
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
zavirovane pc
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
zavirovane pc
Logfile of random's system information tool 1.09 (written by random/random)
Run by Daffoza at 2012-12-29 21:25:07
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 94 GB (38%) free of 250 GB
Total RAM: 16329 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:10, on 29.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files (x86)\steam\steam.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Daffoza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.cloyim.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
O4 - HKLM\..\Run: [ghost] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [win32] "C:\kernels\drivers.vbs"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKCU\..\Run: [Praetorian] C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASDiskUnlocker - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVELO Dataplex Service (nveloSvc) - Unknown owner - C:\Windows\system32\Dataplex\nveloSvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12314 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe"
"C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {8497AA2B-9F98-4310-9FE4-FBB1EAEB56B0}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
"C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe" -Init
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\steam\steam.exe" "steam://rungameid/42690"
"C:\Program Files (x86)\uTorrent\uTorrent.exe" "C:\Users\Daffoza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R0RRO0Z3\torrentdownloads net Doblba!!!(cz) cip avi.torrent"
"C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6332.2.497742768\541783985" --gpu-vendor-id=0x10de --gpu-device-id=0x1080 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.697 --ignored=" --type=renderer " /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --extension-process --renderer-print-preview --channel="6332.3.1067490189\3612399" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6332.5.702722703\1487027833" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.6.623661733\1480877664" /prefetch:3
"C:\Program Files (x86)\Java\jre7\bin\javaw.exe" -jar -Xmx512m JDownloader.jar -rfu
"C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Winamp\winamp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service --lang=cs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi-broker --channel="6332.61.428214925\262113616" --lang=cs /prefetch:14
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.77.1350594967\614582709" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.80.94961694\1616291165" /prefetch:3
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.82.316539001\1901053276" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.85.1981119174\1581182093" /prefetch:3
"C:\Users\Daffoza\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe62_ Global\UsGthrCtrlFltPipeMssGthrPipe62 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 536 540 548 65536 544
"C:\Users\Daffoza\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
prefs.js - "browser.startup.homepage" - "http://home.cloyim.com/"
prefs.js - "keyword.URL" - "http://home.cloyim.com/search.php?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
npwachk.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
Search the web.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\
plugin@yontoo.com
vb@yandex.ru
yasearch@yandex.ru
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\
firmy.cz-043339.xml
gorsel.yandex.com.tr-045337.xml
haber.yandex.com.tr-045337.xml
mapy.cz-043338.xml
seznam.cz-043338.xml
videa.seznam.cz-043339.xml
video.yandex.com.tr-045337.xml
yandex.com.tr-045337.xml
yqs-barff-yagorsel.xml
yqs-barff-yahaber.xml
yqs-barff-yandex.xml
yqs-barff-yavideo.xml
zbozi.cz-043338.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-11-11 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-11-11 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files (x86)\Yontoo\YontooIEClient.dll [2012-10-24 194928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-10-23 6842512]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Praetorian"=C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe []
""= []
"Google Update"=C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-24 116648]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe [2009-12-16 312640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker]
C:\Program Files (x86)\SiteRanker\SiteRankTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"ASUS AiChargerPlus Execute"=C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [2010-11-08 465536]
"ghost"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe [2010-02-08 192000]
"Tilt"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe [2011-04-20 729088]
"CTxfiHlp"=CTXFIHLP.EXE []
"ROC_roc_ssl_v12"=C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe / /PROMPT /CMPID=roc_ssl_v12 []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"googletalk"=C:\Program Files (x86)\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Driver Genius"= []
"win32"=C:\kernels\drivers.vbs [2012-11-29 474]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-03-22 74752]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"RemoteControl11"=C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
C:\Users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
uTorrent Turbo Booster.lnk - C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-12-29 21:22:29 ----D---- C:\rsit
2012-12-29 21:22:29 ----D---- C:\Program Files\trend micro
2012-12-29 06:00:11 ----D---- C:\Users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 05:56:08 ----D---- C:\ProgramData\PDVD
2012-12-29 05:55:51 ----D---- C:\ProgramData\CyberLink
2012-12-29 05:54:10 ----D---- C:\Program Files (x86)\CyberLink
2012-12-29 05:53:45 ----D---- C:\ProgramData\Temp
2012-12-29 05:53:45 ----D---- C:\ProgramData\install_clap
2012-12-29 01:15:06 ----D---- C:\Program Files (x86)\AVSociety
2012-12-29 00:46:30 ----A---- C:\Windows\d3dx.dat
2012-12-29 00:11:59 ----D---- C:\Users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 05:36:33 ----D---- C:\Program Files (x86)\Morphyre
2012-12-25 23:22:06 ----A---- C:\Windows\system32\drivers\aswFW.sys
2012-12-25 23:21:51 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswNdis.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2012-12-22 03:32:41 ----D---- C:\Users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nveloportfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelofsfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelodiskfltr.sys
2012-12-19 00:13:42 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-12-19 00:13:30 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2012-12-18 00:12:58 ----D---- C:\Program Files (x86)\7-Zip
2012-12-17 23:42:12 ----D---- C:\Program Files\OCZ Technology Group
2012-12-17 01:54:13 ----D---- C:\Program Files (x86)\Yontoo
2012-12-17 01:54:11 ----D---- C:\ProgramData\Tarma Installer
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\avastSS.scr
2012-12-17 01:14:44 ----D---- C:\ProgramData\AVAST Software
2012-12-17 01:14:44 ----D---- C:\Program Files\AVAST Software
2012-12-12 04:41:08 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-12-12 03:38:25 ----A---- C:\Windows\Dataplex.ini
2012-12-12 03:23:24 ----SHD---- C:\Config.Msi
2012-12-11 19:11:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-12-11 19:11:45 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-12-11 01:40:02 ----D---- C:\Program Files\Logitech
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files\Logitech
2012-12-08 21:56:05 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 21:55:58 ----D---- C:\Users\Daffoza\AppData\Roaming\Party
2012-12-08 21:55:43 ----D---- C:\Programs
2012-12-04 21:56:03 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-04 21:53:36 ----D---- C:\ProgramData\Orbit
2012-12-04 21:52:02 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-04 21:52:00 ----D---- C:\Program Files (x86)\Ubisoft
2012-12-04 21:36:19 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-12-04 20:20:12 ----D---- C:\Program Files (x86)\JDownloader
2012-12-04 19:39:26 ----D---- C:\ProgramData\Dr Glitter
2012-12-04 19:39:26 ----D---- C:\Program Files (x86)\Dr Glitter
2012-12-04 19:33:08 ----D---- C:\Program Files (x86)\Winamp Detect
2012-12-04 19:33:04 ----D---- C:\Users\Daffoza\AppData\Roaming\Winamp
2012-12-04 19:33:04 ----D---- C:\Program Files (x86)\Winamp
2012-12-04 19:22:17 ----D---- C:\ProgramData\Mozilla
2012-12-04 19:22:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-04 19:22:16 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-12-02 14:37:05 ----SHD---- C:\Windows\SYSWOW64\%APPDATA%
2012-12-02 13:39:29 ----D---- C:\Windows\KJ
======List of files/folders modified in the last 1 month======
2012-12-29 21:23:10 ----D---- C:\Users\Daffoza\AppData\Roaming\uTorrent
2012-12-29 21:22:29 ----RD---- C:\Program Files
2012-12-29 21:11:18 ----D---- C:\Windows\Temp
2012-12-29 17:50:17 ----HD---- C:\ProgramData
2012-12-29 17:50:17 ----D---- C:\Program Files (x86)\Google
2012-12-29 17:50:15 ----SHD---- C:\Windows\Installer
2012-12-29 17:49:54 ----RD---- C:\Program Files (x86)
2012-12-29 06:05:03 ----D---- C:\Windows\system32\config
2012-12-29 06:04:59 ----D---- C:\Windows\winsxs
2012-12-29 05:56:10 ----D---- C:\Windows\system32\Tasks
2012-12-29 05:56:07 ----D---- C:\Windows\system32\catroot
2012-12-29 05:53:45 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-29 05:53:39 ----SHD---- C:\System Volume Information
2012-12-29 01:35:24 ----D---- C:\Program Files (x86)\steam
2012-12-29 00:46:30 ----D---- C:\Windows
2012-12-26 13:49:59 ----SD---- C:\ProgramData\Microsoft
2012-12-26 13:47:27 ----D---- C:\ProgramData\NVIDIA
2012-12-25 23:22:06 ----D---- C:\Windows\system32\drivers
2012-12-25 23:22:00 ----D---- C:\Windows\inf
2012-12-25 23:21:57 ----D---- C:\Windows\system32\DriverStore
2012-12-22 19:05:29 ----D---- C:\Windows\System32
2012-12-22 14:21:47 ----D---- C:\Program Files (x86)\uTorrent
2012-12-22 04:33:22 ----D---- C:\Users\Daffoza\AppData\Roaming\vlc
2012-12-22 03:37:32 ----DC---- C:\Windows\system32\DRVSTORE
2012-12-22 03:35:13 ----D---- C:\Users\Daffoza\AppData\Roaming\YoWindow
2012-12-22 01:12:26 ----D---- C:\Windows\system32\NDF
2012-12-19 02:26:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-19 00:20:39 ----D---- C:\Users\Daffoza\AppData\Roaming\DAEMON Tools Pro
2012-12-19 00:19:09 ----D---- C:\Windows\system32\catroot2
2012-12-18 00:08:15 ----D---- C:\Windows\system32\wbem
2012-12-18 00:07:10 ----D---- C:\Windows\registration
2012-12-17 06:39:31 ----D---- C:\Users\Daffoza\AppData\Roaming\BitTorrent
2012-12-17 01:15:06 ----D---- C:\Windows\SysWOW64
2012-12-13 02:41:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-12 03:33:44 ----D---- C:\Windows\Tasks
2012-12-11 19:15:55 ----RSD---- C:\Windows\assembly
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files
2012-12-10 21:24:02 ----D---- C:\Windows\LiveKernelReports
2012-12-07 00:13:02 ----SHD---- C:\$Recycle.Bin
2012-12-07 00:12:59 ----RD---- C:\Users
2012-12-05 07:54:59 ----D---- C:\Users\Daffoza\AppData\Roaming\Yandex
2012-12-04 21:52:02 ----D---- C:\Windows\system32\LogFiles
2012-12-04 19:40:02 ----D---- C:\Users\Daffoza\AppData\Roaming\NVIDIA
2012-12-04 19:33:06 ----D---- C:\Program Files (x86)\Common Files
2012-12-04 19:23:58 ----SD---- C:\Users\Daffoza\AppData\Roaming\Microsoft
2012-12-04 19:22:19 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla
2012-12-04 16:55:18 ----D---- C:\Program Files (x86)\Opera
2012-12-02 13:09:45 ----D---- C:\Program Files (x86)\ASUS
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AiChargerPlus;ASUS Charger Plus Driver; C:\Windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-10-30 262656]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-31 120920]
R0 nvelodiskfltr;NVCache Policy Driver; C:\Windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
R0 nveloportfltr;NVELO Port Filter Driver; C:\Windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
R0 ocz12xx;ocz12xx; C:\Windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-12-19 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2010-08-24 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2010-08-03 14464]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-10-30 132864]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-30 21136]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 VDiskBus;ASUS Disk Unlocker; C:\Windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
R3 ASFLTDrv.sys;ASFLTDrv.sys; \??\C:\Program Files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver; C:\Windows\system32\DRIVERS\nvstusb.sys [2012-10-03 445800]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
S0 nvelofsfltr;nvelofsfltr; C:\Windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 CT20XUT.SYS;CT20XUT.SYS; C:\Windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 CT20XUT;CT20XUT; C:\Windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2010-07-07 580696]
S3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2010-07-07 697816]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\Windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTEXFIFX;CTEXFIFX; C:\Windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTHWIUT.SYS;CTHWIUT.SYS; C:\Windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 CTHWIUT;CTHWIUT; C:\Windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2010-07-07 15960]
S3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2010-07-07 213080]
S3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2010-07-07 118360]
S3 ha20x22k;Creative 20X2 HAL Driver; C:\Windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
S3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2010-07-07 1567832]
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
S3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2010-07-07 179288]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2012-10-28 31232]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
R2 ASDiskUnlocker;ASDiskUnlocker; C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-04 76888]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S2 nveloSvc;NVELO Dataplex Service; C:\Windows\system32\Dataplex\nveloSvc.exe []
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-13 250808]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-29 115168]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Run by Daffoza at 2012-12-29 21:25:07
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 94 GB (38%) free of 250 GB
Total RAM: 16329 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:10, on 29.12.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe
C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
C:\Program Files (x86)\steam\steam.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Java\jre7\bin\javaw.exe
C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE
C:\Program Files (x86)\Winamp\winamp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Daffoza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.cloyim.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
O4 - HKLM\..\Run: [ghost] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe
O4 - HKLM\..\Run: [Tilt] C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [win32] "C:\kernels\drivers.vbs"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [RemoteControl11] "C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe"
O4 - HKCU\..\Run: [Praetorian] C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
O23 - Service: ASDiskUnlocker - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
O23 - Service: ASUS System Control Service (AsSysCtrlService) - Unknown owner - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: CLHNServiceForPowerDVD - Unknown owner - C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: CyberLink PowerDVD 11.0 Monitor Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
O23 - Service: CyberLink PowerDVD 11.0 Service - CyberLink - C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVELO Dataplex Service (nveloSvc) - Unknown owner - C:\Windows\system32\Dataplex\nveloSvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12314 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe"
"C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe"
"C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe"
"C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\sppsvc.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"taskhost.exe"
taskeng.exe {8497AA2B-9F98-4310-9FE4-FBB1EAEB56B0}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe"
"C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe" -open
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe" -autorun
"C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\GHOSTOPEN.exe"
"C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe" -Init
"C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe" -hide
"C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe" -hide
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\steam\steam.exe" "steam://rungameid/42690"
"C:\Program Files (x86)\uTorrent\uTorrent.exe" "C:\Users\Daffoza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R0RRO0Z3\torrentdownloads net Doblba!!!(cz) cip avi.torrent"
"C:\Program Files (x86)\DAEMON Tools Pro\DTProShellHlp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6332.2.497742768\541783985" --gpu-vendor-id=0x10de --gpu-device-id=0x1080 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.697 --ignored=" --type=renderer " /prefetch:12
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --extension-process --renderer-print-preview --channel="6332.3.1067490189\3612399" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6332.5.702722703\1487027833" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.6.623661733\1480877664" /prefetch:3
"C:\Program Files (x86)\Java\jre7\bin\javaw.exe" -jar -Xmx512m JDownloader.jar -rfu
"C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.EXE"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Winamp\winamp.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=service --lang=cs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi-broker --channel="6332.61.428214925\262113616" --lang=cs /prefetch:14
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.77.1350594967\614582709" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.80.94961694\1616291165" /prefetch:3
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.82.316539001\1901053276" /prefetch:3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials=AsyncDns/disabled/ConnCountImpact/conn_count_6/ConnnectBackupJobs/ConnectBackupJobsEnabled/DnsImpact/default_enabled_prefetch/EnableStage3D/enabled_default/ForceCompositingMode/disable/GlobalSdch/global_enable_sdch/IdleSktToImpact/idle_timeout_10/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxSearchSuggest/14/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/ProxyConnectionImpact/proxy_connections_32/SBInterstitial/V2/SpdyCwnd/cwndMin16/SpeculativePrefetchingLearning/SpeculativePrefetchingDisabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-1-Percent/group_70/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/default/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="6332.85.1981119174\1581182093" /prefetch:3
"C:\Users\Daffoza\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe62_ Global\UsGthrCtrlFltPipeMssGthrPipe62 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 536 540 548 65536 544
"C:\Users\Daffoza\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default
prefs.js - "browser.startup.homepage" - "http://home.cloyim.com/"
prefs.js - "keyword.URL" - "http://home.cloyim.com/search.php?q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.135 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
npwachk.dll
C:\Program Files (x86)\Mozilla Firefox\searchplugins\
google.xml
heureka-cz.xml
jyxo-cz.xml
Search the web.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\
plugin@yontoo.com
vb@yandex.ru
yasearch@yandex.ru
C:\Users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\searchplugins\
firmy.cz-043339.xml
gorsel.yandex.com.tr-045337.xml
haber.yandex.com.tr-045337.xml
mapy.cz-043338.xml
seznam.cz-043338.xml
videa.seznam.cz-043339.xml
video.yandex.com.tr-045337.xml
yandex.com.tr-045337.xml
yqs-barff-yagorsel.xml
yqs-barff-yahaber.xml
yqs-barff-yandex.xml
yqs-barff-yavideo.xml
zbozi.cz-043338.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2012-11-11 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2012-11-11 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files (x86)\Yontoo\YontooIEClient.dll [2012-10-24 194928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2012-10-23 6842512]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Praetorian"=C:\Users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe []
""= []
"Google Update"=C:\Users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-10-24 116648]
"DAEMON Tools Pro Agent"=C:\Program Files (x86)\DAEMON Tools Pro\DTProAgent.exe [2009-12-16 312640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker]
C:\Program Files (x86)\SiteRanker\SiteRankTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-09-07 43608]
"ASUS AiChargerPlus Execute"=C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [2010-11-08 465536]
"ghost"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe [2010-02-08 192000]
"Tilt"=C:\Program Files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe [2011-04-20 729088]
"CTxfiHlp"=CTXFIHLP.EXE []
"ROC_roc_ssl_v12"=C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe / /PROMPT /CMPID=roc_ssl_v12 []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"googletalk"=C:\Program Files (x86)\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Driver Genius"= []
"win32"=C:\kernels\drivers.vbs [2012-11-29 474]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2011-03-22 74752]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"RemoteControl11"=C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [2011-04-20 234792]
C:\Users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
uTorrent Turbo Booster.lnk - C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2012-12-29 21:22:29 ----D---- C:\rsit
2012-12-29 21:22:29 ----D---- C:\Program Files\trend micro
2012-12-29 06:00:11 ----D---- C:\Users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 05:56:08 ----D---- C:\ProgramData\PDVD
2012-12-29 05:55:51 ----D---- C:\ProgramData\CyberLink
2012-12-29 05:54:10 ----D---- C:\Program Files (x86)\CyberLink
2012-12-29 05:53:45 ----D---- C:\ProgramData\Temp
2012-12-29 05:53:45 ----D---- C:\ProgramData\install_clap
2012-12-29 01:15:06 ----D---- C:\Program Files (x86)\AVSociety
2012-12-29 00:46:30 ----A---- C:\Windows\d3dx.dat
2012-12-29 00:11:59 ----D---- C:\Users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 05:36:33 ----D---- C:\Program Files (x86)\Morphyre
2012-12-25 23:22:06 ----A---- C:\Windows\system32\drivers\aswFW.sys
2012-12-25 23:21:51 ----A---- C:\Windows\system32\drivers\aswNdis2.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswNdis.sys
2012-12-25 23:21:50 ----A---- C:\Windows\system32\drivers\aswKbd.sys
2012-12-22 03:32:41 ----D---- C:\Users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nveloportfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelofsfltr.sys
2012-12-19 00:16:49 ----A---- C:\Windows\system32\drivers\nvelodiskfltr.sys
2012-12-19 00:13:42 ----A---- C:\Windows\system32\drivers\sptd.sys
2012-12-19 00:13:30 ----D---- C:\Program Files (x86)\DAEMON Tools Pro
2012-12-18 00:12:58 ----D---- C:\Program Files (x86)\7-Zip
2012-12-17 23:42:12 ----D---- C:\Program Files\OCZ Technology Group
2012-12-17 01:54:13 ----D---- C:\Program Files (x86)\Yontoo
2012-12-17 01:54:11 ----D---- C:\ProgramData\Tarma Installer
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-12-17 01:15:06 ----A---- C:\Windows\system32\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2012-12-17 01:14:54 ----A---- C:\Windows\avastSS.scr
2012-12-17 01:14:44 ----D---- C:\ProgramData\AVAST Software
2012-12-17 01:14:44 ----D---- C:\Program Files\AVAST Software
2012-12-12 04:41:08 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2012-12-12 03:38:25 ----A---- C:\Windows\Dataplex.ini
2012-12-12 03:23:24 ----SHD---- C:\Config.Msi
2012-12-11 19:11:47 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2012-12-11 19:11:45 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2012-12-11 01:40:02 ----D---- C:\Program Files\Logitech
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files\Logitech
2012-12-08 21:56:05 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 21:55:58 ----D---- C:\Users\Daffoza\AppData\Roaming\Party
2012-12-08 21:55:43 ----D---- C:\Programs
2012-12-04 21:56:03 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2012-12-04 21:53:36 ----D---- C:\ProgramData\Orbit
2012-12-04 21:52:02 ----A---- C:\Windows\SYSWOW64\PnkBstrA.exe
2012-12-04 21:52:00 ----D---- C:\Program Files (x86)\Ubisoft
2012-12-04 21:36:19 ----D---- C:\ProgramData\DAEMON Tools Lite
2012-12-04 20:20:12 ----D---- C:\Program Files (x86)\JDownloader
2012-12-04 19:39:26 ----D---- C:\ProgramData\Dr Glitter
2012-12-04 19:39:26 ----D---- C:\Program Files (x86)\Dr Glitter
2012-12-04 19:33:08 ----D---- C:\Program Files (x86)\Winamp Detect
2012-12-04 19:33:04 ----D---- C:\Users\Daffoza\AppData\Roaming\Winamp
2012-12-04 19:33:04 ----D---- C:\Program Files (x86)\Winamp
2012-12-04 19:22:17 ----D---- C:\ProgramData\Mozilla
2012-12-04 19:22:17 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2012-12-04 19:22:16 ----D---- C:\Program Files (x86)\Mozilla Firefox
2012-12-02 14:37:05 ----SHD---- C:\Windows\SYSWOW64\%APPDATA%
2012-12-02 13:39:29 ----D---- C:\Windows\KJ
======List of files/folders modified in the last 1 month======
2012-12-29 21:23:10 ----D---- C:\Users\Daffoza\AppData\Roaming\uTorrent
2012-12-29 21:22:29 ----RD---- C:\Program Files
2012-12-29 21:11:18 ----D---- C:\Windows\Temp
2012-12-29 17:50:17 ----HD---- C:\ProgramData
2012-12-29 17:50:17 ----D---- C:\Program Files (x86)\Google
2012-12-29 17:50:15 ----SHD---- C:\Windows\Installer
2012-12-29 17:49:54 ----RD---- C:\Program Files (x86)
2012-12-29 06:05:03 ----D---- C:\Windows\system32\config
2012-12-29 06:04:59 ----D---- C:\Windows\winsxs
2012-12-29 05:56:10 ----D---- C:\Windows\system32\Tasks
2012-12-29 05:56:07 ----D---- C:\Windows\system32\catroot
2012-12-29 05:53:45 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2012-12-29 05:53:39 ----SHD---- C:\System Volume Information
2012-12-29 01:35:24 ----D---- C:\Program Files (x86)\steam
2012-12-29 00:46:30 ----D---- C:\Windows
2012-12-26 13:49:59 ----SD---- C:\ProgramData\Microsoft
2012-12-26 13:47:27 ----D---- C:\ProgramData\NVIDIA
2012-12-25 23:22:06 ----D---- C:\Windows\system32\drivers
2012-12-25 23:22:00 ----D---- C:\Windows\inf
2012-12-25 23:21:57 ----D---- C:\Windows\system32\DriverStore
2012-12-22 19:05:29 ----D---- C:\Windows\System32
2012-12-22 14:21:47 ----D---- C:\Program Files (x86)\uTorrent
2012-12-22 04:33:22 ----D---- C:\Users\Daffoza\AppData\Roaming\vlc
2012-12-22 03:37:32 ----DC---- C:\Windows\system32\DRVSTORE
2012-12-22 03:35:13 ----D---- C:\Users\Daffoza\AppData\Roaming\YoWindow
2012-12-22 01:12:26 ----D---- C:\Windows\system32\NDF
2012-12-19 02:26:41 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-12-19 00:20:39 ----D---- C:\Users\Daffoza\AppData\Roaming\DAEMON Tools Pro
2012-12-19 00:19:09 ----D---- C:\Windows\system32\catroot2
2012-12-18 00:08:15 ----D---- C:\Windows\system32\wbem
2012-12-18 00:07:10 ----D---- C:\Windows\registration
2012-12-17 06:39:31 ----D---- C:\Users\Daffoza\AppData\Roaming\BitTorrent
2012-12-17 01:15:06 ----D---- C:\Windows\SysWOW64
2012-12-13 02:41:10 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2012-12-12 03:33:44 ----D---- C:\Windows\Tasks
2012-12-11 19:15:55 ----RSD---- C:\Windows\assembly
2012-12-11 01:40:02 ----D---- C:\Program Files\Common Files
2012-12-10 21:24:02 ----D---- C:\Windows\LiveKernelReports
2012-12-07 00:13:02 ----SHD---- C:\$Recycle.Bin
2012-12-07 00:12:59 ----RD---- C:\Users
2012-12-05 07:54:59 ----D---- C:\Users\Daffoza\AppData\Roaming\Yandex
2012-12-04 21:52:02 ----D---- C:\Windows\system32\LogFiles
2012-12-04 19:40:02 ----D---- C:\Users\Daffoza\AppData\Roaming\NVIDIA
2012-12-04 19:33:06 ----D---- C:\Program Files (x86)\Common Files
2012-12-04 19:23:58 ----SD---- C:\Users\Daffoza\AppData\Roaming\Microsoft
2012-12-04 19:22:19 ----D---- C:\Users\Daffoza\AppData\Roaming\Mozilla
2012-12-04 16:55:18 ----D---- C:\Program Files (x86)\Opera
2012-12-02 13:09:45 ----D---- C:\Program Files (x86)\ASUS
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AiChargerPlus;ASUS Charger Plus Driver; C:\Windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
R0 aswNdis;avast! Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service; C:\Windows\system32\drivers\aswNdis2.sys [2012-10-30 262656]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2012-03-31 120920]
R0 nvelodiskfltr;NVCache Policy Driver; C:\Windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
R0 nveloportfltr;NVELO Port Filter Driver; C:\Windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
R0 ocz12xx;ocz12xx; C:\Windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-12-19 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2010-08-24 13440]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2010-08-03 14464]
R1 aswFW;avast! TDI Firewall driver; C:\Windows\system32\drivers\aswFW.sys [2012-10-30 132864]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2012-10-30 21136]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 VDiskBus;ASUS Disk Unlocker; C:\Windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
R3 ASFLTDrv.sys;ASFLTDrv.sys; \??\C:\Program Files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
R3 asmthub3;ASMedia USB3 Hub Service; C:\Windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
R3 asmtxhci;ASMEDIA XHCI Service; C:\Windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-10-23 4187664]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver; C:\Windows\system32\DRIVERS\nvstusb.sys [2012-10-03 445800]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
S0 nvelofsfltr;nvelofsfltr; C:\Windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 CT20XUT.SYS;CT20XUT.SYS; C:\Windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 CT20XUT;CT20XUT; C:\Windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2010-07-07 580696]
S3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2010-07-07 697816]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\Windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTEXFIFX;CTEXFIFX; C:\Windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTHWIUT.SYS;CTHWIUT.SYS; C:\Windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 CTHWIUT;CTHWIUT; C:\Windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2010-07-07 15960]
S3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2010-07-07 213080]
S3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2010-07-07 118360]
S3 ha20x22k;Creative 20X2 HAL Driver; C:\Windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
S3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2010-07-07 1567832]
S3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
S3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2012-06-11 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2012-06-11 27136]
S3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2010-07-07 179288]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys []
S3 tap0901;TAP-Win32 Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2012-10-28 31232]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys []
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-06-11 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 32768]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-06-11 9216]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
R2 ASDiskUnlocker;ASDiskUnlocker; C:\Program Files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
R2 AsSysCtrlService;ASUS System Control Service; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
R2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
R2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-12-04 76888]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S2 nveloSvc;NVELO Dataplex Service; C:\Windows\system32\Dataplex\nveloSvc.exe []
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-02 1258856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-13 250808]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-11-29 115168]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: zavirovane pc
Zdravim
Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- Pokud ho havet blokuje, pouzijte jeden z nasledujicich - i ty prejmenovane
Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill iExplore.exe:
http://download.bleepingcomputer.com/gr ... xplore.exe
Rkill uSeRiNiT.exe:
http://download.bleepingcomputer.com/gr ... eRiNiT.exe
Rkill WiNlOgOn.exe:
http://download.bleepingcomputer.com/gr ... NlOgOn.exe - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne do par sekund a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Na plose vznikne log Rkill.txt ten mi sem vlozte
- Ted nerestartujte PC - prisli byste o ucinek RKillu

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: zavirovane pc
Rkill 2.4.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/31/2012 12:54:51 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 960) [WD-HEUR]
1 proccess terminated!
Possibly Patched Files.
* C:\Windows\system32\services.exe
Checking Registry for malware related settings:
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\Daffoza\Desktop\rkill\rkill-12-31-2012-12-55-29.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* C:\Windows\assembly\GAC_32\Desktop.ini [ZA File]
* C:\Windows\assembly\GAC_64\Desktop.ini [ZA File]
Checking Windows Service Integrity:
* Ovladač ověření brány Windows Firewall (mpsdrv) is not Running.
Startup Type set to: Manual
* BFE [Missing Service]
* BITS [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]
* wuauserv [Missing Service]
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* C:\Windows\System32\services.exe [NoSig]
+-> C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe : 328 704 : 07/14/2009 00:39 AM : 24acb7e5be595468e3b9aa488b9b4fcb [Pos Repl]
Checking HOSTS File:
* No issues found.
Program finished at: 12/31/2012 12:56:05 PM
Execution time: 0 hours(s), 1 minute(s), and 13 seconds(s)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/31/2012 12:54:51 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 960) [WD-HEUR]
1 proccess terminated!
Possibly Patched Files.
* C:\Windows\system32\services.exe
Checking Registry for malware related settings:
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]
Backup Registry file created at:
C:\Users\Daffoza\Desktop\rkill\rkill-12-31-2012-12-55-29.reg
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* C:\Windows\assembly\GAC_32\Desktop.ini [ZA File]
* C:\Windows\assembly\GAC_64\Desktop.ini [ZA File]
Checking Windows Service Integrity:
* Ovladač ověření brány Windows Firewall (mpsdrv) is not Running.
Startup Type set to: Manual
* BFE [Missing Service]
* BITS [Missing Service]
* iphlpsvc [Missing Service]
* MpsSvc [Missing Service]
* WinDefend [Missing Service]
* wscsvc [Missing Service]
* wuauserv [Missing Service]
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* C:\Windows\System32\services.exe [NoSig]
+-> C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe : 328 704 : 07/14/2009 00:39 AM : 24acb7e5be595468e3b9aa488b9b4fcb [Pos Repl]
Checking HOSTS File:
* No issues found.
Program finished at: 12/31/2012 12:56:05 PM
Execution time: 0 hours(s), 1 minute(s), and 13 seconds(s)
Re: zavirovane pc
Fajn, ComboFix by byl



Re: zavirovane pc
ComboFix 12-12-31.01 - Daffoza 31.12.2012 13:16:30.1.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.14342 [GMT 1:00]
Spuštěný z: c:\users\Daffoza\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1028.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1031.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1033.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1036.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1041.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\2052.msi
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\201d3dde
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\4cce1f70
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\76603ac3
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000008.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\000000cb.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\80000000.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz102F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz104F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10C4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10EC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1190.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz121B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz12CB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz158B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz15EA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1837.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1848.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A2F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A4F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FEE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz209F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz20FE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz22DB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz230C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz2FC6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3086.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3096.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz33DD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3770.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz38C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3AE1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3CB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D72.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D73.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3FB2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz40E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4173.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz43A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4691.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz47AB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4919.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4C45.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4EFD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F5B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F8B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51A6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51D6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55D0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55E1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz57EF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz58F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6092.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz60A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz64AD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz65A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6628.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz67DE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz687F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6880.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz69D2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A00.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A21.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6C1E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6F07.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7005.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz707F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz708F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7194.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz71D4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz741.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7698.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7744.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7805.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz79FD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7A4C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7E2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7F70.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8078.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz807B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8098.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8210.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz82FC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz85D5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz866F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8766.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8786.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz890.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8E15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8FFA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9097.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90B6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90E6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz93CD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz940D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9459.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9518.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz95F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz98F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA368.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA3C7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA81E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA91F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA96E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzABC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC67.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC7F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzACED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD42.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD5F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzADAE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB400.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB474.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB8C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBB51.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBC75.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBD8F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBF1A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC1B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC24D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC3F1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC8FA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzCD39.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD258.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD953.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD9F0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzDB37.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE3C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE4E3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE6EE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE7BF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE94F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE9F8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEA57.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBBF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEE6E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEF7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF033.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF246.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF424.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF444.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF479.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4D9.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF7B5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFA90.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFAD0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFC06.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFCD2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFFAA.tmp
.
Nakažená kopie c:\windows\system32\services.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-28 do 2012-12-31 )))))))))))))))))))))))))))))))
.
.
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2012-12-29 04:56 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:22 . 2012-10-30 22:51 132864 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-12-25 22:21 . 2012-10-30 22:51 262656 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-25 22:21 . 2012-09-21 09:26 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
2012-12-12 03:41 . 2012-12-13 01:41 16363960 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-12-11 18:16 . 2012-12-11 18:16 -------- d-----w- c:\users\Daffoza\AppData\Local\Activision
2012-12-11 18:11 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-12-11 18:11 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Logitech
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Common Files\Logitech
2012-12-08 20:56 . 2012-12-08 20:56 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Party
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- C:\Programs
2012-12-06 23:12 . 2012-12-17 23:07 -------- d-----w- c:\users\Administrator
2012-12-04 20:56 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-04 20:56 . 2012-12-12 03:04 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:55 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-04 20:55 . 2012-12-04 20:55 -------- d-----w- c:\users\Daffoza\AppData\Local\PunkBuster
2012-12-04 20:53 . 2012-12-04 20:53 -------- d-----w- c:\programdata\Orbit
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\users\Daffoza\AppData\Local\Ubisoft Game Launcher
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\program files (x86)\Ubisoft
2012-12-04 20:36 . 2012-12-04 20:36 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-12-04 19:20 . 2012-12-29 04:46 -------- d-----w- c:\program files (x86)\JDownloader
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\programdata\Dr Glitter
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\program files (x86)\Dr Glitter
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Winamp Detect
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2012-12-04 18:33 . 2012-12-29 00:35 -------- d-----w- c:\program files (x86)\Winamp
2012-12-04 18:33 . 2012-12-04 18:46 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Winamp
2012-12-04 18:23 . 2012-12-04 18:23 -------- d-----w- c:\users\Daffoza\AppData\Local\Macromedia
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Mozilla
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-12-02 13:37 . 2012-12-02 13:37 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-12-02 12:39 . 2012-12-22 22:27 -------- d-----w- c:\windows\KJ
2012-12-02 11:31 . 2012-12-22 22:22 -------- d-----w- c:\users\Daffoza\temp
2012-12-02 10:56 . 2012-12-03 23:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Deployment
2012-12-02 10:56 . 2012-12-02 10:56 -------- d-----w- c:\users\Daffoza\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-29 23:14 . 2012-10-30 02:05 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-29 23:14 . 2012-10-30 02:05 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-15 08:35 . 2012-10-24 18:03 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-10-17 00:31 . 2012-11-29 04:35 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EE1F503-E65A-4AB3-A956-E2A9330096AE}\mpengine.dll
2012-10-09 18:17 . 2012-11-15 08:34 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-15 08:34 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-15 08:34 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-15 08:34 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-09 16:16 . 2012-11-15 04:17 2700896 ----a-w- c:\windows\system32\FMAPO64.dll
2012-10-08 16:40 . 2012-11-15 04:17 3671184 ----a-w- c:\windows\system32\RtkAPO64.dll
2012-10-08 12:19 . 2012-11-15 08:38 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-10-08 11:42 . 2012-11-15 08:38 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-10-08 11:31 . 2012-11-15 08:38 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 11:24 . 2012-11-15 08:38 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-10-08 11:23 . 2012-11-15 08:38 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 11:22 . 2012-11-15 08:38 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 11:22 . 2012-11-15 08:38 237056 ----a-w- c:\windows\system32\url.dll
2012-10-08 11:20 . 2012-11-15 08:38 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-10-08 11:18 . 2012-11-15 08:38 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 11:17 . 2012-11-15 08:38 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 11:17 . 2012-11-15 08:38 816640 ----a-w- c:\windows\system32\jscript.dll
2012-10-08 11:15 . 2012-11-15 08:38 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-10-08 11:15 . 2012-11-15 08:38 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-10-08 11:13 . 2012-11-15 08:38 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-10-08 11:13 . 2012-11-15 08:38 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-08 11:09 . 2012-11-15 08:38 248320 ----a-w- c:\windows\system32\ieui.dll
2012-10-08 07:56 . 2012-11-15 08:38 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-10-08 07:48 . 2012-11-15 08:38 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-10-08 07:47 . 2012-11-15 08:38 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTProAgent.exe" [2009-12-16 312640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"win32"="c:\kernels\drivers.vbs" [2012-11-29 474]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-03-22 74752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"RemoteControl11"="c:\program files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe" [2011-04-20 234792]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 23:14]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/webhp?sourceid=toolbar-in ... CZ507CZ508
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: browser.startup.homepage - hxxp://home.cloyim.com/
FF - prefs.js: keyword.URL - hxxp://home.cloyim.com/search.php?q=
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-Praetorian - c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe
Wow6432Node-HKLM-Run-Driver Genius - (no file)
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2012-12-31 13:49:35 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 97 426 436 096
Po spuštění: Volných bajtů: 97 401 065 472
.
- - End Of File - - A6FBCD824191A1561C4510792A8D2DBA
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.14342 [GMT 1:00]
Spuštěný z: c:\users\Daffoza\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1028.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1031.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1033.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1036.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\1041.msi
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Templates\2052.msi
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\201d3dde
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\4cce1f70
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\L\76603ac3
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000004.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\00000008.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\000000cb.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\80000000.@
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz102F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz104F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10C4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz10EC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1190.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz121B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz12CB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz158B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz15EA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1837.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1848.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A2F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1A4F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz1FEE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz209F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz20FE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz22DB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz230C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz2FC6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3086.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3096.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz33DD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3770.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz38C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3AE1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3CB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D72.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3D73.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz3FB2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz40E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4173.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz43A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4691.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz47AB.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4919.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4C45.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4EFD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F5B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz4F8B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51A6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz51D6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55D0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz55E1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz57EF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz58F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6092.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz60A3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz64AD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz65A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6628.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz67DE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz687F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6880.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz69D2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A00.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6A21.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6C1E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz6F07.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7005.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz707F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz708F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7194.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz71D4.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz741.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7698.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7744.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7805.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz79FD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7A4C.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7E2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz7F70.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8078.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz807B.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8098.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8210.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz82FC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz85D5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz866F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8766.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8786.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz890.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8E15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz8FFA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9097.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90B6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz90E6.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz93CD.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz940D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9459.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz9518.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz95F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trz98F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA368.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA3C7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA81E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA91F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzA96E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzABC.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC67.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAC7F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzACED.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD42.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzAD5F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzADAE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB400.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB474.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzB8C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBB51.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBC75.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBD8F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzBF1A.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC1B0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC24D.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC3F1.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzC8FA.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzCD39.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD258.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD953.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzD9F0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzDB37.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE15.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE3C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE4E3.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE6EE.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE7BF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE94F.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzE9F8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEA57.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBB7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEBBF.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEE6E.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzEF7.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF033.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF246.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF424.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF444.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF479.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4C8.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF4D9.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzF7B5.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFA90.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFAD0.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFC06.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFCD2.tmp
c:\windows\Installer\{440806d4-4b70-35cc-e0ab-37a8dbddc075}\U\trzFFAA.tmp
.
Nakažená kopie c:\windows\system32\services.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-28 do 2012-12-31 )))))))))))))))))))))))))))))))
.
.
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-12-31 12:26 . 2012-12-31 12:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2012-12-29 04:56 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:22 . 2012-10-30 22:51 132864 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-12-25 22:21 . 2012-10-30 22:51 262656 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-25 22:21 . 2012-09-21 09:26 12368 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
2012-12-12 03:41 . 2012-12-13 01:41 16363960 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-12-11 18:16 . 2012-12-11 18:16 -------- d-----w- c:\users\Daffoza\AppData\Local\Activision
2012-12-11 18:11 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\SysWow64\D3DCompiler_43.dll
2012-12-11 18:11 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\SysWow64\D3DX9_43.dll
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Logitech
2012-12-11 00:40 . 2012-12-11 00:40 -------- d-----w- c:\program files\Common Files\Logitech
2012-12-08 20:56 . 2012-12-08 20:56 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Mozilla-Cache
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Party
2012-12-08 20:55 . 2012-12-08 20:55 -------- d-----w- C:\Programs
2012-12-06 23:12 . 2012-12-17 23:07 -------- d-----w- c:\users\Administrator
2012-12-04 20:56 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2012-12-04 20:56 . 2012-12-12 03:04 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:55 . 2012-12-15 06:00 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-04 20:55 . 2012-12-04 20:55 -------- d-----w- c:\users\Daffoza\AppData\Local\PunkBuster
2012-12-04 20:53 . 2012-12-04 20:53 -------- d-----w- c:\programdata\Orbit
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\users\Daffoza\AppData\Local\Ubisoft Game Launcher
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-12-04 20:52 . 2012-12-04 20:52 -------- d-----w- c:\program files (x86)\Ubisoft
2012-12-04 20:36 . 2012-12-04 20:36 -------- d-----w- c:\programdata\DAEMON Tools Lite
2012-12-04 19:20 . 2012-12-29 04:46 -------- d-----w- c:\program files (x86)\JDownloader
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\programdata\Dr Glitter
2012-12-04 18:39 . 2012-12-04 18:39 -------- d-----w- c:\program files (x86)\Dr Glitter
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Winamp Detect
2012-12-04 18:33 . 2012-12-04 18:33 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2012-12-04 18:33 . 2012-12-29 00:35 -------- d-----w- c:\program files (x86)\Winamp
2012-12-04 18:33 . 2012-12-04 18:46 -------- d-----w- c:\users\Daffoza\AppData\Roaming\Winamp
2012-12-04 18:23 . 2012-12-04 18:23 -------- d-----w- c:\users\Daffoza\AppData\Local\Macromedia
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Mozilla
2012-12-04 18:22 . 2012-12-04 18:22 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-12-02 13:37 . 2012-12-02 13:37 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
2012-12-02 12:39 . 2012-12-22 22:27 -------- d-----w- c:\windows\KJ
2012-12-02 11:31 . 2012-12-22 22:22 -------- d-----w- c:\users\Daffoza\temp
2012-12-02 10:56 . 2012-12-03 23:22 -------- d-----w- c:\users\Daffoza\AppData\Local\Deployment
2012-12-02 10:56 . 2012-12-02 10:56 -------- d-----w- c:\users\Daffoza\AppData\Local\Apps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-29 23:14 . 2012-10-30 02:05 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-12-29 23:14 . 2012-10-30 02:05 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-15 08:35 . 2012-10-24 18:03 66395536 ----a-w- c:\windows\system32\MRT.exe
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-10-17 00:31 . 2012-11-29 04:35 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8EE1F503-E65A-4AB3-A956-E2A9330096AE}\mpengine.dll
2012-10-09 18:17 . 2012-11-15 08:34 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-15 08:34 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-15 08:34 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-15 08:34 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-09 16:16 . 2012-11-15 04:17 2700896 ----a-w- c:\windows\system32\FMAPO64.dll
2012-10-08 16:40 . 2012-11-15 04:17 3671184 ----a-w- c:\windows\system32\RtkAPO64.dll
2012-10-08 12:19 . 2012-11-15 08:38 17811968 ----a-w- c:\windows\system32\mshtml.dll
2012-10-08 11:42 . 2012-11-15 08:38 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-10-08 11:31 . 2012-11-15 08:38 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 11:24 . 2012-11-15 08:38 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-10-08 11:23 . 2012-11-15 08:38 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 11:22 . 2012-11-15 08:38 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 11:22 . 2012-11-15 08:38 237056 ----a-w- c:\windows\system32\url.dll
2012-10-08 11:20 . 2012-11-15 08:38 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-10-08 11:18 . 2012-11-15 08:38 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 11:17 . 2012-11-15 08:38 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 11:17 . 2012-11-15 08:38 816640 ----a-w- c:\windows\system32\jscript.dll
2012-10-08 11:15 . 2012-11-15 08:38 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-10-08 11:15 . 2012-11-15 08:38 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-10-08 11:13 . 2012-11-15 08:38 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-10-08 11:13 . 2012-11-15 08:38 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-08 11:09 . 2012-11-15 08:38 248320 ----a-w- c:\windows\system32\ieui.dll
2012-10-08 07:56 . 2012-11-15 08:38 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-10-08 07:48 . 2012-11-15 08:38 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-10-08 07:47 . 2012-11-15 08:38 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTProAgent.exe" [2009-12-16 312640]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"googletalk"="c:\program files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"win32"="c:\kernels\drivers.vbs" [2012-11-29 474]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-03-22 74752]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"RemoteControl11"="c:\program files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe" [2011-04-20 234792]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2012-09-21 12368]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2012-10-30 133912]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-31 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 23:14]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.cz/webhp?sourceid=toolbar-in ... CZ507CZ508
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: browser.startup.homepage - hxxp://home.cloyim.com/
FF - prefs.js: keyword.URL - hxxp://home.cloyim.com/search.php?q=
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-Praetorian - c:\users\Daffoza\AppData\Local\Yandex\Updater\praetorian.exe
Wow6432Node-HKLM-Run-ROC_roc_ssl_v12 - c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe
Wow6432Node-HKLM-Run-Driver Genius - (no file)
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Celkový čas: 2012-12-31 13:49:35 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 97 426 436 096
Po spuštění: Volných bajtů: 97 401 065 472
.
- - End Of File - - A6FBCD824191A1561C4510792A8D2DBA
Re: zavirovane pc

- Ulozte nejlepe na Plochu
- U vsech polozek udelejte zatrzitko (tim je oznacite pro skenovani)
- Kliknete na Scan
- Po dokonceni skenu se objevi log FSS.txt ten sem vlozte
Re: zavirovane pc
Farbar Service Scanner Version: 05-01-2013
Ran by Daffoza (administrator) on 14-01-2013 at 23:41:31
Running from "C:\Users\Daffoza\Desktop"
Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Ran by Daffoza (administrator) on 14-01-2013 at 23:41:31
Running from "C:\Users\Daffoza\Desktop"
Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Re: zavirovane pc

Re: zavirovane pc
Rkill 2.4.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 01/14/2013 11:48:33 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 2564) [WD-HEUR]
* C:\Users\Daffoza\Desktop\FSS.exe (PID: 4256) [UP-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 01/14/2013 11:48:47 PM
Execution time: 0 hours(s), 0 minute(s), and 13 seconds(s)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 01/14/2013 11:48:33 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\DAODx.exe (PID: 2564) [WD-HEUR]
* C:\Users\Daffoza\Desktop\FSS.exe (PID: 4256) [UP-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* SharedAccess [Missing ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 01/14/2013 11:48:47 PM
Execution time: 0 hours(s), 0 minute(s), and 13 seconds(s)
Re: zavirovane pc


- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: C:\Windows\tasks\Adobe Flash Player Updater.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job C:\STF33F0.tmp c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Praetorian"=- ""=- "Google Update"=- "DAEMON Tools Pro Agent"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteRanker] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "CTxfiHlp"=- "ROC_roc_ssl_v12"=- "Adobe ARM"=- "SunJavaUpdateSched"=- "googletalk"=- "Driver Genius"=- "win32"=- "WinampAgent"=- "RemoteControl11"=- DDS:: uStart Page = hxxp://www.google.cz/webhp?sourceid=too ... CZ507CZ508 Firefox:: FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\ FF - prefs.js: browser.search.selectedEngine - Search the web FF - prefs.js: browser.startup.homepage - hxxp://home.cloyim.com/ FF - prefs.js: keyword.URL - hxxp://home.cloyim.com/search.php?q= FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers FF - user.js: extensions.autoDisableScopes - 14 RegLock:: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security] ClearJavaCache:: Reboot::
- Ulozte vytvoreny TXT jako CFScript.txt tez primo na c:\
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte


Re: zavirovane pc
ComboFix 13-01-14.01 - Daffoza 15.01.2013 0:19.2.8 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.11496 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\STF33F0.tmp"
"c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-15 do 2013-01-15 )))))))))))))))))))))))))))))))
.
.
2013-01-15 02:31 . 2013-01-15 02:31 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\offreg.dll
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-01-14 23:11 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\mpengine.dll
2013-01-14 14:45 . 2013-01-14 14:45 -------- d-----w- c:\users\UpdatusUser.Daffoza-PC
2013-01-14 04:47 . 2013-01-14 04:47 -------- d-----w- c:\program files (x86)\GotClip
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- c:\programdata\MGS
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- C:\Microgaming
2013-01-11 02:04 . 2013-01-11 02:04 -------- d-----w- c:\program files\VideoLAN
2013-01-11 02:03 . 2013-01-11 02:03 308200 ----a-w- c:\windows\system32\javaws.exe
2013-01-11 02:03 . 2013-01-11 02:03 959976 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\javaw.exe
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\java.exe
2013-01-11 02:03 . 2013-01-11 02:03 -------- d-----w- c:\program files\Java
2013-01-11 02:00 . 2013-01-09 02:19 263064 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\programdata\CanonBJ
2013-01-03 08:55 . 2010-04-24 04:00 83968 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9Z.DLL
2013-01-03 08:55 . 2010-04-24 04:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9Z.DLL
2013-01-03 08:54 . 2010-04-24 04:00 336896 ----a-w- c:\windows\system32\CNMLM9Z.DLL
2013-01-03 08:54 . 2009-04-03 15:01 1321984 ----a-w- c:\windows\system32\CNC550C.dll
2013-01-03 08:54 . 2009-04-03 15:00 92672 ----a-w- c:\windows\system32\CNC550I.dll
2013-01-03 08:54 . 2009-04-03 14:57 106496 ----a-w- c:\windows\SysWow64\CNC550U.dll
2013-01-03 08:54 . 2009-03-19 13:39 328192 ----a-w- c:\windows\system32\CNC550L.dll
2013-01-03 08:54 . 2009-03-19 13:38 303104 ----a-w- c:\windows\SysWow64\CNC550L.dll
2013-01-03 08:54 . 2008-08-25 17:02 17920 ----a-w- c:\windows\system32\CNHMCA6.dll
2013-01-03 08:54 . 2008-08-25 17:02 15872 ----a-w- c:\windows\SysWow64\CNHMCA.dll
2013-01-02 14:36 . 2013-01-02 14:36 -------- d-----w- c:\users\Daffoza\AppData\Local\CyberLink
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2013-01-02 14:36 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-18 19:08 . 2012-12-18 19:08 209112 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 02:41 . 2012-10-30 02:05 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 02:41 . 2012-10-30 02:05 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-05 18:14 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-01-05 18:14 . 2012-12-04 20:55 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-16 16:31 . 2012-10-24 18:03 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-15 06:00 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\users\Daffoza\AppData\Roaming\uTorrent\uTorrent.exe" [2013-01-13 1078096]
"uTorrent Turbo Booster"="c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe" [2008-09-18 371712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-13 01:15 1606760 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 02:41]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - ExtSQL: 2013-01-11 03:01; testpilot@labs.mozilla.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\testpilot@labs.mozilla.com.xpi
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\windows\DAODx.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
c:\program files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
.
**************************************************************************
.
Celkový čas: 2013-01-15 07:23:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-15 06:23
ComboFix2.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 88 270 774 272
Po spuštění: Volných bajtů: 89 271 050 240
.
- - End Of File - - DBCCA4EE24CB777D5E3650EA8C961EF4
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.16329.11496 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\STF33F0.tmp"
"c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\uTorrent Turbo Booster.lnk"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-12-15 do 2013-01-15 )))))))))))))))))))))))))))))))
.
.
2013-01-15 02:31 . 2013-01-15 02:31 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\offreg.dll
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-01-15 00:01 . 2013-01-15 00:01 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2013-01-14 23:11 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C4E85938-A77E-4669-8EBA-38BECDE56C33}\mpengine.dll
2013-01-14 14:45 . 2013-01-14 14:45 -------- d-----w- c:\users\UpdatusUser.Daffoza-PC
2013-01-14 04:47 . 2013-01-14 04:47 -------- d-----w- c:\program files (x86)\GotClip
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- c:\programdata\MGS
2013-01-13 01:16 . 2013-01-13 01:16 -------- d-----w- C:\Microgaming
2013-01-11 02:04 . 2013-01-11 02:04 -------- d-----w- c:\program files\VideoLAN
2013-01-11 02:03 . 2013-01-11 02:03 308200 ----a-w- c:\windows\system32\javaws.exe
2013-01-11 02:03 . 2013-01-11 02:03 959976 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 1081320 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-01-11 02:03 . 2013-01-11 02:03 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\javaw.exe
2013-01-11 02:03 . 2013-01-11 02:03 188392 ----a-w- c:\windows\system32\java.exe
2013-01-11 02:03 . 2013-01-11 02:03 -------- d-----w- c:\program files\Java
2013-01-11 02:00 . 2013-01-09 02:19 263064 ----a-w- c:\program files (x86)\Mozilla Firefox\components\browsercomps.dll
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2013-01-03 08:55 . 2013-01-03 08:55 -------- d--h--w- c:\programdata\CanonBJ
2013-01-03 08:55 . 2010-04-24 04:00 83968 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9Z.DLL
2013-01-03 08:55 . 2010-04-24 04:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9Z.DLL
2013-01-03 08:54 . 2010-04-24 04:00 336896 ----a-w- c:\windows\system32\CNMLM9Z.DLL
2013-01-03 08:54 . 2009-04-03 15:01 1321984 ----a-w- c:\windows\system32\CNC550C.dll
2013-01-03 08:54 . 2009-04-03 15:00 92672 ----a-w- c:\windows\system32\CNC550I.dll
2013-01-03 08:54 . 2009-04-03 14:57 106496 ----a-w- c:\windows\SysWow64\CNC550U.dll
2013-01-03 08:54 . 2009-03-19 13:39 328192 ----a-w- c:\windows\system32\CNC550L.dll
2013-01-03 08:54 . 2009-03-19 13:38 303104 ----a-w- c:\windows\SysWow64\CNC550L.dll
2013-01-03 08:54 . 2008-08-25 17:02 17920 ----a-w- c:\windows\system32\CNHMCA6.dll
2013-01-03 08:54 . 2008-08-25 17:02 15872 ----a-w- c:\windows\SysWow64\CNHMCA.dll
2013-01-02 14:36 . 2013-01-02 14:36 -------- d-----w- c:\users\Daffoza\AppData\Local\CyberLink
2012-12-29 05:00 . 2012-12-29 05:00 -------- d-----w- c:\users\Daffoza\AppData\Roaming\CyberLink
2012-12-29 04:56 . 2013-01-02 14:36 -------- d-----w- c:\programdata\PDVD
2012-12-29 04:55 . 2012-12-29 05:00 -------- d-----w- c:\programdata\CyberLink
2012-12-29 04:55 . 2012-12-29 04:55 -------- d-----w- c:\users\Daffoza\AppData\Local\MediaServer
2012-12-29 04:54 . 2012-12-29 04:54 -------- d-----w- c:\program files (x86)\CyberLink
2012-12-29 04:53 . 2012-12-29 04:53 -------- d-----w- c:\programdata\install_clap
2012-12-29 00:15 . 2012-12-29 00:15 -------- d-----w- c:\program files (x86)\AVSociety
2012-12-28 23:11 . 2012-12-28 23:11 -------- d-----w- c:\users\Daffoza\AppData\Roaming\High Speed Download
2012-12-28 04:36 . 2012-12-29 04:50 -------- d-----w- c:\users\Daffoza\AppData\Local\Morphyre
2012-12-28 04:36 . 2012-12-28 23:36 -------- d-----w- c:\program files (x86)\Morphyre
2012-12-25 22:21 . 2012-10-30 22:51 21136 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-12-22 02:32 . 2012-12-22 02:34 -------- d-----w- c:\users\Daffoza\AppData\Roaming\TrafficPrivacy
2012-12-18 23:16 . 2012-08-15 20:18 110736 ----a-w- c:\windows\system32\drivers\nvelofsfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 24208 ----a-w- c:\windows\system32\drivers\nveloportfltr.sys
2012-12-18 23:16 . 2012-08-15 20:18 272016 ----a-w- c:\windows\system32\drivers\nvelodiskfltr.sys
2012-12-18 23:13 . 2012-12-18 23:13 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-12-18 23:13 . 2012-12-18 23:13 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-12-18 19:08 . 2012-12-18 19:08 209112 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll
2012-12-17 23:12 . 2012-12-17 23:12 -------- d-----w- c:\program files (x86)\7-Zip
2012-12-17 22:42 . 2012-12-17 22:42 -------- d-----w- c:\program files\OCZ Technology Group
2012-12-17 05:38 . 2012-12-17 05:38 -------- d-----w- c:\users\Daffoza\AppData\Local\Programs
2012-12-17 00:54 . 2012-12-17 00:54 -------- d-----w- c:\program files (x86)\Yontoo
2012-12-17 00:54 . 2012-12-22 02:35 -------- d-----w- c:\programdata\Tarma Installer
2012-12-17 00:15 . 2012-10-30 22:51 59728 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-17 00:15 . 2012-10-30 22:51 984144 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-17 00:15 . 2012-10-30 22:51 71600 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-12-17 00:15 . 2012-10-30 22:51 370288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-17 00:15 . 2012-10-30 22:51 25232 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-17 00:15 . 2012-10-30 22:50 285328 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-17 00:15 . 2012-10-15 16:59 54072 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-12-17 00:14 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-17 00:14 . 2012-10-30 22:50 227648 ----a-w- c:\windows\SysWow64\aswBoot.exe
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\programdata\AVAST Software
2012-12-17 00:14 . 2012-12-17 00:14 -------- d-----w- c:\program files\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-09 02:41 . 2012-10-30 02:05 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-01-09 02:41 . 2012-10-30 02:05 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-01-05 18:14 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2013-01-05 18:14 . 2012-12-04 20:55 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2012-12-16 16:31 . 2012-10-24 18:03 67599240 ----a-w- c:\windows\system32\MRT.exe
2012-12-15 06:00 . 2012-12-04 20:56 281688 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2012-12-04 20:52 . 2012-12-04 20:52 76888 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2012-11-29 22:00 . 2012-11-29 22:00 4521 ----a-w- C:\STF33F0.tmp
2012-11-11 18:59 . 2012-11-11 18:59 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-11-11 18:59 . 2012-11-11 18:59 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-11-11 18:59 . 2012-11-11 18:59 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-11-06 13:25 . 2012-11-06 13:27 7261256 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
2012-11-04 21:01 . 2012-11-04 21:01 91648 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 89088 ----a-w- c:\windows\system32\ie4uinit.exe
2012-11-04 21:01 . 2012-11-04 21:01 86528 ----a-w- c:\windows\SysWow64\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 85504 ----a-w- c:\windows\system32\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 82432 ----a-w- c:\windows\system32\icardie.dll
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2012-11-04 21:01 . 2012-11-04 21:01 76800 ----a-w- c:\windows\system32\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2012-11-04 21:01 . 2012-11-04 21:01 74752 ----a-w- c:\windows\SysWow64\iesetup.dll
2012-11-04 21:01 . 2012-11-04 21:01 65024 ----a-w- c:\windows\system32\pngfilt.dll
2012-11-04 21:01 . 2012-11-04 21:01 63488 ----a-w- c:\windows\SysWow64\tdc.ocx
2012-11-04 21:01 . 2012-11-04 21:01 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2012-11-04 21:01 . 2012-11-04 21:01 534528 ----a-w- c:\windows\system32\ieapfltr.dll
2012-11-04 21:01 . 2012-11-04 21:01 49664 ----a-w- c:\windows\system32\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-11-04 21:01 . 2012-11-04 21:01 452608 ----a-w- c:\windows\system32\dxtmsft.dll
2012-11-04 21:01 . 2012-11-04 21:01 448512 ----a-w- c:\windows\system32\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 403248 ----a-w- c:\windows\system32\iedkcs32.dll
2012-11-04 21:01 . 2012-11-04 21:01 39936 ----a-w- c:\windows\system32\iernonce.dll
2012-11-04 21:01 . 2012-11-04 21:01 3695416 ----a-w- c:\windows\system32\ieapfltr.dat
2012-11-04 21:01 . 2012-11-04 21:01 367104 ----a-w- c:\windows\SysWow64\html.iec
2012-11-04 21:01 . 2012-11-04 21:01 35840 ----a-w- c:\windows\SysWow64\imgutil.dll
2012-11-04 21:01 . 2012-11-04 21:01 30720 ----a-w- c:\windows\system32\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 282112 ----a-w- c:\windows\system32\dxtrans.dll
2012-11-04 21:01 . 2012-11-04 21:01 267776 ----a-w- c:\windows\system32\ieaksie.dll
2012-11-04 21:01 . 2012-11-04 21:01 249344 ----a-w- c:\windows\system32\webcheck.dll
2012-11-04 21:01 . 2012-11-04 21:01 23552 ----a-w- c:\windows\SysWow64\licmgr10.dll
2012-11-04 21:01 . 2012-11-04 21:01 222208 ----a-w- c:\windows\system32\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 197120 ----a-w- c:\windows\system32\msrating.dll
2012-11-04 21:01 . 2012-11-04 21:01 165888 ----a-w- c:\windows\system32\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 163840 ----a-w- c:\windows\system32\ieakui.dll
2012-11-04 21:01 . 2012-11-04 21:01 161792 ----a-w- c:\windows\SysWow64\msls31.dll
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 160256 ----a-w- c:\windows\system32\ieakeng.dll
2012-11-04 21:01 . 2012-11-04 21:01 152064 ----a-w- c:\windows\SysWow64\wextract.exe
2012-11-04 21:01 . 2012-11-04 21:01 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2012-11-04 21:01 . 2012-11-04 21:01 149504 ----a-w- c:\windows\system32\occache.dll
2012-11-04 21:01 . 2012-11-04 21:01 145920 ----a-w- c:\windows\system32\iepeers.dll
2012-11-04 21:01 . 2012-11-04 21:01 135168 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 12288 ----a-w- c:\windows\system32\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 11776 ----a-w- c:\windows\SysWow64\mshta.exe
2012-11-04 21:01 . 2012-11-04 21:01 114176 ----a-w- c:\windows\system32\admparse.dll
2012-11-04 21:01 . 2012-11-04 21:01 111616 ----a-w- c:\windows\system32\iesysprep.dll
2012-11-04 21:01 . 2012-11-04 21:01 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2012-11-04 21:01 . 2012-11-04 21:01 10752 ----a-w- c:\windows\system32\msfeedssync.exe
2012-11-04 21:01 . 2012-11-04 21:01 103936 ----a-w- c:\windows\system32\inseng.dll
2012-11-04 21:01 . 2012-11-04 21:01 101888 ----a-w- c:\windows\SysWow64\admparse.dll
2012-10-30 13:53 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2012-10-30 13:53 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2012-10-28 13:15 . 2012-10-28 13:15 31232 ----a-w- c:\windows\system32\drivers\tap0901.sys
2012-10-24 23:42 . 2012-10-24 23:42 466520 ----a-w- c:\windows\system32\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 445016 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2012-10-24 23:42 . 2012-10-24 23:42 123480 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-24 17:13 . 2012-10-24 17:13 2484704 ----a-w- c:\windows\PE_Rom.dll
2012-10-24 16:56 . 2012-10-24 16:56 300 ----a-w- c:\windows\system32\4169.reg
2012-10-24 16:56 . 2012-10-24 16:56 7376 ----a-w- c:\windows\system32\24605.reg
2012-10-24 16:56 . 2012-10-24 16:56 1074 ----a-w- c:\windows\system32\15978.reg
2012-10-24 16:56 . 2012-10-24 16:56 11532 ----a-w- c:\windows\system32\26105.reg
2012-10-24 16:15 . 2012-10-24 16:15 16896 ----a-w- c:\windows\AsTaskSched.dll
2012-10-23 17:41 . 2012-11-15 04:17 4187664 ----a-w- c:\windows\system32\drivers\RTKVHD64.sys
2012-10-23 12:03 . 2012-11-15 04:17 8847360 ----a-w- c:\windows\system32\RCoRes64.dat
2012-10-23 09:08 . 2012-11-15 04:17 115856 ----a-w- c:\windows\system32\RCoInstII64.dll
2012-10-22 17:48 . 2012-11-15 04:17 1269904 ----a-w- c:\windows\system32\RTCOM64.dll
2012-10-18 18:25 . 2012-11-15 00:05 3149824 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2012-10-24 00:36 194928 ----a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\users\Daffoza\AppData\Roaming\uTorrent\uTorrent.exe" [2013-01-13 1078096]
"uTorrent Turbo Booster"="c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe" [2008-09-18 371712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-09-07 43608]
"ASUS AiChargerPlus Execute"="c:\program files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe" [2010-11-08 465536]
"ghost"="c:\program files (x86)\GIGABYTE\GHOST(6980)\ghostopen.exe" [2010-02-08 192000]
"Tilt"="c:\program files (x86)\GIGABYTE\GHOST(6980)\Tilt.exe" [2011-04-20 729088]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
c:\users\Daffoza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
uTorrent Turbo Booster.lnk - c:\program files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-8-25 371712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
R0 nvelofsfltr;nvelofsfltr;c:\windows\system32\DRIVERS\nvelofsfltr.sys [2012-08-15 110736]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 nveloSvc;NVELO Dataplex Service;c:\windows\system32\Dataplex\nveloSvc.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2010-04-29 32768]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2012-11-15 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-11-15 79360]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-11-15 79360]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
R3 netr28x;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys [2009-06-10 620544]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2008-01-01 1255736]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2010-02-15 401696]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys [2010-11-08 14464]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2012-04-11 82560]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2012-04-11 42624]
S0 nvelodiskfltr;NVCache Policy Driver;c:\windows\system32\DRIVERS\nvelodiskfltr.sys [2012-08-15 272016]
S0 nveloportfltr;NVELO Port Filter Driver;c:\windows\system32\DRIVERS\nveloportfltr.sys [2012-08-15 24208]
S0 ocz12xx;ocz12xx;c:\windows\system32\DRIVERS\ocz12xx.sys [2011-09-14 138544]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2012-12-18 834544]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 VDiskBus;ASUS Disk Unlocker;c:\windows\system32\DRIVERS\VDiskBus64.sys [2010-09-21 43136]
S2 {329F96B6-DF1E-4328-BFDA-39EA953C1312};Power Control [2012/12/29 05:56];c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [2011-04-12 09:16 148976]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 ASDiskUnlocker;ASDiskUnlocker;c:\program files (x86)\ASUS\Disk Unlocker\ASPFSVS64.exe [2010-12-02 258688]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
S2 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-04-20 83240]
S2 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-03-31 70952]
S2 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service;c:\program files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe [2011-03-31 312616]
S2 ntk_PowerDVD;ntk_PowerDVD;c:\program files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-04-20 75248]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S3 ASFLTDrv.sys;ASFLTDrv.sys;c:\program files (x86)\ASUS\Disk Unlocker\ASFLTDrv64.sys [2010-09-16 16512]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2012-08-20 138568]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2012-08-20 416072]
S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-10-02 445800]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-10-06 766096]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-13 01:15 1606760 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-01-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 02:41]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-24 16:04]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000Core.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
2013-01-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1651589027-2217478159-1708087879-1000UA.job
- c:\users\Daffoza\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15 16:10]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-10-23 6842512]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 10.0.0.138
TCP: Interfaces\{175416B4-2D00-4AB4-A94B-263660AECE28}: NameServer = 8.8.8.8,8.8.4.4
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\
FF - ExtSQL: 2012-12-04 19:22; yasearch@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\yasearch@yandex.ru
FF - ExtSQL: 2012-12-05 07:54; vb@yandex.ru; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\vb@yandex.ru
FF - ExtSQL: 2012-12-17 01:15; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: 2012-12-17 01:54; torntv@torntv.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\torntv@torntv.com.xpi
FF - ExtSQL: 2012-12-17 01:54; plugin@yontoo.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\plugin@yontoo.com
FF - ExtSQL: 2013-01-11 03:01; testpilot@labs.mozilla.com; c:\users\Daffoza\AppData\Roaming\Mozilla\Firefox\Profiles\nahd6ha2.default\extensions\testpilot@labs.mozilla.com.xpi
FF - user.js: extentions.y2layers.installId - aec20c76-77b4-46c1-92c2-c95033e3d0dd
FF - user.js: extentions.y2layers.defaultEnableAppsList - twittube,buzzdock,YontooNewOffers
FF - user.js: extensions.autoDisableScopes - 14
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{7473B6BD-4691-4744-A82B-7854EB3D70B6} - (no file)
AddRemove-dBpoweramp DSP Effects - c:\windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
AddRemove-{1040143F-FEFB-4B90-8E51-E47D40E14C4E} - c:\program files\Common Files\EAInstaller\Medal of Honor Warfighter\Cleanup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\services\{329F96B6-DF1E-4328-BFDA-39EA953C1312}]
"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
c:\windows\DAODx.exe
c:\program files (x86)\ASUS\AI Suite II\AsRoutineController.exe
c:\program files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
c:\program files (x86)\ASUS\AI Suite II\AI Suite II.exe
c:\program files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
.
**************************************************************************
.
Celkový čas: 2013-01-15 07:23:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-01-15 06:23
ComboFix2.txt 2012-12-31 12:49
.
Před spuštěním: Volných bajtů: 88 270 774 272
Po spuštění: Volných bajtů: 89 271 050 240
.
- - End Of File - - DBCCA4EE24CB777D5E3650EA8C961EF4
Re: zavirovane pc

- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Search
- Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte