zavirovane pc
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
zavirovane pc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Daffoza at 2012-12-29 21:25:07
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 94 GB (38%) free of 250 GB
Total RAM: 16329 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:10, on 29.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files (x86)\steam\steam.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Daffoza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.cloyim.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
O4 - HKLM\..\Run: [ghost] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [win32] "C:\kernels\drivers.vbs"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKCU\..\Run: [Praetorian] C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASDiskUnlocker - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVELO Dataplex Service (nveloSvc) - Unknown owner - C:\Windows\system32\Dataplex\nveloSvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12314 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe"
"C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {8497AA2B-9F98-4310-9FE4-FBB1EAEB56B0}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
"C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe" -Init
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\steam\steam.exe" "steam://rungameid/42690"
"C:\Program Files (x86)\uTorrent\uTorrent.exe" "C:\Users\Daffoza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R0RRO0Z3\torrentdownloads net Doblba!!!(cz) cip avi.torrent"
"C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6332.2.497742768\541783985" --gpu-vendor-id=0x10de --gpu-device-id=0x1080 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.697 --ignored=" --type=renderer " /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --extension-process --renderer-print-preview --channel="6332.3.1067490189\3612399" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6332.5.702722703\1487027833" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.6.623661733\1480877664" /prefetch:3
"C:\Program Files (x86)\Java\jre7\bin\javaw.exe" -jar -Xmx512m JDownloader.jar -rfu
"C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Winamp\winamp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service --lang=cs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi-broker --channel="6332.61.428214925\262113616" --lang=cs /prefetch:14
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.77.1350594967\614582709" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.80.94961694\1616291165" /prefetch:3
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.82.316539001\1901053276" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.85.1981119174\1581182093" /prefetch:3
"C:\Users\Daffoza\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe62_ Global\UsGthrCtrlFltPipeMssGthrPipe62 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 536 540 548 65536 544
"C:\Users\Daffoza\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
prefs.js - "browser.startup.homepage" - "http://home.cloyim.com/"
prefs.js - "keyword.URL" - "http://home.cloyim.com/search.php?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
npwachk.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
Search the web.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\
plugin@yontoo.com
vb@yandex.ru
yasearch@yandex.ru
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\
firmy.cz-043339.xml
gorsel.yandex.com.tr-045337.xml
haber.yandex.com.tr-045337.xml
mapy.cz-043338.xml
seznam.cz-043338.xml
videa.seznam.cz-043339.xml
video.yandex.com.tr-045337.xml
yandex.com.tr-045337.xml
yqs-barff-yagorsel.xml
yqs-barff-yahaber.xml
yqs-barff-yandex.xml
yqs-barff-yavideo.xml
zbozi.cz-043338.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-11-11 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-11-11 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files (x86)\Yontoo\YontooIEClient.dll [2012-10-24 194928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-10-23 6842512]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Praetorian"=C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe []
""= []
"Google Update"=C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-24 116648]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe [2009-12-16 312640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker]
C:\Program Files (x86)\SiteRanker\SiteRankTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"ASUS AiChargerPlus Execute"=C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [2010-11-08 465536]
"ghost"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe [2010-02-08 192000]
"Tilt"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe [2011-04-20 729088]
"CTxfiHlp"=CTXFIHLP.EXE []
"ROC_roc_ssl_v12"=C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe / /PROMPT /CMPID=roc_ssl_v12 []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"googletalk"=C:\Program Files (x86)\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Driver Genius"= []
"win32"=C:\kernels\drivers.vbs [2012-11-29 474]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-03-22 74752]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"RemoteControl11"=C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
C:\Users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
uTorrent Turbo Booster.lnk - C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-12-29 21:22:29 ----D---- C:\rsit
2012-12-29 21:22:29 ----D---- C:\Program Files\trend micro
2012-12-29 06:00:11 ----D---- C:\Users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 05:56:08 ----D---- C:\ProgramData\PDVD
2012-12-29 05:55:51 ----D---- C:\ProgramData\CyberLink
2012-12-29 05:54:10 ----D---- C:\Program Files (x86)\CyberLink
2012-12-29 05:53:45 ----D---- C:\ProgramData\Temp
2012-12-29 05:53:45 ----D---- C:\ProgramData\install_clap
2012-12-29 01:15:06 ----D---- C:\Program Files (x86)\AVSociety
2012-12-29 00:46:30 ----A---- C:\Windows\d3dx.dat
2012-12-29 00:11:59 ----D---- C:\Users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 05:36:33 ----D---- C:\Program Files (x86)\Morphyre
2012-12-25 23:22:06 ----A---- C:\Windows\system32\drivers\aswFW.sys
2012-12-25 23:21:51 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswNdis.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2012-12-22 03:32:41 ----D---- C:\Users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nveloportfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelofsfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelodiskfltr.sys
2012-12-19 00:13:42 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-12-19 00:13:30 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2012-12-18 00:12:58 ----D---- C:\Program Files (x86)\7-Zip
2012-12-17 23:42:12 ----D---- C:\Program Files\OCZ Technology Group
2012-12-17 01:54:13 ----D---- C:\Program Files (x86)\Yontoo
2012-12-17 01:54:11 ----D---- C:\ProgramData\Tarma Installer
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\avastSS.scr
2012-12-17 01:14:44 ----D---- C:\ProgramData\AVAST Software
2012-12-17 01:14:44 ----D---- C:\Program Files\AVAST Software
2012-12-12 04:41:08 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-12-12 03:38:25 ----A---- C:\Windows\Dataplex.ini
2012-12-12 03:23:24 ----SHD---- C:\Config.Msi
2012-12-11 19:11:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-12-11 19:11:45 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-12-11 01:40:02 ----D---- C:\Program Files\Logitech
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files\Logitech
2012-12-08 21:56:05 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 21:55:58 ----D---- C:\Users\Daffoza\AppData\Roaming\Party
2012-12-08 21:55:43 ----D---- C:\Programs
2012-12-04 21:56:03 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-04 21:53:36 ----D---- C:\ProgramData\Orbit
2012-12-04 21:52:02 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-04 21:52:00 ----D---- C:\Program Files (x86)\Ubisoft
2012-12-04 21:36:19 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-12-04 20:20:12 ----D---- C:\Program Files (x86)\JDownloader
2012-12-04 19:39:26 ----D---- C:\ProgramData\Dr Glitter
2012-12-04 19:39:26 ----D---- C:\Program Files (x86)\Dr Glitter
2012-12-04 19:33:08 ----D---- C:\Program Files (x86)\Winamp Detect
2012-12-04 19:33:04 ----D---- C:\Users\Daffoza\AppData\Roaming\Winamp
2012-12-04 19:33:04 ----D---- C:\Program Files (x86)\Winamp
2012-12-04 19:22:17 ----D---- C:\ProgramData\Mozilla
2012-12-04 19:22:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-04 19:22:16 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-12-02 14:37:05 ----SHD---- C:\Windows\SYSWOW64\%APPDATA%
2012-12-02 13:39:29 ----D---- C:\Windows\KJ
======List of files/folders modified in the last 1 month======
2012-12-29 21:23:10 ----D---- C:\Users\Daffoza\AppData\Roaming\uTorrent
2012-12-29 21:22:29 ----RD---- C:\Program Files
2012-12-29 21:11:18 ----D---- C:\Windows\Temp
2012-12-29 17:50:17 ----HD---- C:\ProgramData
2012-12-29 17:50:17 ----D---- C:\Program Files (x86)\Google
2012-12-29 17:50:15 ----SHD---- C:\Windows\Installer
2012-12-29 17:49:54 ----RD---- C:\Program Files (x86)
2012-12-29 06:05:03 ----D---- C:\Windows\system32\config
2012-12-29 06:04:59 ----D---- C:\Windows\winsxs
2012-12-29 05:56:10 ----D---- C:\Windows\system32\Tasks
2012-12-29 05:56:07 ----D---- C:\Windows\system32\catroot
2012-12-29 05:53:45 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-29 05:53:39 ----SHD---- C:\System Volume Information
2012-12-29 01:35:24 ----D---- C:\Program Files (x86)\steam
2012-12-29 00:46:30 ----D---- C:\Windows
2012-12-26 13:49:59 ----SD---- C:\ProgramData\Microsoft
2012-12-26 13:47:27 ----D---- C:\ProgramData\NVIDIA
2012-12-25 23:22:06 ----D---- C:\Windows\system32\drivers
2012-12-25 23:22:00 ----D---- C:\Windows\inf
2012-12-25 23:21:57 ----D---- C:\Windows\system32\DriverStore
2012-12-22 19:05:29 ----D---- C:\Windows\System32
2012-12-22 14:21:47 ----D---- C:\Program Files (x86)\uTorrent
2012-12-22 04:33:22 ----D---- C:\Users\Daffoza\AppData\Roaming\vlc
2012-12-22 03:37:32 ----DC---- C:\Windows\system32\DRVSTORE
2012-12-22 03:35:13 ----D---- C:\Users\Daffoza\AppData\Roaming\YoWindow
2012-12-22 01:12:26 ----D---- C:\Windows\system32\NDF
2012-12-19 02:26:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-19 00:20:39 ----D---- C:\Users\Daffoza\AppData\Roaming\DAEMON Tools Pro
2012-12-19 00:19:09 ----D---- C:\Windows\system32\catroot2
2012-12-18 00:08:15 ----D---- C:\Windows\system32\wbem
2012-12-18 00:07:10 ----D---- C:\Windows\registration
2012-12-17 06:39:31 ----D---- C:\Users\Daffoza\AppData\Roaming\BitTorrent
2012-12-17 01:15:06 ----D---- C:\Windows\SysWOW64
2012-12-13 02:41:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-12 03:33:44 ----D---- C:\Windows\Tasks
2012-12-11 19:15:55 ----RSD---- C:\Windows\assembly
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files
2012-12-10 21:24:02 ----D---- C:\Windows\LiveKernelReports
2012-12-07 00:13:02 ----SHD---- C:\$Recycle.Bin
2012-12-07 00:12:59 ----RD---- C:\Users
2012-12-05 07:54:59 ----D---- C:\Users\Daffoza\AppData\Roaming\Yandex
2012-12-04 21:52:02 ----D---- C:\Windows\system32\LogFiles
2012-12-04 19:40:02 ----D---- C:\Users\Daffoza\AppData\Roaming\NVIDIA
2012-12-04 19:33:06 ----D---- C:\Program Files (x86)\Common Files
2012-12-04 19:23:58 ----SD---- C:\Users\Daffoza\AppData\Roaming\Microsoft
2012-12-04 19:22:19 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla
2012-12-04 16:55:18 ----D---- C:\Program Files (x86)\Opera
2012-12-02 13:09:45 ----D---- C:\Program Files (x86)\ASUS
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AiChargerPlus;ASUS Charger Plus Driver; C:\Windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-10-30 262656]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-31 120920]
R0 nvelodiskfltr;NVCache Policy Driver; C:\Windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
R0 nveloportfltr;NVELO Port Filter Driver; C:\Windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
R0 ocz12xx;ocz12xx; C:\Windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-12-19 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2010-08-24 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2010-08-03 14464]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-10-30 132864]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-30 21136]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 VDiskBus;ASUS Disk Unlocker; C:\Windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
R3 ASFLTDrv.sys;ASFLTDrv.sys; \??\C:\Program Files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver; C:\Windows\system32\DRIVERS\nvstusb.sys [2012-10-03 445800]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
S0 nvelofsfltr;nvelofsfltr; C:\Windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 CT20XUT.SYS;CT20XUT.SYS; C:\Windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 CT20XUT;CT20XUT; C:\Windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2010-07-07 580696]
S3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2010-07-07 697816]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\Windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTEXFIFX;CTEXFIFX; C:\Windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTHWIUT.SYS;CTHWIUT.SYS; C:\Windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 CTHWIUT;CTHWIUT; C:\Windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2010-07-07 15960]
S3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2010-07-07 213080]
S3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2010-07-07 118360]
S3 ha20x22k;Creative 20X2 HAL Driver; C:\Windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
S3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2010-07-07 1567832]
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
S3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2010-07-07 179288]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2012-10-28 31232]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
R2 ASDiskUnlocker;ASDiskUnlocker; C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-04 76888]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S2 nveloSvc;NVELO Dataplex Service; C:\Windows\system32\Dataplex\nveloSvc.exe []
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-13 250808]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-29 115168]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Daffoza at 2012-12-29 21:25:07
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 94 GB (38%) free of 250 GB
Total RAM: 16329 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:10, on 29.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files (x86)\steam\steam.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Daffoza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.cloyim.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
O4 - HKLM\..\Run: [ghost] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [win32] "C:\kernels\drivers.vbs"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKCU\..\Run: [Praetorian] C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASDiskUnlocker - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVELO Dataplex Service (nveloSvc) - Unknown owner - C:\Windows\system32\Dataplex\nveloSvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12314 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe"
"C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {8497AA2B-9F98-4310-9FE4-FBB1EAEB56B0}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
"C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe" -Init
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\steam\steam.exe" "steam://rungameid/42690"
"C:\Program Files (x86)\uTorrent\uTorrent.exe" "C:\Users\Daffoza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R0RRO0Z3\torrentdownloads net Doblba!!!(cz) cip avi.torrent"
"C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6332.2.497742768\541783985" --gpu-vendor-id=0x10de --gpu-device-id=0x1080 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.697 --ignored=" --type=renderer " /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --extension-process --renderer-print-preview --channel="6332.3.1067490189\3612399" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6332.5.702722703\1487027833" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.6.623661733\1480877664" /prefetch:3
"C:\Program Files (x86)\Java\jre7\bin\javaw.exe" -jar -Xmx512m JDownloader.jar -rfu
"C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Winamp\winamp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service --lang=cs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi-broker --channel="6332.61.428214925\262113616" --lang=cs /prefetch:14
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.77.1350594967\614582709" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.80.94961694\1616291165" /prefetch:3
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.82.316539001\1901053276" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.85.1981119174\1581182093" /prefetch:3
"C:\Users\Daffoza\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe62_ Global\UsGthrCtrlFltPipeMssGthrPipe62 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 536 540 548 65536 544
"C:\Users\Daffoza\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
prefs.js - "browser.startup.homepage" - "http://home.cloyim.com/"
prefs.js - "keyword.URL" - "http://home.cloyim.com/search.php?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
npwachk.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
Search the web.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\
plugin@yontoo.com
vb@yandex.ru
yasearch@yandex.ru
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\
firmy.cz-043339.xml
gorsel.yandex.com.tr-045337.xml
haber.yandex.com.tr-045337.xml
mapy.cz-043338.xml
seznam.cz-043338.xml
videa.seznam.cz-043339.xml
video.yandex.com.tr-045337.xml
yandex.com.tr-045337.xml
yqs-barff-yagorsel.xml
yqs-barff-yahaber.xml
yqs-barff-yandex.xml
yqs-barff-yavideo.xml
zbozi.cz-043338.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-11-11 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-11-11 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files (x86)\Yontoo\YontooIEClient.dll [2012-10-24 194928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-10-23 6842512]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Praetorian"=C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe []
""= []
"Google Update"=C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-24 116648]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe [2009-12-16 312640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker]
C:\Program Files (x86)\SiteRanker\SiteRankTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"ASUS AiChargerPlus Execute"=C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [2010-11-08 465536]
"ghost"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe [2010-02-08 192000]
"Tilt"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe [2011-04-20 729088]
"CTxfiHlp"=CTXFIHLP.EXE []
"ROC_roc_ssl_v12"=C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe / /PROMPT /CMPID=roc_ssl_v12 []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"googletalk"=C:\Program Files (x86)\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Driver Genius"= []
"win32"=C:\kernels\drivers.vbs [2012-11-29 474]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-03-22 74752]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"RemoteControl11"=C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
C:\Users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
uTorrent Turbo Booster.lnk - C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-12-29 21:22:29 ----D---- C:\rsit
2012-12-29 21:22:29 ----D---- C:\Program Files\trend micro
2012-12-29 06:00:11 ----D---- C:\Users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 05:56:08 ----D---- C:\ProgramData\PDVD
2012-12-29 05:55:51 ----D---- C:\ProgramData\CyberLink
2012-12-29 05:54:10 ----D---- C:\Program Files (x86)\CyberLink
2012-12-29 05:53:45 ----D---- C:\ProgramData\Temp
2012-12-29 05:53:45 ----D---- C:\ProgramData\install_clap
2012-12-29 01:15:06 ----D---- C:\Program Files (x86)\AVSociety
2012-12-29 00:46:30 ----A---- C:\Windows\d3dx.dat
2012-12-29 00:11:59 ----D---- C:\Users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 05:36:33 ----D---- C:\Program Files (x86)\Morphyre
2012-12-25 23:22:06 ----A---- C:\Windows\system32\drivers\aswFW.sys
2012-12-25 23:21:51 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswNdis.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2012-12-22 03:32:41 ----D---- C:\Users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nveloportfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelofsfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelodiskfltr.sys
2012-12-19 00:13:42 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-12-19 00:13:30 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2012-12-18 00:12:58 ----D---- C:\Program Files (x86)\7-Zip
2012-12-17 23:42:12 ----D---- C:\Program Files\OCZ Technology Group
2012-12-17 01:54:13 ----D---- C:\Program Files (x86)\Yontoo
2012-12-17 01:54:11 ----D---- C:\ProgramData\Tarma Installer
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\avastSS.scr
2012-12-17 01:14:44 ----D---- C:\ProgramData\AVAST Software
2012-12-17 01:14:44 ----D---- C:\Program Files\AVAST Software
2012-12-12 04:41:08 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-12-12 03:38:25 ----A---- C:\Windows\Dataplex.ini
2012-12-12 03:23:24 ----SHD---- C:\Config.Msi
2012-12-11 19:11:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-12-11 19:11:45 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-12-11 01:40:02 ----D---- C:\Program Files\Logitech
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files\Logitech
2012-12-08 21:56:05 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 21:55:58 ----D---- C:\Users\Daffoza\AppData\Roaming\Party
2012-12-08 21:55:43 ----D---- C:\Programs
2012-12-04 21:56:03 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-04 21:53:36 ----D---- C:\ProgramData\Orbit
2012-12-04 21:52:02 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-04 21:52:00 ----D---- C:\Program Files (x86)\Ubisoft
2012-12-04 21:36:19 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-12-04 20:20:12 ----D---- C:\Program Files (x86)\JDownloader
2012-12-04 19:39:26 ----D---- C:\ProgramData\Dr Glitter
2012-12-04 19:39:26 ----D---- C:\Program Files (x86)\Dr Glitter
2012-12-04 19:33:08 ----D---- C:\Program Files (x86)\Winamp Detect
2012-12-04 19:33:04 ----D---- C:\Users\Daffoza\AppData\Roaming\Winamp
2012-12-04 19:33:04 ----D---- C:\Program Files (x86)\Winamp
2012-12-04 19:22:17 ----D---- C:\ProgramData\Mozilla
2012-12-04 19:22:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-04 19:22:16 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-12-02 14:37:05 ----SHD---- C:\Windows\SYSWOW64\%APPDATA%
2012-12-02 13:39:29 ----D---- C:\Windows\KJ
======List of files/folders modified in the last 1 month======
2012-12-29 21:23:10 ----D---- C:\Users\Daffoza\AppData\Roaming\uTorrent
2012-12-29 21:22:29 ----RD---- C:\Program Files
2012-12-29 21:11:18 ----D---- C:\Windows\Temp
2012-12-29 17:50:17 ----HD---- C:\ProgramData
2012-12-29 17:50:17 ----D---- C:\Program Files (x86)\Google
2012-12-29 17:50:15 ----SHD---- C:\Windows\Installer
2012-12-29 17:49:54 ----RD---- C:\Program Files (x86)
2012-12-29 06:05:03 ----D---- C:\Windows\system32\config
2012-12-29 06:04:59 ----D---- C:\Windows\winsxs
2012-12-29 05:56:10 ----D---- C:\Windows\system32\Tasks
2012-12-29 05:56:07 ----D---- C:\Windows\system32\catroot
2012-12-29 05:53:45 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-29 05:53:39 ----SHD---- C:\System Volume Information
2012-12-29 01:35:24 ----D---- C:\Program Files (x86)\steam
2012-12-29 00:46:30 ----D---- C:\Windows
2012-12-26 13:49:59 ----SD---- C:\ProgramData\Microsoft
2012-12-26 13:47:27 ----D---- C:\ProgramData\NVIDIA
2012-12-25 23:22:06 ----D---- C:\Windows\system32\drivers
2012-12-25 23:22:00 ----D---- C:\Windows\inf
2012-12-25 23:21:57 ----D---- C:\Windows\system32\DriverStore
2012-12-22 19:05:29 ----D---- C:\Windows\System32
2012-12-22 14:21:47 ----D---- C:\Program Files (x86)\uTorrent
2012-12-22 04:33:22 ----D---- C:\Users\Daffoza\AppData\Roaming\vlc
2012-12-22 03:37:32 ----DC---- C:\Windows\system32\DRVSTORE
2012-12-22 03:35:13 ----D---- C:\Users\Daffoza\AppData\Roaming\YoWindow
2012-12-22 01:12:26 ----D---- C:\Windows\system32\NDF
2012-12-19 02:26:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-19 00:20:39 ----D---- C:\Users\Daffoza\AppData\Roaming\DAEMON Tools Pro
2012-12-19 00:19:09 ----D---- C:\Windows\system32\catroot2
2012-12-18 00:08:15 ----D---- C:\Windows\system32\wbem
2012-12-18 00:07:10 ----D---- C:\Windows\registration
2012-12-17 06:39:31 ----D---- C:\Users\Daffoza\AppData\Roaming\BitTorrent
2012-12-17 01:15:06 ----D---- C:\Windows\SysWOW64
2012-12-13 02:41:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-12 03:33:44 ----D---- C:\Windows\Tasks
2012-12-11 19:15:55 ----RSD---- C:\Windows\assembly
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files
2012-12-10 21:24:02 ----D---- C:\Windows\LiveKernelReports
2012-12-07 00:13:02 ----SHD---- C:\$Recycle.Bin
2012-12-07 00:12:59 ----RD---- C:\Users
2012-12-05 07:54:59 ----D---- C:\Users\Daffoza\AppData\Roaming\Yandex
2012-12-04 21:52:02 ----D---- C:\Windows\system32\LogFiles
2012-12-04 19:40:02 ----D---- C:\Users\Daffoza\AppData\Roaming\NVIDIA
2012-12-04 19:33:06 ----D---- C:\Program Files (x86)\Common Files
2012-12-04 19:23:58 ----SD---- C:\Users\Daffoza\AppData\Roaming\Microsoft
2012-12-04 19:22:19 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla
2012-12-04 16:55:18 ----D---- C:\Program Files (x86)\Opera
2012-12-02 13:09:45 ----D---- C:\Program Files (x86)\ASUS
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AiChargerPlus;ASUS Charger Plus Driver; C:\Windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-10-30 262656]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-31 120920]
R0 nvelodiskfltr;NVCache Policy Driver; C:\Windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
R0 nveloportfltr;NVELO Port Filter Driver; C:\Windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
R0 ocz12xx;ocz12xx; C:\Windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-12-19 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2010-08-24 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2010-08-03 14464]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-10-30 132864]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-30 21136]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 VDiskBus;ASUS Disk Unlocker; C:\Windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
R3 ASFLTDrv.sys;ASFLTDrv.sys; \??\C:\Program Files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver; C:\Windows\system32\DRIVERS\nvstusb.sys [2012-10-03 445800]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
S0 nvelofsfltr;nvelofsfltr; C:\Windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 CT20XUT.SYS;CT20XUT.SYS; C:\Windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 CT20XUT;CT20XUT; C:\Windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2010-07-07 580696]
S3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2010-07-07 697816]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\Windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTEXFIFX;CTEXFIFX; C:\Windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTHWIUT.SYS;CTHWIUT.SYS; C:\Windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 CTHWIUT;CTHWIUT; C:\Windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2010-07-07 15960]
S3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2010-07-07 213080]
S3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2010-07-07 118360]
S3 ha20x22k;Creative 20X2 HAL Driver; C:\Windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
S3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2010-07-07 1567832]
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
S3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2010-07-07 179288]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2012-10-28 31232]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
R2 ASDiskUnlocker;ASDiskUnlocker; C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-04 76888]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S2 nveloSvc;NVELO Dataplex Service; C:\Windows\system32\Dataplex\nveloSvc.exe []
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-13 250808]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-29 115168]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: zavirovane pc
Zdravim
Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Pokud ho havet blokuje, pouzijte jeden z nasledujicich - i ty prejmenovane
Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill iExplore.exe:
http://download.bleepingcomputer.com/gr ... xplore.exe
Rkill uSeRiNiT.exe:
http://download.bleepingcomputer.com/gr ... eRiNiT.exe
Rkill WiNlOgOn.exe:
http://download.bleepingcomputer.com/gr ... NlOgOn.exe - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne do par sekund a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Na plose vznikne log Rkill.txt ten mi sem vlozte
- Ted nerestartujte PC - prisli byste o ucinek RKillu
- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: zavirovane pc
Rkill 2.4.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/31/2012 12:54:51 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 960) [WD-HEUR]
1 proccess terminated!
Possibly Patched Files.
* C:\Windows\system32\services.exe
Checking Registry for malware related settings:
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\Daffoza\Desktop\rkill\rkill-12-31-2012-12-55-29.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* C:\Windows\assembly\GAC_32\Desktop.ini [ZA File]
* C:\Windows\assembly\GAC_64\Desktop.ini [ZA File]
Checking Windows Service Integrity:
* Ovladač ověření brány Windows Firewall (mpsdrv) is not Running.
Startup Type set to: Manual
* BFE [Missing Service]
* BITS [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]
* wuauserv [Missing Service]
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* C:\Windows\System32\services.exe [NoSig]
+-> C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe : 328 704 : 07/14/2009 00:39 AM : 24acb7e5be595468e3b9aa488b9b4fcb [Pos Repl]
Checking HOSTS File:
* No issues found.
Program finished at: 12/31/2012 12:56:05 PM
Execution time: 0 hours(s), 1 minute(s), and 13 seconds(s)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/31/2012 12:54:51 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 960) [WD-HEUR]
1 proccess terminated!
Possibly Patched Files.
* C:\Windows\system32\services.exe
Checking Registry for malware related settings:
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\Daffoza\Desktop\rkill\rkill-12-31-2012-12-55-29.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* C:\Windows\assembly\GAC_32\Desktop.ini [ZA File]
* C:\Windows\assembly\GAC_64\Desktop.ini [ZA File]
Checking Windows Service Integrity:
* Ovladač ověření brány Windows Firewall (mpsdrv) is not Running.
Startup Type set to: Manual
* BFE [Missing Service]
* BITS [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]
* wuauserv [Missing Service]
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* C:\Windows\System32\services.exe [NoSig]
+-> C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe : 328 704 : 07/14/2009 00:39 AM : 24acb7e5be595468e3b9aa488b9b4fcb [Pos Repl]
Checking HOSTS File:
* No issues found.
Program finished at: 12/31/2012 12:56:05 PM
Execution time: 0 hours(s), 1 minute(s), and 13 seconds(s)
Re: zavirovane pc
Fajn, ComboFix by byl

Re: zavirovane pc
ComboFix 12-12-31.01 - Daffoza 31.12.2012 13:16:30.1.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.14342 [GMT 1:00]
Spuštěný z: c:\users\Daffoza\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1028.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1031.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1033.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1036.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1041.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\2052.msi
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\201d3dde
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\4cce1f70
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\76603ac3
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000008.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\000000cb.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\80000000.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz102F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz104F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10C4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10EC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1190.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz121B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz12CB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz158B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz15EA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1837.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1848.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A2F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A4F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FEE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz209F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz20FE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz22DB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz230C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz2FC6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3086.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3096.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz33DD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3770.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz38C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3AE1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3CB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D72.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D73.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3FB2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz40E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4173.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz43A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4691.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz47AB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4919.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4C45.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4EFD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F5B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F8B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51A6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51D6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55D0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55E1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz57EF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz58F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6092.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz60A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz64AD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz65A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6628.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz67DE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz687F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6880.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz69D2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A00.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A21.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6C1E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6F07.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7005.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz707F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz708F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7194.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz71D4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz741.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7698.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7744.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7805.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz79FD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7A4C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7E2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7F70.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8078.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz807B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8098.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8210.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz82FC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz85D5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz866F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8766.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8786.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz890.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8E15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8FFA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9097.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90B6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90E6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz93CD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz940D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9459.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9518.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz95F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz98F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA368.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA3C7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA81E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA91F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA96E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzABC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC67.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC7F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzACED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD42.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD5F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzADAE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB400.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB474.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB8C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBB51.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBC75.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBD8F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBF1A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC1B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC24D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC3F1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC8FA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzCD39.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD258.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD953.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD9F0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzDB37.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE3C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE4E3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE6EE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE7BF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE94F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE9F8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEA57.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBBF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEE6E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEF7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF033.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF246.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF424.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF444.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF479.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4D9.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF7B5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFA90.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFAD0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFC06.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFCD2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFFAA.tmp
.
Nakažená kopie c:\windows\system32\services.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-28 do 2012-12-31 )))))))))))))))))))))))))))))))
.
.
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2012-12-29 04:56 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:22 . 2012-10-30 22:51 132864 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-12-25 22:21 . 2012-10-30 22:51 262656 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-25 22:21 . 2012-09-21 09:26 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
2012-12-12 03:41 . 2012-12-13 01:41 16363960 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-12-11 18:16 . 2012-12-11 18:16 -------- d-----w- c:\users\Daffoza\AppData\Local\Activision
2012-12-11 18:11 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-12-11 18:11 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Logitech
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Common Files\Logitech
2012-12-08 20:56 . 2012-12-08 20:56 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Party
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- C:\Programs
2012-12-06 23:12 . 2012-12-17 23:07 -------- d-----w- c:\users\Administrator
2012-12-04 20:56 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-04 20:56 . 2012-12-12 03:04 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:55 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-04 20:55 . 2012-12-04 20:55 -------- d-----w- c:\users\Daffoza\AppData\Local\PunkBuster
2012-12-04 20:53 . 2012-12-04 20:53 -------- d-----w- c:\programdata\Orbit
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\users\Daffoza\AppData\Local\Ubisoft Game Launcher
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\program files (x86)\Ubisoft
2012-12-04 20:36 . 2012-12-04 20:36 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-12-04 19:20 . 2012-12-29 04:46 -------- d-----w- c:\program files (x86)\JDownloader
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\programdata\Dr Glitter
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\program files (x86)\Dr Glitter
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Winamp Detect
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2012-12-04 18:33 . 2012-12-29 00:35 -------- d-----w- c:\program files (x86)\Winamp
2012-12-04 18:33 . 2012-12-04 18:46 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Winamp
2012-12-04 18:23 . 2012-12-04 18:23 -------- d-----w- c:\users\Daffoza\AppData\Local\Macromedia
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Mozilla
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-12-02 13:37 . 2012-12-02 13:37 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-12-02 12:39 . 2012-12-22 22:27 -------- d-----w- c:\windows\KJ
2012-12-02 11:31 . 2012-12-22 22:22 -------- d-----w- c:\users\Daffoza\temp
2012-12-02 10:56 . 2012-12-03 23:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Deployment
2012-12-02 10:56 . 2012-12-02 10:56 -------- d-----w- c:\users\Daffoza\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-29 23:14 . 2012-10-30 02:05 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-29 23:14 . 2012-10-30 02:05 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-15 08:35 . 2012-10-24 18:03 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-10-17 00:31 . 2012-11-29 04:35 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EE1F503-E65A-4AB3-A956-E2A9330096AE}\mpengine.dll
2012-10-09 18:17 . 2012-11-15 08:34 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-15 08:34 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-15 08:34 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-15 08:34 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-09 16:16 . 2012-11-15 04:17 2700896 ----a-w- c:\windows\system32\FMAPO64.dll
2012-10-08 16:40 . 2012-11-15 04:17 3671184 ----a-w- c:\windows\system32\RtkAPO64.dll
2012-10-08 12:19 . 2012-11-15 08:38 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-10-08 11:42 . 2012-11-15 08:38 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-10-08 11:31 . 2012-11-15 08:38 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 11:24 . 2012-11-15 08:38 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-10-08 11:23 . 2012-11-15 08:38 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 11:22 . 2012-11-15 08:38 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 11:22 . 2012-11-15 08:38 237056 ----a-w- c:\windows\system32\url.dll
2012-10-08 11:20 . 2012-11-15 08:38 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-10-08 11:18 . 2012-11-15 08:38 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 11:17 . 2012-11-15 08:38 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 11:17 . 2012-11-15 08:38 816640 ----a-w- c:\windows\system32\jscript.dll
2012-10-08 11:15 . 2012-11-15 08:38 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-10-08 11:15 . 2012-11-15 08:38 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-10-08 11:13 . 2012-11-15 08:38 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-10-08 11:13 . 2012-11-15 08:38 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-08 11:09 . 2012-11-15 08:38 248320 ----a-w- c:\windows\system32\ieui.dll
2012-10-08 07:56 . 2012-11-15 08:38 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-10-08 07:48 . 2012-11-15 08:38 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-10-08 07:47 . 2012-11-15 08:38 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTProAgent.exe" [2009-12-16 312640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"win32"="c:\kernels\drivers.vbs" [2012-11-29 474]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-03-22 74752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"RemoteControl11"="c:\program files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe" [2011-04-20 234792]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 23:14]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/webhp?sourceid=toolbar-in ... CZ507CZ508
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: browser.startup.homepage - hxxp://home.cloyim.com/
FF - prefs.js: keyword.URL - hxxp://home.cloyim.com/search.php?q=
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-Praetorian - c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe
Wow6432Node-HKLM-Run-Driver Genius - (no file)
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2012-12-31 13:49:35 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 97 426 436 096
Po spuštění: Volných bajtů: 97 401 065 472
.
- - End Of File - - A6FBCD824191A1561C4510792A8D2DBA
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.14342 [GMT 1:00]
Spuštěný z: c:\users\Daffoza\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1028.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1031.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1033.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1036.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1041.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\2052.msi
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\201d3dde
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\4cce1f70
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\76603ac3
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000008.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\000000cb.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\80000000.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz102F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz104F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10C4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10EC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1190.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz121B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz12CB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz158B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz15EA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1837.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1848.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A2F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A4F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FEE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz209F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz20FE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz22DB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz230C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz2FC6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3086.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3096.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz33DD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3770.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz38C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3AE1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3CB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D72.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D73.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3FB2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz40E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4173.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz43A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4691.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz47AB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4919.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4C45.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4EFD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F5B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F8B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51A6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51D6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55D0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55E1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz57EF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz58F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6092.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz60A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz64AD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz65A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6628.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz67DE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz687F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6880.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz69D2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A00.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A21.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6C1E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6F07.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7005.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz707F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz708F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7194.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz71D4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz741.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7698.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7744.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7805.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz79FD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7A4C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7E2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7F70.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8078.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz807B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8098.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8210.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz82FC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz85D5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz866F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8766.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8786.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz890.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8E15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8FFA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9097.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90B6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90E6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz93CD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz940D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9459.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9518.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz95F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz98F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA368.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA3C7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA81E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA91F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA96E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzABC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC67.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC7F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzACED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD42.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD5F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzADAE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB400.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB474.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB8C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBB51.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBC75.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBD8F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBF1A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC1B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC24D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC3F1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC8FA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzCD39.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD258.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD953.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD9F0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzDB37.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE3C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE4E3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE6EE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE7BF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE94F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE9F8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEA57.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBBF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEE6E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEF7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF033.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF246.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF424.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF444.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF479.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4D9.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF7B5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFA90.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFAD0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFC06.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFCD2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFFAA.tmp
.
Nakažená kopie c:\windows\system32\services.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-28 do 2012-12-31 )))))))))))))))))))))))))))))))
.
.
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2012-12-29 04:56 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:22 . 2012-10-30 22:51 132864 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-12-25 22:21 . 2012-10-30 22:51 262656 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-25 22:21 . 2012-09-21 09:26 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
2012-12-12 03:41 . 2012-12-13 01:41 16363960 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-12-11 18:16 . 2012-12-11 18:16 -------- d-----w- c:\users\Daffoza\AppData\Local\Activision
2012-12-11 18:11 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-12-11 18:11 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Logitech
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Common Files\Logitech
2012-12-08 20:56 . 2012-12-08 20:56 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Party
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- C:\Programs
2012-12-06 23:12 . 2012-12-17 23:07 -------- d-----w- c:\users\Administrator
2012-12-04 20:56 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-04 20:56 . 2012-12-12 03:04 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:55 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-04 20:55 . 2012-12-04 20:55 -------- d-----w- c:\users\Daffoza\AppData\Local\PunkBuster
2012-12-04 20:53 . 2012-12-04 20:53 -------- d-----w- c:\programdata\Orbit
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\users\Daffoza\AppData\Local\Ubisoft Game Launcher
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\program files (x86)\Ubisoft
2012-12-04 20:36 . 2012-12-04 20:36 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-12-04 19:20 . 2012-12-29 04:46 -------- d-----w- c:\program files (x86)\JDownloader
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\programdata\Dr Glitter
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\program files (x86)\Dr Glitter
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Winamp Detect
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2012-12-04 18:33 . 2012-12-29 00:35 -------- d-----w- c:\program files (x86)\Winamp
2012-12-04 18:33 . 2012-12-04 18:46 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Winamp
2012-12-04 18:23 . 2012-12-04 18:23 -------- d-----w- c:\users\Daffoza\AppData\Local\Macromedia
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Mozilla
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-12-02 13:37 . 2012-12-02 13:37 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-12-02 12:39 . 2012-12-22 22:27 -------- d-----w- c:\windows\KJ
2012-12-02 11:31 . 2012-12-22 22:22 -------- d-----w- c:\users\Daffoza\temp
2012-12-02 10:56 . 2012-12-03 23:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Deployment
2012-12-02 10:56 . 2012-12-02 10:56 -------- d-----w- c:\users\Daffoza\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-29 23:14 . 2012-10-30 02:05 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-29 23:14 . 2012-10-30 02:05 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-15 08:35 . 2012-10-24 18:03 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-10-17 00:31 . 2012-11-29 04:35 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EE1F503-E65A-4AB3-A956-E2A9330096AE}\mpengine.dll
2012-10-09 18:17 . 2012-11-15 08:34 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-15 08:34 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-15 08:34 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-15 08:34 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-09 16:16 . 2012-11-15 04:17 2700896 ----a-w- c:\windows\system32\FMAPO64.dll
2012-10-08 16:40 . 2012-11-15 04:17 3671184 ----a-w- c:\windows\system32\RtkAPO64.dll
2012-10-08 12:19 . 2012-11-15 08:38 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-10-08 11:42 . 2012-11-15 08:38 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-10-08 11:31 . 2012-11-15 08:38 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 11:24 . 2012-11-15 08:38 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-10-08 11:23 . 2012-11-15 08:38 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 11:22 . 2012-11-15 08:38 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 11:22 . 2012-11-15 08:38 237056 ----a-w- c:\windows\system32\url.dll
2012-10-08 11:20 . 2012-11-15 08:38 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-10-08 11:18 . 2012-11-15 08:38 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 11:17 . 2012-11-15 08:38 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 11:17 . 2012-11-15 08:38 816640 ----a-w- c:\windows\system32\jscript.dll
2012-10-08 11:15 . 2012-11-15 08:38 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-10-08 11:15 . 2012-11-15 08:38 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-10-08 11:13 . 2012-11-15 08:38 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-10-08 11:13 . 2012-11-15 08:38 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-08 11:09 . 2012-11-15 08:38 248320 ----a-w- c:\windows\system32\ieui.dll
2012-10-08 07:56 . 2012-11-15 08:38 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-10-08 07:48 . 2012-11-15 08:38 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-10-08 07:47 . 2012-11-15 08:38 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTProAgent.exe" [2009-12-16 312640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"win32"="c:\kernels\drivers.vbs" [2012-11-29 474]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-03-22 74752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"RemoteControl11"="c:\program files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe" [2011-04-20 234792]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 23:14]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/webhp?sourceid=toolbar-in ... CZ507CZ508
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: browser.startup.homepage - hxxp://home.cloyim.com/
FF - prefs.js: keyword.URL - hxxp://home.cloyim.com/search.php?q=
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-Praetorian - c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe
Wow6432Node-HKLM-Run-Driver Genius - (no file)
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2012-12-31 13:49:35 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 97 426 436 096
Po spuštění: Volných bajtů: 97 401 065 472
.
- - End Of File - - A6FBCD824191A1561C4510792A8D2DBA
Re: zavirovane pc
- Ulozte nejlepe na Plochu
- U vsech polozek udelejte zatrzitko (tim je oznacite pro skenovani)
- Kliknete na Scan
- Po dokonceni skenu se objevi log FSS.txt ten sem vlozte
Re: zavirovane pc
Farbar Service Scanner Version: 05-01-2013
Ran by Daffoza (administrator) on 14-01-2013 at 23:41:31
Running from "C:\Users\Daffoza\Desktop"
Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Ran by Daffoza (administrator) on 14-01-2013 at 23:41:31
Running from "C:\Users\Daffoza\Desktop"
Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Re: zavirovane pc
Re: zavirovane pc
Rkill 2.4.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 01/14/2013 11:48:33 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 2564) [WD-HEUR]
* C:\Users\Daffoza\Desktop\FSS.exe (PID: 4256) [UP-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 01/14/2013 11:48:47 PM
Execution time: 0 hours(s), 0 minute(s), and 13 seconds(s)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 01/14/2013 11:48:33 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 2564) [WD-HEUR]
* C:\Users\Daffoza\Desktop\FSS.exe (PID: 4256) [UP-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 01/14/2013 11:48:47 PM
Execution time: 0 hours(s), 0 minute(s), and 13 seconds(s)
Re: zavirovane pc
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job C:\STF33F0.tmp c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Praetorian"=- ""=- "Google Update"=- "DAEMON Tools Pro Agent"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "CTxfiHlp"=- "ROC_roc_ssl_v12"=- "Adobe ARM"=- "SunJavaUpdateSched"=- "googletalk"=- "Driver Genius"=- "win32"=- "WinampAgent"=- "RemoteControl11"=- DDS:: uStart Page = hxxp://www.google.cz/webhp?sourceid=too ... CZ507CZ508 Firefox:: FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\ FF - prefs.js: browser.search.selectedEngine - Search the web FF - prefs.js: browser.startup.homepage - hxxp://home.cloyim.com/ FF - prefs.js: keyword.URL - hxxp://home.cloyim.com/search.php?q= FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 RegLock:: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security] ClearJavaCache:: Reboot::- Ulozte vytvoreny TXT jako CFScript.txt tez primo na c:\
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: zavirovane pc
ComboFix 13-01-14.01 - Daffoza 15.01.2013 0:19.2.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.11496 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\STF33F0.tmp"
"c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-15 do 2013-01-15 )))))))))))))))))))))))))))))))
.
.
2013-01-15 02:31 . 2013-01-15 02:31 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\offreg.dll
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-01-14 23:11 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\mpengine.dll
2013-01-14 14:45 . 2013-01-14 14:45 -------- d-----w- c:\users\UpdatusUser.Daffoza-PC
2013-01-14 04:47 . 2013-01-14 04:47 -------- d-----w- c:\program files (x86)\GotClip
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- c:\programdata\MGS
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- C:\Microgaming
2013-01-11 02:04 . 2013-01-11 02:04 -------- d-----w- c:\program files\VideoLAN
2013-01-11 02:03 . 2013-01-11 02:03 308200 ----a-w- c:\windows\system32\javaws.exe
2013-01-11 02:03 . 2013-01-11 02:03 959976 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\javaw.exe
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\java.exe
2013-01-11 02:03 . 2013-01-11 02:03 -------- d-----w- c:\program files\Java
2013-01-11 02:00 . 2013-01-09 02:19 263064 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\programdata\CanonBJ
2013-01-03 08:55 . 2010-04-24 04:00 83968 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9Z.DLL
2013-01-03 08:55 . 2010-04-24 04:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9Z.DLL
2013-01-03 08:54 . 2010-04-24 04:00 336896 ----a-w- c:\windows\system32\CNMLM9Z.DLL
2013-01-03 08:54 . 2009-04-03 15:01 1321984 ----a-w- c:\windows\system32\CNC550C.dll
2013-01-03 08:54 . 2009-04-03 15:00 92672 ----a-w- c:\windows\system32\CNC550I.dll
2013-01-03 08:54 . 2009-04-03 14:57 106496 ----a-w- c:\windows\SysWow64\CNC550U.dll
2013-01-03 08:54 . 2009-03-19 13:39 328192 ----a-w- c:\windows\system32\CNC550L.dll
2013-01-03 08:54 . 2009-03-19 13:38 303104 ----a-w- c:\windows\SysWow64\CNC550L.dll
2013-01-03 08:54 . 2008-08-25 17:02 17920 ----a-w- c:\windows\system32\CNHMCA6.dll
2013-01-03 08:54 . 2008-08-25 17:02 15872 ----a-w- c:\windows\SysWow64\CNHMCA.dll
2013-01-02 14:36 . 2013-01-02 14:36 -------- d-----w- c:\users\Daffoza\AppData\Local\CyberLink
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2013-01-02 14:36 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-18 19:08 . 2012-12-18 19:08 209112 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 02:41 . 2012-10-30 02:05 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 02:41 . 2012-10-30 02:05 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-05 18:14 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-01-05 18:14 . 2012-12-04 20:55 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-16 16:31 . 2012-10-24 18:03 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-15 06:00 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\users\Daffoza\AppData\Roaming\uTorrent\uTorrent.exe" [2013-01-13 1078096]
"uTorrent Turbo Booster"="c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe" [2008-09-18 371712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-13 01:15 1606760 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 02:41]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - ExtSQL: 2013-01-11 03:01; testpilot@labs.mozilla.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\testpilot@labs.mozilla.com.xpi
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\windows\DAODx.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
c:\program files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
.
**************************************************************************
.
Celkový čas: 2013-01-15 07:23:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-15 06:23
ComboFix2.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 88 270 774 272
Po spuštění: Volných bajtů: 89 271 050 240
.
- - End Of File - - DBCCA4EE24CB777D5E3650EA8C961EF4
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.11496 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\STF33F0.tmp"
"c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-15 do 2013-01-15 )))))))))))))))))))))))))))))))
.
.
2013-01-15 02:31 . 2013-01-15 02:31 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\offreg.dll
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-01-14 23:11 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\mpengine.dll
2013-01-14 14:45 . 2013-01-14 14:45 -------- d-----w- c:\users\UpdatusUser.Daffoza-PC
2013-01-14 04:47 . 2013-01-14 04:47 -------- d-----w- c:\program files (x86)\GotClip
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- c:\programdata\MGS
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- C:\Microgaming
2013-01-11 02:04 . 2013-01-11 02:04 -------- d-----w- c:\program files\VideoLAN
2013-01-11 02:03 . 2013-01-11 02:03 308200 ----a-w- c:\windows\system32\javaws.exe
2013-01-11 02:03 . 2013-01-11 02:03 959976 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\javaw.exe
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\java.exe
2013-01-11 02:03 . 2013-01-11 02:03 -------- d-----w- c:\program files\Java
2013-01-11 02:00 . 2013-01-09 02:19 263064 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\programdata\CanonBJ
2013-01-03 08:55 . 2010-04-24 04:00 83968 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9Z.DLL
2013-01-03 08:55 . 2010-04-24 04:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9Z.DLL
2013-01-03 08:54 . 2010-04-24 04:00 336896 ----a-w- c:\windows\system32\CNMLM9Z.DLL
2013-01-03 08:54 . 2009-04-03 15:01 1321984 ----a-w- c:\windows\system32\CNC550C.dll
2013-01-03 08:54 . 2009-04-03 15:00 92672 ----a-w- c:\windows\system32\CNC550I.dll
2013-01-03 08:54 . 2009-04-03 14:57 106496 ----a-w- c:\windows\SysWow64\CNC550U.dll
2013-01-03 08:54 . 2009-03-19 13:39 328192 ----a-w- c:\windows\system32\CNC550L.dll
2013-01-03 08:54 . 2009-03-19 13:38 303104 ----a-w- c:\windows\SysWow64\CNC550L.dll
2013-01-03 08:54 . 2008-08-25 17:02 17920 ----a-w- c:\windows\system32\CNHMCA6.dll
2013-01-03 08:54 . 2008-08-25 17:02 15872 ----a-w- c:\windows\SysWow64\CNHMCA.dll
2013-01-02 14:36 . 2013-01-02 14:36 -------- d-----w- c:\users\Daffoza\AppData\Local\CyberLink
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2013-01-02 14:36 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-18 19:08 . 2012-12-18 19:08 209112 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 02:41 . 2012-10-30 02:05 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 02:41 . 2012-10-30 02:05 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-05 18:14 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-01-05 18:14 . 2012-12-04 20:55 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-16 16:31 . 2012-10-24 18:03 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-15 06:00 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\users\Daffoza\AppData\Roaming\uTorrent\uTorrent.exe" [2013-01-13 1078096]
"uTorrent Turbo Booster"="c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe" [2008-09-18 371712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-13 01:15 1606760 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 02:41]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - ExtSQL: 2013-01-11 03:01; testpilot@labs.mozilla.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\testpilot@labs.mozilla.com.xpi
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\windows\DAODx.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
c:\program files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
.
**************************************************************************
.
Celkový čas: 2013-01-15 07:23:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-15 06:23
ComboFix2.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 88 270 774 272
Po spuštění: Volných bajtů: 89 271 050 240
.
- - End Of File - - DBCCA4EE24CB777D5E3650EA8C961EF4
Re: zavirovane pc
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Search
- Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte



Přispějete na provoz fóra?