSP2STOR;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2011-10-27 259688]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
R3 SmbDrvIntel;SmbDrvIntel; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2012-06-19 27448]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2012-06-19 431928]
R3 TVTI2C;Lenovo SM bus driver; C:\Windows\system32\DRIVERS\Tvti2c.sys [2011-05-29 40248]
R3 tvtvcamd;ThinkVantage Virtual Camera; C:\Windows\system32\DRIVERS\tvtvcamd.sys [2011-12-08 27432]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WinUsb;WinUSB Driver; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]
S3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol; C:\Windows\system32\DRIVERS\amppal.sys [2012-01-09 195584]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-12-08 80384]
S3 btmaux;Intel Bluetooth Auxiliary Service; C:\Windows\system32\DRIVERS\btmaux.sys [2012-02-13 95232]
S3 btmhsf;btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [2012-02-13 747008]
S3 ibtfltcoex;ibtfltcoex; C:\Windows\system32\DRIVERS\iBtFltCoex.sys [2012-03-21 60928]
S3 intaud_WaveExtensible;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2011-12-21 34200]
S3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0; C:\Windows\system32\DRIVERS\libusb0.sys [2012-01-16 44480]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
R2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-01-09 659968]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-09-25 108320]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-09-25 84256]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-03-27 1014096]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-03-27 1104208]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-01-18 135952]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2010-12-17 198784]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2012-02-26 626960]
R2 FastbootService;FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2012-01-17 169776]
R2 FPLService;TrueSuiteService; C:\Program Files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2012-06-07 328552]
R2 IBMPMSVC;Lenovo PM Service; C:\Windows\system32\ibmpmsvc.exe [2012-04-11 47440]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-02-03 628448]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-03-07 128280]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-03-07 163608]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [2012-06-02 58224]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2012-06-02 61296]
R2 LENOVO.TVTVCAM;ThinkVantage Virtual Camera Controller; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2012-06-02 179568]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [2011-07-12 133992]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-03-07 277784]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-11 193824]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2012-02-26 148752]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SUService;System Update; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [2012-06-06 34728]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 145256]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2011-12-29 144960]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-03-07 363800]
R2 VIPAppService;VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [2012-04-19 84080]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-19 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 136176]
S2 HyperW7Svc;HyperW7 Service; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2012-05-30 144992]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [2012-03-27 1304912]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-06-25 276288]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 136176]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2012-02-26 273168]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2012-05-15 1662560]
S3 PwmEWSvc;Cisco EnergyWise Enabler; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2012-05-15 1665120]
S3 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\Windows\System32\TPHDEXLG64.exe [2011-12-29 49480]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-09-04 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu a pomoc s Avirou

#2 Příspěvek od Rudy »

Zdravím!
Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Re: Prosím o kontrolu logu a pomoc s Avirou

#3 Příspěvek od Moody.01 »

imformuji, ze skenuje uz pul hodiny, smazal 3 soubory (i autorun), 3 slozky a je uz nejakou dobu ve fazi pripravy log report.
po spusteni scanu se ozvala avira s varovanim Registry blocked.

Po asi hodině a čtvrt! se konečně zobrazil log, restart neproběhl.



ComboFix 12-10-04.02 - H 07.10.2012 12:58:55.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3685.2157 [GMT 2:00]
Spuštěný z: c:\users\H\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\users\H\AppData\Local\assembly\tmp
c:\users\H\AppData\Roaming\bkchem
c:\users\H\AppData\Roaming\bkchem\prefs.xml
c:\users\Public\AlexaNSISPlugin.5032.dll
Q:\Autorun.inf
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-07 do 2012-10-07 )))))))))))))))))))))))))))))))
.
.
2012-10-07 11:18 . 2012-10-07 11:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-07 09:57 . 2012-10-07 09:57 -------- d-----w- C:\rsit
2012-10-07 09:57 . 2012-10-07 09:57 -------- d-----w- c:\program files\trend micro
2012-10-07 09:52 . 2012-10-07 09:52 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-10-05 19:09 . 2012-10-05 19:09 -------- d-----w- c:\program files (x86)\PdfMerge
2012-10-05 19:08 . 2012-10-05 19:08 -------- d-----w- c:\users\H\.pdfsam
2012-10-05 19:06 . 2012-10-05 19:08 -------- d-----w- c:\program files (x86)\pdfsam
2012-10-05 18:51 . 2012-10-05 19:02 -------- d-----w- c:\users\H\AppData\Roaming\pdfforge
2012-10-05 18:51 . 2012-07-29 11:59 96768 ----a-w- c:\windows\system32\pdfcmon.dll
2012-10-05 18:51 . 2012-05-05 09:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2012-10-05 18:51 . 2012-05-05 09:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2012-10-05 18:51 . 2012-05-05 09:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2012-10-05 18:51 . 2012-10-05 18:51 -------- d-----w- c:\program files (x86)\PDFCreator
2012-10-05 18:16 . 2012-10-05 18:16 -------- d-----w- c:\program files (x86)\PdfSvg
2012-10-05 18:06 . 2000-05-22 02:00 244416 ----a-w- c:\windows\SysWow64\Msflxgrd.ocx
2012-10-05 18:06 . 1999-05-07 02:00 140288 ----a-w- c:\windows\SysWow64\comdlg32.ocx
2012-10-05 17:25 . 2012-10-05 17:25 -------- d-----w- c:\program files (x86)\FreeTime
2012-10-05 16:11 . 2012-10-07 10:57 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28F61C57-1A3E-4EC2-8536-746D00ADA80E}\offreg.dll
2012-10-05 14:09 . 2012-09-18 22:58 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28F61C57-1A3E-4EC2-8536-746D00ADA80E}\mpengine.dll
2012-10-04 10:34 . 2012-10-04 10:34 -------- d-----w- c:\users\H\AppData\Roaming\Avira
2012-10-04 10:29 . 2012-10-01 15:14 129576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-10-04 10:29 . 2012-09-24 07:58 27800 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-10-04 10:29 . 2012-09-13 13:52 99248 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-10-04 10:29 . 2012-10-04 10:29 -------- d-----w- c:\programdata\Avira
2012-10-04 10:29 . 2012-10-04 10:29 -------- d-----w- c:\program files (x86)\Avira
2012-10-03 20:35 . 2012-10-03 20:35 -------- d-----w- c:\program files\AuthenTec
2012-10-03 20:14 . 2012-10-03 20:14 -------- d-----w- c:\users\H\AppData\Local\Chemistry Add-in for Word
2012-10-03 20:14 . 2012-10-07 11:07 -------- d-----w- c:\users\H\AppData\Local\assembly
2012-10-02 18:14 . 2012-10-06 12:54 -------- d-----w- c:\users\H\AppData\Roaming\vlc
2012-10-02 18:08 . 2012-10-02 18:08 -------- d-----w- c:\program files (x86)\VideoLAN
2012-09-26 15:35 . 2012-09-26 15:36 -------- d-----w- c:\users\H\AppData\Roaming\ProfiCAD
2012-09-26 15:35 . 2012-09-26 15:35 -------- d-----w- c:\program files (x86)\ProfiCAD
2012-09-26 15:21 . 2012-09-26 15:21 -------- d-----w- c:\users\H\eagle
2012-09-26 15:20 . 2012-09-26 16:07 -------- d-----w- c:\program files (x86)\EAGLE-6.2.0
2012-09-26 15:08 . 2012-09-26 15:15 -------- d-----w- c:\users\H\.qucs
2012-09-26 14:17 . 2012-09-26 14:17 -------- d-----w- c:\program files (x86)\MSECache
2012-09-26 07:45 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-09-24 17:44 . 2012-09-24 17:44 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-09-24 17:44 . 2012-09-24 17:43 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-09-24 17:44 . 2012-09-24 17:43 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-24 17:44 . 2012-09-24 17:43 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-24 17:43 . 2012-09-24 17:43 -------- d-----w- c:\program files (x86)\Java
2012-09-24 17:37 . 2012-09-24 17:37 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 17:37 . 2012-09-24 17:37 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-24 17:37 . 2012-09-24 17:37 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-24 17:37 . 2012-09-24 17:37 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-24 17:37 . 2012-09-24 17:37 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-24 17:37 . 2012-09-24 17:37 188904 ----a-w- c:\windows\system32\java.exe
2012-09-24 17:37 . 2012-09-24 17:37 -------- d-----w- c:\program files\Java
2012-09-24 17:34 . 2012-09-24 17:34 -------- d-----w- c:\program files (x86)\GeoGebra
2012-09-24 17:29 . 2012-09-24 17:29 -------- d-----w- C:\Math Studio
2012-09-24 17:07 . 2012-09-24 17:07 -------- d-----w- c:\program files (x86)\Graph
2012-09-22 18:08 . 2012-09-22 18:08 -------- d-----w- c:\program files\Scan Tailor
2012-09-22 10:29 . 2012-09-22 10:29 -------- d-----w- c:\program files (x86)\HD Tune
2012-09-21 12:25 . 2012-09-21 12:25 -------- d-----w- c:\programdata\TrueSuite
2012-09-16 17:48 . 2012-09-16 17:51 -------- d-----w- c:\users\H\AppData\Roaming\Canon
2012-09-16 17:48 . 2012-09-16 17:48 -------- d-----w- c:\windows\system32\Macromed
2012-09-16 17:45 . 2012-09-16 17:46 -------- d-----w- c:\program files (x86)\Canon
2012-09-15 08:27 . 2012-09-15 08:28 -------- d-----w- c:\program files (x86)\Keepinhead
2012-09-13 19:27 . 2012-09-13 19:34 -------- d-----w- c:\program files (x86)\Lavalys
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- C:\PC TRANSLATOR DEMO
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- c:\users\H\AppData\Roaming\LangSoft
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- c:\programdata\LangSoft
2012-09-13 17:39 . 2012-09-13 17:39 -------- d-----w- c:\programdata\Advanced Chemistry Development
2012-09-13 17:39 . 2012-09-13 17:39 -------- d-----w- C:\ACDFREE10
2012-09-13 09:47 . 2012-09-13 09:51 -------- d-----w- c:\program files (x86)\TrayStatus
2012-09-12 20:09 . 2012-09-12 20:09 -------- d-----w- c:\users\H\AppData\Roaming\IrfanView
2012-09-12 20:09 . 2012-09-12 20:09 -------- d-----w- c:\program files (x86)\IrfanView
2012-09-11 20:06 . 2012-09-11 20:06 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-09-11 20:04 . 2012-09-11 20:04 -------- d-----w- c:\windows\PCHEALTH
2012-09-11 19:56 . 2012-08-02 17:58 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-11 19:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2012-09-11 19:56 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-11 19:56 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-11 19:56 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-11 19:56 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-11 19:56 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-11 19:50 . 2012-09-11 19:50 -------- d-----w- c:\program files\Common Files\DESIGNER
2012-09-11 19:48 . 2012-09-11 19:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-09-11 19:48 . 2012-09-11 19:48 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-09-11 19:48 . 2012-09-11 19:50 -------- d-----w- c:\program files\Microsoft Office
2012-09-11 19:47 . 2012-09-11 19:47 -------- d-----r- C:\MSOCache
2012-09-11 19:37 . 2012-09-11 19:37 -------- d-----w- c:\users\H\AppData\Roaming\TP
2012-09-11 18:44 . 2012-09-11 18:44 -------- d-----w- c:\users\H\AppData\Roaming\Template
2012-09-11 18:04 . 2012-09-24 17:06 -------- d-----w- c:\program files (x86)\Microsoft Works
2012-09-10 18:00 . 2012-09-10 18:55 -------- d-----w- c:\users\H\AppData\Roaming\codeblocks
2012-09-10 18:00 . 2012-09-10 18:15 -------- d-----w- c:\program files (x86)\CodeBlocks
2012-09-10 15:41 . 2012-01-16 05:57 44480 ----a-w- c:\windows\system32\drivers\libusb0.sys
2012-09-10 15:41 . 2012-01-16 05:57 75200 ----a-w- c:\windows\system32\libusb0.dll
2012-09-10 15:41 . 2012-01-16 05:57 67008 ----a-w- c:\windows\SysWow64\libusb0.dll
2012-09-08 16:05 . 2012-09-08 16:05 -------- d-----w- c:\users\H\AppData\Roaming\Exent Technologies
2012-09-08 08:30 . 2012-09-08 12:46 -------- d-----w- c:\programdata\FarmFrenzy3_Madagascar
2012-09-07 17:55 . 2012-09-07 17:56 -------- d-----w- c:\programdata\InterAction studios
2012-09-07 17:54 . 2012-09-07 17:54 -------- d-----w- c:\programdata\Free Ride Games
2012-09-07 17:53 . 2011-09-01 15:25 53314 ------w- c:\windows\ExentInfo.exe
2012-09-07 17:53 . 2012-09-08 08:30 -------- d-----w- c:\program files (x86)\Free Ride Games
2012-09-07 17:53 . 2012-09-07 17:53 -------- d-----w- C:\Remote Programs
2012-09-07 17:50 . 2012-09-07 17:50 -------- d-----w- c:\users\H\AppData\Local\SugarSync
2012-09-07 16:36 . 2010-05-21 10:11 1147392 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.exe
2012-09-07 16:36 . 2012-10-05 16:47 -------- d-----w- c:\program files\MyDefrag v4.3.1
2012-09-07 16:36 . 2010-05-21 10:11 485376 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.scr
2012-09-07 13:35 . 2012-09-07 13:42 -------- d-----w- C:\ldiag
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-02 17:02 . 2012-09-04 20:18 73136 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-02 17:02 . 2012-09-04 20:18 696240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-11 20:00 . 2012-09-04 20:01 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-09-07 10:15 . 2012-09-07 10:14 6233848 ----a-w- c:\users\H\AppData\Roaming\LoJackSetup.exe
2012-09-05 01:08 . 2012-09-05 01:08 3993600 ----a-w- c:\program files (x86)\GUT3FAF.tmp
2012-09-04 19:11 . 2011-03-29 01:36 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-08-15 15:12 . 2012-08-15 15:12 20000 ----a-w- c:\windows\system32\tccoinst.dll
2012-08-15 15:12 . 2012-08-15 15:12 1014440 ----a-w- c:\windows\system32\drivers\UMDF\tcwbf.dll
2012-08-03 16:12 . 2012-08-03 16:12 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-08-03 16:10 . 2012-08-03 16:10 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-08-03 16:10 . 2012-08-03 16:10 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-08-03 16:10 . 2012-08-03 16:10 1544704 ----a-w- c:\windows\system32\DWrite.dll
2012-08-03 16:10 . 2012-08-03 16:10 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-08-03 16:10 . 2012-08-03 16:10 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-08-03 16:10 . 2012-08-03 16:10 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-08-03 16:10 . 2012-08-03 16:10 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-08-03 16:10 . 2012-08-03 16:10 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-08-03 16:10 . 2012-08-03 16:10 5120 ----a-w- c:\windows\system32\wmi.dll
2012-08-03 16:10 . 2012-08-03 16:10 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-08-03 16:10 . 2012-08-03 16:10 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-08-03 16:10 . 2012-08-03 16:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-08-03 16:10 . 2012-08-03 16:10 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-08-03 16:09 . 2012-08-03 16:09 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-08-03 16:09 . 2012-08-03 16:09 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-08-03 16:09 . 2012-08-03 16:09 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-08-03 16:09 . 2012-08-03 16:09 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-08-03 16:09 . 2012-08-03 16:09 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-08-03 16:08 . 2012-08-03 16:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-08-03 16:08 . 2012-08-03 16:08 2048 ----a-w- c:\windows\system32\tzres.dll
2012-08-03 16:08 . 2012-08-03 16:08 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-08-03 16:08 . 2012-08-03 16:08 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-08-03 16:08 . 2012-08-03 16:08 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-08-03 16:08 . 2012-08-03 16:08 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-08-03 16:08 . 2012-08-03 16:08 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-08-03 16:08 . 2012-08-03 16:08 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-08-03 16:08 . 2012-08-03 16:08 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-08-03 16:08 . 2012-08-03 16:08 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-08-03 16:07 . 2012-08-03 16:07 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2012-08-03 16:07 . 2012-08-03 16:07 229888 ----a-w- c:\windows\system32\wwansvc.dll
2012-08-03 16:07 . 2012-08-03 16:07 395776 ----a-w- c:\windows\system32\webio.dll
2012-08-03 16:07 . 2012-08-03 16:07 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-08-03 16:07 . 2012-08-03 16:07 31232 ----a-w- c:\windows\system32\lsass.exe
2012-08-03 16:07 . 2012-08-03 16:07 29184 ----a-w- c:\windows\system32\sspisrv.dll
2012-08-03 16:07 . 2012-08-03 16:07 28160 ----a-w- c:\windows\system32\secur32.dll
2012-08-03 16:07 . 2012-08-03 16:07 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2012-08-03 16:07 . 2012-08-03 16:07 136192 ----a-w- c:\windows\system32\sspicli.dll
2012-08-03 16:06 . 2012-08-03 16:06 77312 ----a-w- c:\windows\system32\packager.dll
2012-08-03 16:06 . 2012-08-03 16:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-08-03 16:06 . 2012-08-03 16:06 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-08-03 16:06 . 2012-08-03 16:06 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-08-03 16:06 . 2012-08-03 16:06 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-08-03 16:06 . 2012-08-03 16:06 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-08-03 16:06 . 2012-08-03 16:06 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-08-03 16:06 . 2012-08-03 16:06 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-08-03 16:06 . 2012-08-03 16:06 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-08-03 16:06 . 2012-08-03 16:06 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-08-03 16:06 . 2012-08-03 16:06 163840 ----a-w- c:\windows\system32\umpo.dll
2012-08-03 16:04 . 2012-08-03 16:04 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2012-08-03 16:04 . 2012-08-03 16:04 5632 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2012-08-03 16:04 . 2012-08-03 16:04 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2012-08-03 16:04 . 2012-08-03 16:04 50176 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2012-08-03 16:03 . 2012-08-03 16:03 27136 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2012-08-03 16:03 . 2012-08-03 16:03 15360 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
2012-07-18 18:15 . 2012-09-04 20:00 3148800 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrayStatus"="c:\program files (x86)\TrayStatus\TrayStatus.exe" [2011-05-18 283032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-03-06 133400]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-04-13 291608]
"RotateImage"="c:\program files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" [2008-10-30 55808]
"Dolby Advanced Audio v2"="c:\program files (x86)\Dolby Advanced Audio v2\pcee4.exe" [2011-12-21 507744]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2012-05-15 5941344]
"Fastboot"="c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" [2012-01-17 1091376]
"Intel AppUp(SM) center"="c:\program files (x86)\Intel\IntelAppStore\bin\ismagent.exe" [2012-07-12 155488]
"IntelSBA"="c:\program files (x86)\Intel\Intel(R) Small Business Advantage\Service\SBALaunchDelay.exe" [2012-07-17 55560]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 136176]
R2 HyperW7Svc;HyperW7 Service;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe [2012-05-29 144992]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2012-02-26 2669840]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2012-01-09 195584]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2012-03-27 1304912]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2012-02-13 95232]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2012-02-13 747008]
R3 cphs;Intel(R) Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-06-25 276288]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 136176]
R3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2012-03-21 60928]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-12-21 34200]
R3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0;c:\windows\system32\DRIVERS\libusb0.sys [2012-01-16 44480]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2012-02-26 273168]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2012-05-15 1662560]
R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2012-05-15 1665120]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-04 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 Fastboot;Fastboot;c:\windows\System32\DRIVERS\Fastboot.sys [2012-01-17 70416]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-04-13 19224]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [2011-12-29 25416]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-09-24 27800]
S1 PHCORE;PHCORE;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS [2012-03-26 33344]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-01-09 659968]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-09-25 84256]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-03-27 1014096]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2012-03-27 1104208]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-01-17 135952]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2010-12-17 198784]
S2 FastbootService;FastbootService;c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2012-01-17 169776]
S2 FPLService;TrueSuiteService;c:\program files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2012-06-07 328552]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-03 628448]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-03-06 128280]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-03-06 163608]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2012-06-02 58224]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2012-06-02 61296]
S2 LENOVO.TVTVCAM;ThinkVantage Virtual Camera Controller;c:\program files\Lenovo\Communications Utility\vcamsvc.exe [2012-06-02 179568]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2011-07-12 133992]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe [x]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 145256]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2011-12-29 144960]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-03-06 363800]
S2 VIPAppService;VIPAppService;c:\program files (x86)\Symantec\VIP Access Client\VIPAppService.exe [2012-04-19 84080]
S2 X5XSEx;X5XSEx;c:\program files (x86)\Free Ride Games\X5XSEx.Sys [2010-11-22 55400]
S3 5U877;5U877;c:\windows\system32\DRIVERS\5U877.sys [2012-03-28 216704]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2012-01-09 195584]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2012-06-21 331264]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-04-13 356632]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-04-13 789272]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-12-21 25496]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2011-11-10 60184]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\Netwsw00.sys [2012-02-20 11471872]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;c:\windows\system32\DRIVERS\RtsP2Stor.sys [2011-10-27 259688]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
S3 SmbDrvIntel;SmbDrvIntel;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys [2012-06-19 27448]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2011-05-29 40248]
S3 tvtvcamd;ThinkVantage Virtual Camera;c:\windows\system32\DRIVERS\tvtvcamd.sys [2011-12-08 27432]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 08:55]
.
2012-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 08:55]
.
2012-10-07 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
2012-10-07 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-06-25 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-06-25 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-06-25 440128]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2012-03-01 564352]
"ForteConfig"="c:\program files\Conexant\ForteConfig\fmapp.exe" [2010-10-26 49056]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2012-02-21 1654400]
"TpShocks"="TpShocks.exe" [2012-02-25 382528]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2012-06-02 290160]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 62.129.50.20 85.135.32.100
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fastboot]
"ImagePath"=multi:"System32\DRIVERS\Fastboot.sys\00"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fastboot]
"ImagePath"=multi:"System32\DRIVERS\Fastboot.sys\00"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-10-07 14:21:27
ComboFix-quarantined-files.txt 2012-10-07 12:21
.
Před spuštěním: Volných bajtů: 424 526 131 200
Po spuštění: Volných bajtů: 424 382 185 472
.
- - End Of File - - 0354EC9479C744144530B4A3D4917BB4

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu a pomoc s Avirou

#4 Příspěvek od Rudy »

Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

RegLock::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

Regnull::
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Re: Prosím o kontrolu logu a pomoc s Avirou

#5 Příspěvek od Moody.01 »

Dobře, jdu na to. Doufám, že to nebude trvat příliš dlouho. ;)

Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Re: Prosím o kontrolu logu a pomoc s Avirou

#6 Příspěvek od Moody.01 »

objevil se velky problem. po restartu nemuzu spustit zadny program.

pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni.

co s tim!!!
v logu jsou vymazany pouze prvni dva job soubory.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu a pomoc s Avirou

#7 Příspěvek od Rudy »

Zkuste ještě jeden restart.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Re: Prosím o kontrolu logu a pomoc s Avirou

#8 Příspěvek od Moody.01 »

Dobře, snad to pomůže.
Jinak po spuštění skriptu opět avira hlásila registry blocked.
Nejprve ještě zálohuji pár souborů, pro jistotu a pak provedu restart. ;)
A podařilo se mi vytvořit recovery medium, odstraněním autorun.inf se proces zálohy podařil.

edit
Vytáhla jsem i log, soubory mám zálohované, takže jdu restartova ;)

ComboFix 12-10-04.02 - H 07.10.2012 18:32:19.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3685.2133 [GMT 2:00]
Spuštěný z: c:\users\H\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\H\Desktop\CFScript.txt
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-09-07 do 2012-10-07 )))))))))))))))))))))))))))))))
.
.
2012-10-07 16:50 . 2012-10-07 16:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-07 09:57 . 2012-10-07 09:57 -------- d-----w- C:\rsit
2012-10-07 09:57 . 2012-10-07 09:57 -------- d-----w- c:\program files\trend micro
2012-10-07 09:52 . 2012-10-07 09:52 -------- d-----w- c:\program files (x86)\VS Revo Group
2012-10-05 19:09 . 2012-10-05 19:09 -------- d-----w- c:\program files (x86)\PdfMerge
2012-10-05 19:08 . 2012-10-05 19:08 -------- d-----w- c:\users\H\.pdfsam
2012-10-05 19:06 . 2012-10-05 19:08 -------- d-----w- c:\program files (x86)\pdfsam
2012-10-05 18:51 . 2012-10-05 19:02 -------- d-----w- c:\users\H\AppData\Roaming\pdfforge
2012-10-05 18:51 . 2012-07-29 11:59 96768 ----a-w- c:\windows\system32\pdfcmon.dll
2012-10-05 18:51 . 2012-05-05 09:54 662288 ----a-w- c:\windows\SysWow64\MSCOMCT2.OCX
2012-10-05 18:51 . 2012-05-05 09:54 137000 ----a-w- c:\windows\SysWow64\MSMAPI32.OCX
2012-10-05 18:51 . 2012-05-05 09:54 23552 ----a-w- c:\windows\SysWow64\MSMPIDE.DLL
2012-10-05 18:51 . 2012-10-05 18:51 -------- d-----w- c:\program files (x86)\PDFCreator
2012-10-05 18:16 . 2012-10-05 18:16 -------- d-----w- c:\program files (x86)\PdfSvg
2012-10-05 18:06 . 2000-05-22 02:00 244416 ----a-w- c:\windows\SysWow64\Msflxgrd.ocx
2012-10-05 18:06 . 1999-05-07 02:00 140288 ----a-w- c:\windows\SysWow64\comdlg32.ocx
2012-10-05 17:25 . 2012-10-05 17:25 -------- d-----w- c:\program files (x86)\FreeTime
2012-10-05 14:09 . 2012-09-18 22:58 9308616 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{28F61C57-1A3E-4EC2-8536-746D00ADA80E}\mpengine.dll
2012-10-04 10:34 . 2012-10-04 10:34 -------- d-----w- c:\users\H\AppData\Roaming\Avira
2012-10-04 10:29 . 2012-10-01 15:14 129576 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-10-04 10:29 . 2012-09-24 07:58 27800 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-10-04 10:29 . 2012-09-13 13:52 99248 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-10-04 10:29 . 2012-10-04 10:29 -------- d-----w- c:\programdata\Avira
2012-10-04 10:29 . 2012-10-04 10:29 -------- d-----w- c:\program files (x86)\Avira
2012-10-03 20:35 . 2012-10-03 20:35 -------- d-----w- c:\program files\AuthenTec
2012-10-03 20:14 . 2012-10-03 20:14 -------- d-----w- c:\users\H\AppData\Local\Chemistry Add-in for Word
2012-10-03 20:14 . 2012-10-07 11:07 -------- d-----w- c:\users\H\AppData\Local\assembly
2012-10-02 18:14 . 2012-10-06 12:54 -------- d-----w- c:\users\H\AppData\Roaming\vlc
2012-10-02 18:08 . 2012-10-02 18:08 -------- d-----w- c:\program files (x86)\VideoLAN
2012-09-26 15:35 . 2012-09-26 15:36 -------- d-----w- c:\users\H\AppData\Roaming\ProfiCAD
2012-09-26 15:35 . 2012-09-26 15:35 -------- d-----w- c:\program files (x86)\ProfiCAD
2012-09-26 15:21 . 2012-09-26 15:21 -------- d-----w- c:\users\H\eagle
2012-09-26 15:20 . 2012-09-26 16:07 -------- d-----w- c:\program files (x86)\EAGLE-6.2.0
2012-09-26 15:08 . 2012-09-26 15:15 -------- d-----w- c:\users\H\.qucs
2012-09-26 14:17 . 2012-09-26 14:17 -------- d-----w- c:\program files (x86)\MSECache
2012-09-26 07:45 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
2012-09-24 17:44 . 2012-09-24 17:44 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-09-24 17:44 . 2012-09-24 17:43 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-09-24 17:44 . 2012-09-24 17:43 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-09-24 17:44 . 2012-09-24 17:43 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-24 17:43 . 2012-09-24 17:43 -------- d-----w- c:\program files (x86)\Java
2012-09-24 17:37 . 2012-09-24 17:37 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 17:37 . 2012-09-24 17:37 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-24 17:37 . 2012-09-24 17:37 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-24 17:37 . 2012-09-24 17:37 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-24 17:37 . 2012-09-24 17:37 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-24 17:37 . 2012-09-24 17:37 188904 ----a-w- c:\windows\system32\java.exe
2012-09-24 17:37 . 2012-09-24 17:37 -------- d-----w- c:\program files\Java
2012-09-24 17:34 . 2012-09-24 17:34 -------- d-----w- c:\program files (x86)\GeoGebra
2012-09-24 17:29 . 2012-09-24 17:29 -------- d-----w- C:\Math Studio
2012-09-24 17:07 . 2012-09-24 17:07 -------- d-----w- c:\program files (x86)\Graph
2012-09-22 18:08 . 2012-09-22 18:08 -------- d-----w- c:\program files\Scan Tailor
2012-09-22 10:29 . 2012-09-22 10:29 -------- d-----w- c:\program files (x86)\HD Tune
2012-09-21 12:25 . 2012-09-21 12:25 -------- d-----w- c:\programdata\TrueSuite
2012-09-16 17:48 . 2012-09-16 17:51 -------- d-----w- c:\users\H\AppData\Roaming\Canon
2012-09-16 17:48 . 2012-09-16 17:48 -------- d-----w- c:\windows\system32\Macromed
2012-09-16 17:45 . 2012-09-16 17:46 -------- d-----w- c:\program files (x86)\Canon
2012-09-15 08:27 . 2012-09-15 08:28 -------- d-----w- c:\program files (x86)\Keepinhead
2012-09-13 19:27 . 2012-09-13 19:34 -------- d-----w- c:\program files (x86)\Lavalys
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- C:\PC TRANSLATOR DEMO
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- c:\users\H\AppData\Roaming\LangSoft
2012-09-13 19:12 . 2012-09-13 19:12 -------- d-----w- c:\programdata\LangSoft
2012-09-13 17:39 . 2012-09-13 17:39 -------- d-----w- c:\programdata\Advanced Chemistry Development
2012-09-13 17:39 . 2012-09-13 17:39 -------- d-----w- C:\ACDFREE10
2012-09-13 09:47 . 2012-09-13 09:51 -------- d-----w- c:\program files (x86)\TrayStatus
2012-09-12 20:09 . 2012-09-12 20:09 -------- d-----w- c:\users\H\AppData\Roaming\IrfanView
2012-09-12 20:09 . 2012-09-12 20:09 -------- d-----w- c:\program files (x86)\IrfanView
2012-09-11 20:06 . 2012-09-11 20:06 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-09-11 20:04 . 2012-09-11 20:04 -------- d-----w- c:\windows\PCHEALTH
2012-09-11 19:56 . 2012-08-02 17:58 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2012-09-11 19:56 . 2012-08-02 16:57 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2012-09-11 19:56 . 2012-08-22 18:12 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-09-11 19:56 . 2012-07-04 20:26 41472 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2012-09-11 19:56 . 2012-08-22 18:12 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-09-11 19:56 . 2012-08-22 18:12 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-09-11 19:56 . 2012-08-22 18:12 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-09-11 19:50 . 2012-09-11 19:50 -------- d-----w- c:\program files\Common Files\DESIGNER
2012-09-11 19:48 . 2012-09-11 19:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-09-11 19:48 . 2012-09-11 19:48 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2012-09-11 19:48 . 2012-09-11 19:50 -------- d-----w- c:\program files\Microsoft Office
2012-09-11 19:47 . 2012-09-11 19:47 -------- d-----r- C:\MSOCache
2012-09-11 19:37 . 2012-09-11 19:37 -------- d-----w- c:\users\H\AppData\Roaming\TP
2012-09-11 18:44 . 2012-09-11 18:44 -------- d-----w- c:\users\H\AppData\Roaming\Template
2012-09-11 18:04 . 2012-09-24 17:06 -------- d-----w- c:\program files (x86)\Microsoft Works
2012-09-10 18:00 . 2012-09-10 18:55 -------- d-----w- c:\users\H\AppData\Roaming\codeblocks
2012-09-10 18:00 . 2012-09-10 18:15 -------- d-----w- c:\program files (x86)\CodeBlocks
2012-09-10 15:41 . 2012-01-16 05:57 44480 ----a-w- c:\windows\system32\drivers\libusb0.sys
2012-09-10 15:41 . 2012-01-16 05:57 75200 ----a-w- c:\windows\system32\libusb0.dll
2012-09-10 15:41 . 2012-01-16 05:57 67008 ----a-w- c:\windows\SysWow64\libusb0.dll
2012-09-08 16:05 . 2012-09-08 16:05 -------- d-----w- c:\users\H\AppData\Roaming\Exent Technologies
2012-09-08 08:30 . 2012-09-08 12:46 -------- d-----w- c:\programdata\FarmFrenzy3_Madagascar
2012-09-07 17:55 . 2012-09-07 17:56 -------- d-----w- c:\programdata\InterAction studios
2012-09-07 17:54 . 2012-09-07 17:54 -------- d-----w- c:\programdata\Free Ride Games
2012-09-07 17:53 . 2011-09-01 15:25 53314 ------w- c:\windows\ExentInfo.exe
2012-09-07 17:53 . 2012-09-08 08:30 -------- d-----w- c:\program files (x86)\Free Ride Games
2012-09-07 17:53 . 2012-09-07 17:53 -------- d-----w- C:\Remote Programs
2012-09-07 17:50 . 2012-09-07 17:50 -------- d-----w- c:\users\H\AppData\Local\SugarSync
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-02 17:02 . 2012-09-04 20:18 73136 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-02 17:02 . 2012-09-04 20:18 696240 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-09-11 20:00 . 2012-09-04 20:01 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-09-07 10:15 . 2012-09-07 10:14 6233848 ----a-w- c:\users\H\AppData\Roaming\LoJackSetup.exe
2012-09-05 01:08 . 2012-09-05 01:08 3993600 ----a-w- c:\program files (x86)\GUT3FAF.tmp
2012-09-04 19:11 . 2011-03-29 01:36 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-08-15 15:12 . 2012-08-15 15:12 20000 ----a-w- c:\windows\system32\tccoinst.dll
2012-08-15 15:12 . 2012-08-15 15:12 1014440 ----a-w- c:\windows\system32\drivers\UMDF\tcwbf.dll
2012-08-03 16:12 . 2012-08-03 16:12 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-08-03 16:10 . 2012-08-03 16:10 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-08-03 16:10 . 2012-08-03 16:10 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-08-03 16:10 . 2012-08-03 16:10 1544704 ----a-w- c:\windows\system32\DWrite.dll
2012-08-03 16:10 . 2012-08-03 16:10 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll
2012-08-03 16:10 . 2012-08-03 16:10 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-08-03 16:10 . 2012-08-03 16:10 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-08-03 16:10 . 2012-08-03 16:10 81408 ----a-w- c:\windows\system32\imagehlp.dll
2012-08-03 16:10 . 2012-08-03 16:10 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-08-03 16:10 . 2012-08-03 16:10 5120 ----a-w- c:\windows\system32\wmi.dll
2012-08-03 16:10 . 2012-08-03 16:10 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-08-03 16:10 . 2012-08-03 16:10 220672 ----a-w- c:\windows\system32\wintrust.dll
2012-08-03 16:10 . 2012-08-03 16:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-08-03 16:10 . 2012-08-03 16:10 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-08-03 16:09 . 2012-08-03 16:09 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-08-03 16:09 . 2012-08-03 16:09 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-08-03 16:09 . 2012-08-03 16:09 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-08-03 16:09 . 2012-08-03 16:09 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-08-03 16:09 . 2012-08-03 16:09 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-08-03 16:08 . 2012-08-03 16:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-08-03 16:08 . 2012-08-03 16:08 2048 ----a-w- c:\windows\system32\tzres.dll
2012-08-03 16:08 . 2012-08-03 16:08 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-08-03 16:08 . 2012-08-03 16:08 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-08-03 16:08 . 2012-08-03 16:08 826880 ----a-w- c:\windows\SysWow64\rdpcore.dll
2012-08-03 16:08 . 2012-08-03 16:08 23552 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-08-03 16:08 . 2012-08-03 16:08 1031680 ----a-w- c:\windows\system32\rdpcore.dll
2012-08-03 16:08 . 2012-08-03 16:08 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-08-03 16:08 . 2012-08-03 16:08 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-08-03 16:08 . 2012-08-03 16:08 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-08-03 16:07 . 2012-08-03 16:07 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2012-08-03 16:07 . 2012-08-03 16:07 229888 ----a-w- c:\windows\system32\wwansvc.dll
2012-08-03 16:07 . 2012-08-03 16:07 395776 ----a-w- c:\windows\system32\webio.dll
2012-08-03 16:07 . 2012-08-03 16:07 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-08-03 16:07 . 2012-08-03 16:07 31232 ----a-w- c:\windows\system32\lsass.exe
2012-08-03 16:07 . 2012-08-03 16:07 29184 ----a-w- c:\windows\system32\sspisrv.dll
2012-08-03 16:07 . 2012-08-03 16:07 28160 ----a-w- c:\windows\system32\secur32.dll
2012-08-03 16:07 . 2012-08-03 16:07 1447936 ----a-w- c:\windows\system32\lsasrv.dll
2012-08-03 16:07 . 2012-08-03 16:07 136192 ----a-w- c:\windows\system32\sspicli.dll
2012-08-03 16:06 . 2012-08-03 16:06 77312 ----a-w- c:\windows\system32\packager.dll
2012-08-03 16:06 . 2012-08-03 16:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-08-03 16:06 . 2012-08-03 16:06 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-08-03 16:06 . 2012-08-03 16:06 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-08-03 16:06 . 2012-08-03 16:06 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-08-03 16:06 . 2012-08-03 16:06 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-08-03 16:06 . 2012-08-03 16:06 861696 ----a-w- c:\windows\system32\oleaut32.dll
2012-08-03 16:06 . 2012-08-03 16:06 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2012-08-03 16:06 . 2012-08-03 16:06 331776 ----a-w- c:\windows\system32\oleacc.dll
2012-08-03 16:06 . 2012-08-03 16:06 233472 ----a-w- c:\windows\SysWow64\oleacc.dll
2012-08-03 16:06 . 2012-08-03 16:06 163840 ----a-w- c:\windows\system32\umpo.dll
2012-08-03 16:04 . 2012-08-03 16:04 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\qwavedrv.sys.mui
2012-08-03 16:04 . 2012-08-03 16:04 5632 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\ndiscap.sys.mui
2012-08-03 16:04 . 2012-08-03 16:04 2560 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\scfilter.sys.mui
2012-08-03 16:04 . 2012-08-03 16:04 50176 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\tcpip.sys.mui
2012-08-03 16:03 . 2012-08-03 16:03 27136 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\bfe.dll.mui
2012-08-03 16:03 . 2012-08-03 16:03 15360 ----a-w- c:\windows\SysWow64\drivers\cs-CZ\pacer.sys.mui
2012-07-18 18:15 . 2012-09-04 20:00 3148800 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrayStatus"="c:\program files (x86)\TrayStatus\TrayStatus.exe" [2011-05-18 283032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2012-03-06 133400]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-04-13 291608]
"RotateImage"="c:\program files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" [2008-10-30 55808]
"Dolby Advanced Audio v2"="c:\program files (x86)\Dolby Advanced Audio v2\pcee4.exe" [2011-12-21 507744]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2012-05-15 5941344]
"Fastboot"="c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe" [2012-01-17 1091376]
"Intel AppUp(SM) center"="c:\program files (x86)\Intel\IntelAppStore\bin\ismagent.exe" [2012-07-12 155488]
"IntelSBA"="c:\program files (x86)\Intel\Intel(R) Small Business Advantage\Service\SBALaunchDelay.exe" [2012-07-17 55560]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-25 386336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Služba Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 136176]
R2 HyperW7Svc;HyperW7 Service;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe [2012-05-29 144992]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;c:\program files\Intel\WiFi\bin\ZeroConfigService.exe [2012-02-26 2669840]
R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys [2012-01-09 195584]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [2012-03-27 1304912]
R3 cphs;Intel(R) Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-06-25 276288]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-29 136176]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-12-21 34200]
R3 libusb0;libusb-win32 - Kernel Driver 04/08/2011 1.2.4.0;c:\windows\system32\DRIVERS\libusb0.sys [2012-01-16 44480]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2012-02-26 273168]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2012-05-15 1662560]
R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2012-05-15 1665120]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-04 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 Fastboot;Fastboot;c:\windows\System32\DRIVERS\Fastboot.sys [2012-01-17 70416]
S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-04-13 19224]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [2011-12-29 25416]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-09-24 27800]
S1 PHCORE;PHCORE;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS [2012-03-26 33344]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-01-09 659968]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-09-25 84256]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-03-27 1014096]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [2012-03-27 1104208]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-01-17 135952]
S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2010-12-17 198784]
S2 FastbootService;FastbootService;c:\program files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [2012-01-17 169776]
S2 FPLService;TrueSuiteService;c:\program files\Lenovo Fingerprint Reader\TrueSuiteService.exe [2012-06-07 328552]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-03 628448]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-03-06 128280]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-03-06 163608]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2012-06-02 58224]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2012-06-02 61296]
S2 LENOVO.TVTVCAM;ThinkVantage Virtual Camera Controller;c:\program files\Lenovo\Communications Utility\vcamsvc.exe [2012-06-02 179568]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2011-07-12 133992]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe [x]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 145256]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2011-12-29 144960]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-03-06 363800]
S2 VIPAppService;VIPAppService;c:\program files (x86)\Symantec\VIP Access Client\VIPAppService.exe [2012-04-19 84080]
S2 X5XSEx;X5XSEx;c:\program files (x86)\Free Ride Games\X5XSEx.Sys [2010-11-22 55400]
S3 5U877;5U877;c:\windows\system32\DRIVERS\5U877.sys [2012-03-28 216704]
S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys [2012-01-09 195584]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys [2012-02-13 95232]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys [2012-02-13 747008]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys [2012-03-21 60928]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2012-06-21 331264]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-04-13 356632]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-04-13 789272]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-12-21 25496]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2011-11-10 60184]
S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\Netwsw00.sys [2012-02-20 11471872]
S3 RSP2STOR;Realtek PCIE CardReader Driver - P2;c:\windows\system32\DRIVERS\RtsP2Stor.sys [2011-10-27 259688]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352]
S3 SmbDrvIntel;SmbDrvIntel;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys [2012-06-19 27448]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2011-05-29 40248]
S3 tvtvcamd;ThinkVantage Virtual Camera;c:\windows\system32\DRIVERS\tvtvcamd.sys [2011-12-08 27432]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-10-07 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
2012-10-07 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 20:41]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2012-05-14 17:39 463952 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-06-25 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-06-25 398656]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-06-25 440128]
"cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2012-03-01 564352]
"ForteConfig"="c:\program files\Conexant\ForteConfig\fmapp.exe" [2010-10-26 49056]
"SmartAudio"="c:\program files\CONEXANT\SAII\SACpl.exe" [2012-02-21 1654400]
"TpShocks"="TpShocks.exe" [2012-02-25 382528]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2012-06-02 290160]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: WikiKomentáře Google... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files (x86)\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 62.129.50.20 85.135.32.100
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fastboot]
"ImagePath"=multi:"System32\DRIVERS\Fastboot.sys\00"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Fastboot]
"ImagePath"=multi:"System32\DRIVERS\Fastboot.sys\00"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\SysWOW64\SAsrv.exe
c:\progra~1\Lenovo\HOTKEY\TPONSCR.EXE
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\Lenovo\System Update\SUService.exe
c:\program files (x86)\Lenovo\message center plus\mcplaunch.exe
c:\program files\lenovo\lenovo solution center\lsc.exe
.
**************************************************************************
.
Celkový čas: 2012-10-07 19:13:13 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-10-07 17:13
ComboFix2.txt 2012-10-07 12:22
.
Před spuštěním: Volných bajtů: 425 783 193 600
Po spuštění: Volných bajtů: 425 732 026 368
.
- - End Of File - - 28E9CC33EB4B2AE2646C0BC929D6E94D
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@=
Naposledy upravil(a) Moody.01 dne 07 říj 2012 18:56, celkem upraveno 2 x.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu a pomoc s Avirou

#9 Příspěvek od Rudy »

OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Re: Prosím o kontrolu logu a pomoc s Avirou

#10 Příspěvek od Moody.01 »

Restart pomohl. :happy:
Log jsem vložila do předchozího příspěvku.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu a pomoc s Avirou

#11 Příspěvek od Rudy »

Log již vypadá čistý. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Moody.01
Návštěvník
Návštěvník
Příspěvky: 139
Registrován: 20 dub 2009 19:13

Re: Prosím o kontrolu logu a pomoc s Avirou

#12 Příspěvek od Moody.01 »

Avira už nehlásí žádný problém s žádným souborem, takže už bude asi všechno v pořádku :)
Děkuju Vás moc za pomoc. Netušila jsem, že to povede k vyřešení celého problému s oddílem Q a vytvoření zálohy, s tím si nevěděl rady ani technik. Ještě jednou velké díky :worship:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu a pomoc s Avirou

#13 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno