
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Počítač zamrzá při startu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Počítač zamrzá při startu
Dobrý den,
počítač z ničeho nic nenabíhá, respektice naběhne, ale nelze nic spustit.
(Edit: Zdá se, že zamrzá po smustění nortonu, Edit2: jednou naběhl => 2. RSIT v odpovědi)
zde je log z normálního režimu, po útrapách se naběhl:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ervd at 2013-03-07 00:15:22
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 272 GB (60%) free of 455 GB
Total RAM: 4030 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:15:30, on 7.3.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\RapooV1Process.exe
C:\Program Files (x86)\Opera\opera.exe
C:\ProgramData\Premium\MagniPic\MagniPic.exe
C:\ProgramData\Premium\MagniPic\MagniPic.exe
C:\Program Files\trend micro\Ervd.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: MagniPic - {CC6084C6-42BE-3EBE-22D0-66C55B335E6B} - C:\ProgramData\MagniPic\511d307d9314a.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [trustGTX14] "C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~2\magnipic\sprote~1.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Brother Resource manager service (brmfrsmg) - Unknown owner - C:\windows\system32\BrmfRsmg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Game Mouse Communication And Update Service V1 (KmGameMouseServiceV1) - UASSOFT.COM - C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MSC.Licensing_11.9 - Flexera Software, Inc. - C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 16204 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
taskeng.exe {1AFAC7BF-10A8-427A-B4BD-4918B810419D}
C:\windows\System32\spoolsv.exe
"taskhost.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\ProgramData\Premium\MagniPic\MagniPic.exe /schedule /profile "C:\ProgramData\Premium\MagniPic\profile.ini"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
C:\windows\system32\BrmfRsmg.exe -service
C:\windows\system32\BrmfRsmg.exe -process -overmain -load -open
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE"
"C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll" /prefetch:1
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
WLIDSvcM.exe 2460
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /c /a /s UserSession2
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
"C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe" RapooV1Process.exe
RapooV1Process.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
-Minimized
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\ProgramData\Premium\MagniPic\MagniPic.exe" /profile "C:\ProgramData\Premium\MagniPic\profile.ini"
"C:\ProgramData\Premium\MagniPic\MagniPic.exe" /profile "C:\ProgramData\Premium\MagniPic\profile.ini"
taskhost.exe $(Arg0)
C:\windows\splwow64.exe 12288
"C:\windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Ervd\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AutoKMS.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\HPCeeScheduleForERVD-HP$.job
C:\windows\tasks\HPCeeScheduleForErvd.job
C:\windows\tasks\MagniPicUpdaterTask{4B84FAAA-0663-4D31-BE8A-3190F52801C0}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 6670496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-08-16 545264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-08-16 193520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL [2012-06-21 210400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-02-24 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC6084C6-42BE-3EBE-22D0-66C55B335E6B}]
MagniPic - C:\ProgramData\MagniPic\511d307d9314a.dll [2013-02-14 118272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-02-24 170912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-09-16 2828072]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-09-01 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-09-01 392472]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-09-01 416024]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-02-15 21709904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess]
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-09-17 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-08-03 1086376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08 18705664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-01-07 446648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-02-25 1602984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-12-10 5629312]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"trustGTX14"=C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe [2009-05-11 4832256]
"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-05-23 103992]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-09-01 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 6670496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-03-06 23:29:13 ----A---- C:\windows\ntbtlog.txt
2013-03-06 23:15:06 ----N---- C:\bootsqm.dat
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\msmpeg2vdec.dll
2013-02-28 00:00:36 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-02-28 00:00:36 ----A---- C:\windows\system32\WMPhoto.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10_1.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\d2d1.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\FntCache.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\d2d1.dll
2013-02-26 13:46:00 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-02-26 13:45:22 ----D---- C:\windows\PCHEALTH
2013-02-26 13:45:22 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2013-02-26 13:42:59 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-02-26 13:42:33 ----D---- C:\Program Files\Microsoft Office
2013-02-26 13:42:10 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2013-02-26 12:56:01 ----A---- C:\windows\AutoKMS.ini
2013-02-26 12:56:01 ----A---- C:\windows\AutoKMS.exe
2013-02-26 11:55:52 ----D---- C:\office
2013-02-25 00:18:35 ----A---- C:\windows\SYSWOW64\sho9680.tmp
2013-02-24 13:32:44 ----A---- C:\windows\SYSWOW64\javaws.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\javaw.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\java.exe
2013-02-24 13:32:08 ----D---- C:\Program Files (x86)\Java
2013-02-17 15:45:23 ----D---- C:\ProgramData\Prometheus
2013-02-17 15:45:23 ----D---- C:\Program Files (x86)\Prometheus
2013-02-14 19:17:04 ----D---- C:\ProgramData\CLSoft LTD
2013-02-14 19:16:58 ----D---- C:\ProgramData\Premium
2013-02-14 19:16:53 ----D---- C:\Program Files (x86)\MagniPic
2013-02-14 19:16:48 ----D---- C:\ProgramData\MagniPic
2013-02-14 19:16:43 ----D---- C:\ProgramData\InstallMate
2013-02-14 19:16:37 ----A---- C:\prefs.js
2013-02-14 19:04:29 ----D---- C:\Program Files (x86)\Conduit
2013-02-14 19:02:26 ----D---- C:\Users\Ervd\AppData\Roaming\ExpressFiles
2013-02-13 11:38:48 ----D---- C:\ProgramData\Blizzard Entertainment
2013-02-13 11:38:48 ----D---- C:\Program Files (x86)\Diablo III
2013-02-13 11:37:24 ----D---- C:\ProgramData\Battle.net
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\ieui.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-02-13 11:26:20 ----A---- C:\windows\system32\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\ieUnatt.exe
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\wininet.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\vbscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\jscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\iertutil.dll
2013-02-13 11:26:16 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-02-13 11:26:14 ----A---- C:\windows\system32\mshtml.dll
2013-02-13 11:26:13 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-02-13 11:26:13 ----A---- C:\windows\system32\ieframe.dll
2013-02-13 11:10:51 ----A---- C:\windows\system32\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 11:10:45 ----A---- C:\windows\system32\win32k.sys
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\user.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-02-13 11:10:44 ----A---- C:\windows\system32\winsrv.dll
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-08 11:08:29 ----RD---- C:\Program Files (x86)\Skype
======List of files/folders modified in the last 1 month======
2013-03-07 00:15:29 ----D---- C:\Program Files\trend micro
2013-03-07 00:15:01 ----D---- C:\windows\Prefetch
2013-03-06 23:57:29 ----D---- C:\windows\SoftwareDistribution
2013-03-06 23:52:27 ----D---- C:\windows\Temp
2013-03-06 23:50:12 ----D---- C:\Windows
2013-03-06 23:47:31 ----A---- C:\windows\SYSWOW64\log.txt
2013-03-06 23:45:36 ----D---- C:\Users\Ervd\AppData\Roaming\Dropbox
2013-03-06 23:45:29 ----D---- C:\windows\inf
2013-03-06 23:45:21 ----D---- C:\ProgramData\PDFC
2013-03-06 23:27:57 ----D---- C:\Program Files (x86)\Steam
2013-03-06 22:47:53 ----SHD---- C:\System Volume Information
2013-03-06 22:44:36 ----D---- C:\windows\system32\config
2013-03-06 08:36:57 ----SHD---- C:\windows\Installer
2013-03-05 20:08:22 ----D---- C:\Users\Ervd\AppData\Roaming\Media Player Classic
2013-03-05 20:08:22 ----D---- C:\Users\Ervd\AppData\Roaming\DAEMON Tools Lite
2013-03-05 20:07:39 ----D---- C:\Program Files\CCleaner
2013-03-05 11:06:35 ----D---- C:\windows\System32
2013-03-05 11:06:35 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-03-04 16:23:33 ----D---- C:\windows\system32\catroot2
2013-03-04 01:29:37 ----D---- C:\ProgramData\FLEXnet
2013-03-03 15:56:35 ----D---- C:\Users\Ervd\AppData\Roaming\Skype
2013-03-01 21:08:51 ----D---- C:\Program Files (x86)\Google
2013-03-01 15:36:05 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-02-28 09:39:33 ----D---- C:\windows\winsxs
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\zh-HK
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-PT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-BR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pl-PL
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\ko-KR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\it-IT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\hu-HU
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\el-GR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-TW
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-CN
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\tr-TR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\sv-SE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ru-RU
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\nl-NL
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ja-JP
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fr-FR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fi-FI
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\es-ES
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\de-DE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\nb-NO
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\en-US
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\da-DK
2013-02-28 09:38:33 ----D---- C:\windows\SysWOW64
2013-02-28 09:38:32 ----D---- C:\windows\system32\zh-HK
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-PT
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-BR
2013-02-28 09:38:32 ----D---- C:\windows\system32\pl-PL
2013-02-28 09:38:32 ----D---- C:\windows\system32\nl-NL
2013-02-28 09:38:32 ----D---- C:\windows\system32\ko-KR
2013-02-28 09:38:32 ----D---- C:\windows\system32\it-IT
2013-02-28 09:38:32 ----D---- C:\windows\system32\hu-HU
2013-02-28 09:38:32 ----D---- C:\windows\system32\el-GR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fr-FR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fi-FI
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-TW
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-CN
2013-02-28 09:38:29 ----D---- C:\windows\system32\tr-TR
2013-02-28 09:38:29 ----D---- C:\windows\system32\sv-SE
2013-02-28 09:38:29 ----D---- C:\windows\system32\es-ES
2013-02-28 09:38:29 ----D---- C:\windows\system32\de-DE
2013-02-28 09:38:29 ----D---- C:\windows\system32\cs-CZ
2013-02-28 09:38:28 ----D---- C:\windows\system32\ru-RU
2013-02-28 09:38:28 ----D---- C:\windows\system32\nb-NO
2013-02-28 09:38:28 ----D---- C:\windows\system32\ja-JP
2013-02-28 09:38:28 ----D---- C:\windows\system32\en-US
2013-02-28 09:38:28 ----D---- C:\windows\system32\da-DK
2013-02-28 00:10:02 ----D---- C:\ProgramData\Microsoft Help
2013-02-28 00:03:16 ----D---- C:\windows\system32\catroot
2013-02-28 00:00:25 ----A---- C:\windows\win.ini
2013-02-27 21:21:02 ----SD---- C:\Users\Ervd\AppData\Roaming\Microsoft
2013-02-27 17:11:46 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2013-02-26 14:34:42 ----D---- C:\windows\Microsoft.NET
2013-02-26 14:34:28 ----RSD---- C:\windows\assembly
2013-02-26 13:57:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-02-26 13:57:27 ----SD---- C:\ProgramData\Microsoft
2013-02-26 13:46:48 ----RSD---- C:\windows\Fonts
2013-02-26 13:46:42 ----D---- C:\windows\ShellNew
2013-02-26 13:46:28 ----D---- C:\Program Files (x86)\MSBuild
2013-02-26 13:46:00 ----RD---- C:\Program Files (x86)
2013-02-26 13:45:59 ----D---- C:\Program Files (x86)\Common Files
2013-02-26 13:45:24 ----D---- C:\Program Files (x86)\Microsoft Office
2013-02-26 13:45:22 ----D---- C:\Program Files (x86)\Microsoft.NET
2013-02-26 13:45:22 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-02-26 13:42:33 ----RD---- C:\Program Files
2013-02-26 13:25:20 ----D---- C:\Users\Ervd\AppData\Roaming\SoftGrid Client
2013-02-26 12:56:02 ----D---- C:\windows\system32\Tasks
2013-02-26 12:56:01 ----D---- C:\windows\Tasks
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\npDeployJava1.dll
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\deployJava1.dll
2013-02-18 11:03:56 ----D---- C:\ProgramData\Adobe
2013-02-17 15:45:23 ----HD---- C:\ProgramData
2013-02-14 01:01:29 ----D---- C:\windows\debug
2013-02-13 13:19:30 ----D---- C:\windows\SYSWOW64\migration
2013-02-13 13:19:30 ----D---- C:\windows\system32\migration
2013-02-13 13:19:30 ----D---- C:\windows\system32\drivers
2013-02-13 13:19:30 ----D---- C:\windows\AppPatch
2013-02-13 13:19:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-13 13:19:29 ----D---- C:\Program Files\Internet Explorer
2013-02-13 11:34:08 ----A---- C:\windows\system32\MRT.exe
2013-02-11 12:04:38 ----D---- C:\windows\Logs
2013-02-08 11:08:39 ----D---- C:\ProgramData\Skype
2013-02-08 10:20:00 ----D---- C:\Program Files (x86)\Opera
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-03-29 451192]
R0 SymEFA;Symantec Extended File Attributes; C:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-01-16 1388120]
R1 ccSet_NIS;Norton Internet Security Settings Manager; C:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-21 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-01-19 484512]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20130305.001\IDSvia64.sys [2013-01-11 513184]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [2012-07-06 37536]
R1 SymIRON;Symantec Iron Driver; C:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
R1 SymNetS;Symantec Network Security WFP Driver; C:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-10-14 10496000]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-10-14 326656]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys [2010-12-03 25912]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.005\ENG64.SYS [2013-01-19 126192]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.005\EX64.SYS [2013-01-19 2087664]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [2012-07-06 737952]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SymEvent;SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [2012-06-09 175736]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-09-16 392752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BrUsbScn;Ovladač skeneru Brother MFC USB; C:\windows\System32\Drivers\BrUsbScn.sys [2009-06-10 14336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-01-02 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-06-30 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2011-02-08 486144]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2013-01-16 27760]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-09-01 12306848]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-10-14 204288]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
R2 brmfrsmg;Brother Resource manager service; C:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
R2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1; C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-08-10 1001376]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 251248]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-09 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 MSC.Licensing_11.9;MSC.Licensing_11.9; C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe [2011-03-15 1775440]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-08-01 724888]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
počítač z ničeho nic nenabíhá, respektice naběhne, ale nelze nic spustit.
(Edit: Zdá se, že zamrzá po smustění nortonu, Edit2: jednou naběhl => 2. RSIT v odpovědi)
zde je log z normálního režimu, po útrapách se naběhl:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ervd at 2013-03-07 00:15:22
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 272 GB (60%) free of 455 GB
Total RAM: 4030 MB (55% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:15:30, on 7.3.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\RapooV1Process.exe
C:\Program Files (x86)\Opera\opera.exe
C:\ProgramData\Premium\MagniPic\MagniPic.exe
C:\ProgramData\Premium\MagniPic\MagniPic.exe
C:\Program Files\trend micro\Ervd.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: MagniPic - {CC6084C6-42BE-3EBE-22D0-66C55B335E6B} - C:\ProgramData\MagniPic\511d307d9314a.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [trustGTX14] "C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~2\magnipic\sprote~1.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Brother Resource manager service (brmfrsmg) - Unknown owner - C:\windows\system32\BrmfRsmg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Game Mouse Communication And Update Service V1 (KmGameMouseServiceV1) - UASSOFT.COM - C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MSC.Licensing_11.9 - Flexera Software, Inc. - C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 16204 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
C:\windows\system32\svchost.exe -k NetworkService
taskeng.exe {1AFAC7BF-10A8-427A-B4BD-4918B810419D}
C:\windows\System32\spoolsv.exe
"taskhost.exe"
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\ProgramData\Premium\MagniPic\MagniPic.exe /schedule /profile "C:\ProgramData\Premium\MagniPic\profile.ini"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
C:\windows\system32\BrmfRsmg.exe -service
C:\windows\system32\BrmfRsmg.exe -process -overmain -load -open
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE"
"C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll" /prefetch:1
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
WLIDSvcM.exe 2460
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /c /a /s UserSession2
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
"C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe" RapooV1Process.exe
RapooV1Process.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
-Minimized
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Opera\opera.exe"
"C:\ProgramData\Premium\MagniPic\MagniPic.exe" /profile "C:\ProgramData\Premium\MagniPic\profile.ini"
"C:\ProgramData\Premium\MagniPic\MagniPic.exe" /profile "C:\ProgramData\Premium\MagniPic\profile.ini"
taskhost.exe $(Arg0)
C:\windows\splwow64.exe 12288
"C:\windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Ervd\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AutoKMS.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\HPCeeScheduleForERVD-HP$.job
C:\windows\tasks\HPCeeScheduleForErvd.job
C:\windows\tasks\MagniPicUpdaterTask{4B84FAAA-0663-4D31-BE8A-3190F52801C0}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 6670496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-08-16 545264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 689040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-08-16 193520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL [2012-06-21 210400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-02-24 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2010-12-21 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC6084C6-42BE-3EBE-22D0-66C55B335E6B}]
MagniPic - C:\ProgramData\MagniPic\511d307d9314a.dll [2013-02-14 118272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-02-24 170912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-09-16 2828072]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-09-01 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-09-01 392472]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-09-01 416024]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-02-15 21709904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess]
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-09-17 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-08-03 1086376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08 18705664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-01-07 446648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-02-25 1602984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-12-10 5629312]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"trustGTX14"=C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe [2009-05-11 4832256]
"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-05-23 103992]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-09-01 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 6670496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2012-08-16 4171424]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-03-06 23:29:13 ----A---- C:\windows\ntbtlog.txt
2013-03-06 23:15:06 ----N---- C:\bootsqm.dat
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\msmpeg2vdec.dll
2013-02-28 00:00:36 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-02-28 00:00:36 ----A---- C:\windows\system32\WMPhoto.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10_1.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\d2d1.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\FntCache.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\d2d1.dll
2013-02-26 13:46:00 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-02-26 13:45:22 ----D---- C:\windows\PCHEALTH
2013-02-26 13:45:22 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2013-02-26 13:42:59 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-02-26 13:42:33 ----D---- C:\Program Files\Microsoft Office
2013-02-26 13:42:10 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2013-02-26 12:56:01 ----A---- C:\windows\AutoKMS.ini
2013-02-26 12:56:01 ----A---- C:\windows\AutoKMS.exe
2013-02-26 11:55:52 ----D---- C:\office
2013-02-25 00:18:35 ----A---- C:\windows\SYSWOW64\sho9680.tmp
2013-02-24 13:32:44 ----A---- C:\windows\SYSWOW64\javaws.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\javaw.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\java.exe
2013-02-24 13:32:08 ----D---- C:\Program Files (x86)\Java
2013-02-17 15:45:23 ----D---- C:\ProgramData\Prometheus
2013-02-17 15:45:23 ----D---- C:\Program Files (x86)\Prometheus
2013-02-14 19:17:04 ----D---- C:\ProgramData\CLSoft LTD
2013-02-14 19:16:58 ----D---- C:\ProgramData\Premium
2013-02-14 19:16:53 ----D---- C:\Program Files (x86)\MagniPic
2013-02-14 19:16:48 ----D---- C:\ProgramData\MagniPic
2013-02-14 19:16:43 ----D---- C:\ProgramData\InstallMate
2013-02-14 19:16:37 ----A---- C:\prefs.js
2013-02-14 19:04:29 ----D---- C:\Program Files (x86)\Conduit
2013-02-14 19:02:26 ----D---- C:\Users\Ervd\AppData\Roaming\ExpressFiles
2013-02-13 11:38:48 ----D---- C:\ProgramData\Blizzard Entertainment
2013-02-13 11:38:48 ----D---- C:\Program Files (x86)\Diablo III
2013-02-13 11:37:24 ----D---- C:\ProgramData\Battle.net
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\ieui.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-02-13 11:26:20 ----A---- C:\windows\system32\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\ieUnatt.exe
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\wininet.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\vbscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\jscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\iertutil.dll
2013-02-13 11:26:16 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-02-13 11:26:14 ----A---- C:\windows\system32\mshtml.dll
2013-02-13 11:26:13 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-02-13 11:26:13 ----A---- C:\windows\system32\ieframe.dll
2013-02-13 11:10:51 ----A---- C:\windows\system32\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 11:10:45 ----A---- C:\windows\system32\win32k.sys
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\user.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-02-13 11:10:44 ----A---- C:\windows\system32\winsrv.dll
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-08 11:08:29 ----RD---- C:\Program Files (x86)\Skype
======List of files/folders modified in the last 1 month======
2013-03-07 00:15:29 ----D---- C:\Program Files\trend micro
2013-03-07 00:15:01 ----D---- C:\windows\Prefetch
2013-03-06 23:57:29 ----D---- C:\windows\SoftwareDistribution
2013-03-06 23:52:27 ----D---- C:\windows\Temp
2013-03-06 23:50:12 ----D---- C:\Windows
2013-03-06 23:47:31 ----A---- C:\windows\SYSWOW64\log.txt
2013-03-06 23:45:36 ----D---- C:\Users\Ervd\AppData\Roaming\Dropbox
2013-03-06 23:45:29 ----D---- C:\windows\inf
2013-03-06 23:45:21 ----D---- C:\ProgramData\PDFC
2013-03-06 23:27:57 ----D---- C:\Program Files (x86)\Steam
2013-03-06 22:47:53 ----SHD---- C:\System Volume Information
2013-03-06 22:44:36 ----D---- C:\windows\system32\config
2013-03-06 08:36:57 ----SHD---- C:\windows\Installer
2013-03-05 20:08:22 ----D---- C:\Users\Ervd\AppData\Roaming\Media Player Classic
2013-03-05 20:08:22 ----D---- C:\Users\Ervd\AppData\Roaming\DAEMON Tools Lite
2013-03-05 20:07:39 ----D---- C:\Program Files\CCleaner
2013-03-05 11:06:35 ----D---- C:\windows\System32
2013-03-05 11:06:35 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-03-04 16:23:33 ----D---- C:\windows\system32\catroot2
2013-03-04 01:29:37 ----D---- C:\ProgramData\FLEXnet
2013-03-03 15:56:35 ----D---- C:\Users\Ervd\AppData\Roaming\Skype
2013-03-01 21:08:51 ----D---- C:\Program Files (x86)\Google
2013-03-01 15:36:05 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-02-28 09:39:33 ----D---- C:\windows\winsxs
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\zh-HK
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-PT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-BR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pl-PL
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\ko-KR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\it-IT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\hu-HU
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\el-GR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-TW
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-CN
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\tr-TR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\sv-SE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ru-RU
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\nl-NL
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ja-JP
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fr-FR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fi-FI
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\es-ES
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\de-DE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\nb-NO
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\en-US
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\da-DK
2013-02-28 09:38:33 ----D---- C:\windows\SysWOW64
2013-02-28 09:38:32 ----D---- C:\windows\system32\zh-HK
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-PT
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-BR
2013-02-28 09:38:32 ----D---- C:\windows\system32\pl-PL
2013-02-28 09:38:32 ----D---- C:\windows\system32\nl-NL
2013-02-28 09:38:32 ----D---- C:\windows\system32\ko-KR
2013-02-28 09:38:32 ----D---- C:\windows\system32\it-IT
2013-02-28 09:38:32 ----D---- C:\windows\system32\hu-HU
2013-02-28 09:38:32 ----D---- C:\windows\system32\el-GR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fr-FR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fi-FI
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-TW
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-CN
2013-02-28 09:38:29 ----D---- C:\windows\system32\tr-TR
2013-02-28 09:38:29 ----D---- C:\windows\system32\sv-SE
2013-02-28 09:38:29 ----D---- C:\windows\system32\es-ES
2013-02-28 09:38:29 ----D---- C:\windows\system32\de-DE
2013-02-28 09:38:29 ----D---- C:\windows\system32\cs-CZ
2013-02-28 09:38:28 ----D---- C:\windows\system32\ru-RU
2013-02-28 09:38:28 ----D---- C:\windows\system32\nb-NO
2013-02-28 09:38:28 ----D---- C:\windows\system32\ja-JP
2013-02-28 09:38:28 ----D---- C:\windows\system32\en-US
2013-02-28 09:38:28 ----D---- C:\windows\system32\da-DK
2013-02-28 00:10:02 ----D---- C:\ProgramData\Microsoft Help
2013-02-28 00:03:16 ----D---- C:\windows\system32\catroot
2013-02-28 00:00:25 ----A---- C:\windows\win.ini
2013-02-27 21:21:02 ----SD---- C:\Users\Ervd\AppData\Roaming\Microsoft
2013-02-27 17:11:46 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2013-02-26 14:34:42 ----D---- C:\windows\Microsoft.NET
2013-02-26 14:34:28 ----RSD---- C:\windows\assembly
2013-02-26 13:57:41 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-02-26 13:57:27 ----SD---- C:\ProgramData\Microsoft
2013-02-26 13:46:48 ----RSD---- C:\windows\Fonts
2013-02-26 13:46:42 ----D---- C:\windows\ShellNew
2013-02-26 13:46:28 ----D---- C:\Program Files (x86)\MSBuild
2013-02-26 13:46:00 ----RD---- C:\Program Files (x86)
2013-02-26 13:45:59 ----D---- C:\Program Files (x86)\Common Files
2013-02-26 13:45:24 ----D---- C:\Program Files (x86)\Microsoft Office
2013-02-26 13:45:22 ----D---- C:\Program Files (x86)\Microsoft.NET
2013-02-26 13:45:22 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-02-26 13:42:33 ----RD---- C:\Program Files
2013-02-26 13:25:20 ----D---- C:\Users\Ervd\AppData\Roaming\SoftGrid Client
2013-02-26 12:56:02 ----D---- C:\windows\system32\Tasks
2013-02-26 12:56:01 ----D---- C:\windows\Tasks
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\npDeployJava1.dll
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\deployJava1.dll
2013-02-18 11:03:56 ----D---- C:\ProgramData\Adobe
2013-02-17 15:45:23 ----HD---- C:\ProgramData
2013-02-14 01:01:29 ----D---- C:\windows\debug
2013-02-13 13:19:30 ----D---- C:\windows\SYSWOW64\migration
2013-02-13 13:19:30 ----D---- C:\windows\system32\migration
2013-02-13 13:19:30 ----D---- C:\windows\system32\drivers
2013-02-13 13:19:30 ----D---- C:\windows\AppPatch
2013-02-13 13:19:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-13 13:19:29 ----D---- C:\Program Files\Internet Explorer
2013-02-13 11:34:08 ----A---- C:\windows\system32\MRT.exe
2013-02-11 12:04:38 ----D---- C:\windows\Logs
2013-02-08 11:08:39 ----D---- C:\ProgramData\Skype
2013-02-08 10:20:00 ----D---- C:\Program Files (x86)\Opera
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-03-29 451192]
R0 SymEFA;Symantec Extended File Attributes; C:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-01-16 1388120]
R1 ccSet_NIS;Norton Internet Security Settings Manager; C:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-21 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-01-19 484512]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20130305.001\IDSvia64.sys [2013-01-11 513184]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [2012-07-06 37536]
R1 SymIRON;Symantec Iron Driver; C:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
R1 SymNetS;Symantec Network Security WFP Driver; C:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-10-14 10496000]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-10-14 326656]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys [2010-12-03 25912]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.005\ENG64.SYS [2013-01-19 126192]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.005\EX64.SYS [2013-01-19 2087664]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [2012-07-06 737952]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SymEvent;SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [2012-06-09 175736]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-09-16 392752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BrUsbScn;Ovladač skeneru Brother MFC USB; C:\windows\System32\Drivers\BrUsbScn.sys [2009-06-10 14336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-01-02 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-06-30 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2011-02-08 486144]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2013-01-16 27760]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-09-01 12306848]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-10-14 204288]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
R2 brmfrsmg;Brother Resource manager service; C:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
R2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1; C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-08-10 1001376]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 251248]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-09 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2012-09-20 30785672]
S3 MSC.Licensing_11.9;MSC.Licensing_11.9; C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe [2011-03-15 1775440]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-08-01 724888]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Naposledy upravil(a) Mc_Murphy dne 07 bře 2013 10:07, celkem upraveno 1 x.
Důvod: Příspěvky pro přehlednost sloučeny do jednoho.
Důvod: Příspěvky pro přehlednost sloučeny do jednoho.
Re: Počítač zamrzá při startu
Dobrý den,
objevil jsem, že mi do počítače rodinný příslušník před týdnem naistaloval nelegalni office 2010 s nějakym virem, snažil jsem se je odinstalovat, ale během odistalace zamrznul počítač. Jsou nějak napůl odinstalované, v seznamu nainstalovaných programů teď nejsou.
1)
Projel jsem pc v nouzovem režimu pomocí programu MWAV, který našel a smazal trojana a 5 spyware. Pak se pc sekl a jediný log, který jsem poté našel je tento:
07 3 2013 12:32:18 - **********************************************************
07 3 2013 12:32:18 - MWAV - eScanAV AntiVirus Toolkit.
07 3 2013 12:32:18 - Copyright © MicroWorld Technologies
07 3 2013 12:32:18 - **********************************************************
07 3 2013 12:32:18 - Source: C:\Users\Ervd\Desktop\mwav.exe
07 3 2013 12:32:18 - Version 14.0.51 (C:\USERS\ERVD\APPDATA\LOCAL\TEMP\MEXETMP.EX~)
07 3 2013 12:32:18 - Log File: C:\Users\Ervd\AppData\Local\Temp\MWAV.LOG
07 3 2013 12:32:18 - MWAV Registered: TRUE
07 3 2013 12:32:18 - User Account: Ervd (Administrator Mode)
07 3 2013 12:32:18 - OS Type: Windows Workstation
07 3 2013 12:32:18 - OS: Windows 7 64-Bit
07 3 2013 12:32:18 - Ver: Personal Service Pack 1 (Build 7601)
07 3 2013 12:32:18 - System Up Time: 25 Minutes, 47 Seconds
07 3 2013 12:32:18 - Parent Process Name : C:\Users\Ervd\AppData\Local\Temp\mexe.com
07 3 2013 12:32:18 - Windows Root Folder: C:\windows
07 3 2013 12:32:18 - Windows Sys32 Folder: C:\windows\system32
07 3 2013 12:32:18 - DHCP NameServer: 8.8.8.8 8.8.4.4
07 3 2013 12:32:18 - Interface0 DHCPNameServer: 192.168.42.129
07 3 2013 12:32:18 - Interface1 DHCPNameServer: 8.8.8.8 8.8.4.4
07 3 2013 12:32:18 - Interface2 DHCPNameServer: 192.168.42.129
07 3 2013 12:32:18 - Interface3 DHCPNameServer: 192.168.42.129
07 3 2013 12:32:18 - Local Fixed Drives: c:\,d:\,e:\
07 3 2013 12:32:18 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
07 3 2013 12:32:18 - [CREATED ZIP FILE: C:\Users\Ervd\AppData\Local\Temp\pinfect.zip]
07 3 2013 12:32:18 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
07 3 2013 12:32:20 - C:\windows\AutoKMS.exe (614400), 26-Feb-2013 [Added C:\windows\AutoKMS.exe to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d2d1.dll (3419136), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\d3d10.dll (1080832), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\d3d10core.dll (220160), 27-Feb-2013 [Added C:\windows\system32\d3d10core.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d10level9.dll (604160), 27-Feb-2013 [Added C:\windows\system32\d3d10level9.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d10warp.dll (1988096), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\d3d10_1.dll (161792), 27-Feb-2013 [Added C:\windows\system32\d3d10_1.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d10_1core.dll (249856), 27-Feb-2013 [Added C:\windows\system32\d3d10_1core.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d11.dll (1504768), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\deployJava1.dll (782240), 24-Feb-2013 [Added C:\windows\system32\deployJava1.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\DWrite.dll (1247744), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\dxgi.dll (293376), 27-Feb-2013 [Added C:\windows\system32\dxgi.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 12:32:20 - C:\windows\system32\FlashPlayerApp.exe (691568), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerApp.exe to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\FlashPlayerCPLApp.cpl (71024), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerCPLApp.cpl to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\javaw.exe (174496), 24-Feb-2013 [Added C:\windows\system32\javaw.exe to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\msmpeg2vdec.dll (2284544), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 12:32:20 - C:\windows\system32\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 12:32:20 - C:\windows\system32\npDeployJava1.dll (861088), 24-Feb-2013 [Added C:\windows\system32\npDeployJava1.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\UIAnimation.dll (187392), 27-Feb-2013 [Added C:\windows\system32\UIAnimation.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\WindowsAccessBridge-32.dll (95648), 24-Feb-2013 [Added C:\windows\system32\WindowsAccessBridge-32.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\WindowsCodecs.dll (1230336), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\WindowsCodecsExt.dll (207872), 27-Feb-2013 [Added C:\windows\system32\WindowsCodecsExt.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\WMPhoto.dll (417792), 27-Feb-2013 [Added C:\windows\system32\WMPhoto.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\XpsGdiConverter.dll (364544), 27-Feb-2013 [Added C:\windows\system32\XpsGdiConverter.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\XpsPrint.dll (1158144), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll (495776), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll (548288), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\BACKUP.12518614.mexe.com (775976), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdc.exe (182792), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdfltlib2k.dll (231944), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus32.dll (85288), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus64.dll (91944), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\DEVCON.EXE (61184), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\encdec.dll (254696), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\erootdrv.sys (22920), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\HxFD03.tmp (877368), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\mexe.com (776488), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\mexe.com to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\msvclnt.dll (201448), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\mwavdwnl.exe (990952), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\MWAVSCAN.COM (775976), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\red32.dll (11496), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Reload.exe (153832), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\setpriv.exe (81640), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\trufos.dll (394408), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.dll to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\trufos.sys (350160), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.sys to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\unregx.exe (83176), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\UPDLL10.DLL (1121512), 02-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\viewtcp.exe (576744), 27-Feb-2013
07 3 2013 12:32:21 - C:\windows\Fonts, 14-Jul-2009 [SR] [Folder]
07 3 2013 12:32:21 - C:\windows\Media, 14-Jul-2009 [SR] [Folder]
07 3 2013 12:32:21 - C:\windows\PCHEALTH, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 12:32:21 - C:\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 12:32:21 - C:\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 12:32:21 - C:\office, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 12:32:21 - C:\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\AVCBack, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\comtypes_cache, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\FtpTemp, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\FtpTempF, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\LOCK, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Log, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Low, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\plugins, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Setup000005ac, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Setup000009e4, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Setup00001dd4, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\TempBK, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\WPDNSE, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Roaming\Microsoft, 09-Jun-2012 [S] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Application Data, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\ArcSoft, 09-Jun-2012 [H] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Desktop, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Documents, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Microsoft, 14-Jul-2009 [S] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Start Menu, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Templates, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\office, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Java, 24-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Analysis Services, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Sync Framework, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Synchronization Services, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Visual Studio 8, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\DESIGNER, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\DW, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\EURO, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Filters, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Help, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\IME14, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSClientDataMgr, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Portal, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\RRLoc14, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Smart Tag, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\THEMES14, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\TRANSLAT, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\VBA, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Server Extensions, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\WORDBRKR, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - *********************************************************************************************
07 3 2013 12:32:21 - Command Line Options Given: /xsign
07 3 2013 12:32:29 - Latest Date of files inside MWAV: Thu Mar 7 12:27:45 2013.
07 3 2013 12:32:29 - Sign Version: 7.45890
07 3 2013 12:32:29 - Loading/Creating FileScan Cache Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\Ervd\AppData\Local\Temp\ESCANDB.LOG]
07 3 2013 12:32:29 - Loaded/Created FileScan Cache Database...
07 3 2013 12:32:29 - Loading AV Library [DB]...
07 3 2013 12:32:32 - ArchiveScan: DISABLED
07 3 2013 12:32:34 - AV Library Loaded [DB-DIRECT].
07 3 2013 12:32:34 - MWAV doing self scanning...
07 3 2013 12:32:34 - MWAV files are clean.
07 3 2013 12:32:38 - ArchiveScan: DISABLED
07 3 2013 12:32:38 - Virus Database Date: 07 Mar 2013
07 3 2013 12:32:38 - Virus Database Count: 9224033
07 3 2013 12:32:38 - Scheduler Service not enabled. Scheduler Feature Disabled.
07 3 2013 12:33:00 - ArchiveScan: ENABLED
07 3 2013 12:33:01 - **********************************************************
07 3 2013 12:33:01 - MWAV - eScanAV AntiVirus Toolkit.
07 3 2013 12:33:01 - Copyright © MicroWorld Technologies
07 3 2013 12:33:01 -
07 3 2013 12:33:01 - Support: support@escanav.com
07 3 2013 12:33:01 - Web: http://www.escanav.com
07 3 2013 12:33:01 - **********************************************************
07 3 2013 12:33:01 - Version 14.0.51[DB] (C:\USERS\ERVD\APPDATA\LOCAL\TEMP\MEXETMP.EX~)
07 3 2013 12:33:01 - Log File: C:\Users\Ervd\AppData\Local\Temp\MWAV.LOG
07 3 2013 12:33:01 - User Account: Ervd (Administrator Mode)
07 3 2013 12:33:01 - Parent Process Name : C:\Users\Ervd\AppData\Local\Temp\mexe.com
07 3 2013 12:33:01 - Windows Root Folder: C:\windows
07 3 2013 12:33:01 - Windows Sys32 Folder: C:\windows\system32
07 3 2013 12:33:01 - OS: Windows 7 64-Bit
07 3 2013 12:33:01 - Ver: Personal Service Pack 1 (Build 7601)
07 3 2013 12:33:01 - Latest Date of files inside MWAV: Thu Mar 7 12:27:45 2013.
07 3 2013 12:33:01 - Sign Version: 7.45890
07 3 2013 12:33:08 - Scheduler Service not enabled. Scheduler Feature Disabled.
07 3 2013 12:33:08 - Options Selected by User:
07 3 2013 12:33:08 - Memory Check: Enabled
07 3 2013 12:33:08 - Registry Check: Enabled
07 3 2013 12:33:08 - StartUp Folder Check: Enabled
07 3 2013 12:33:08 - System Folder Check: Enabled
07 3 2013 12:33:08 - Services Check: Enabled
07 3 2013 12:33:08 - Scan Spyware: Enabled
07 3 2013 12:33:08 - Scan Archives: Enabled
07 3 2013 12:33:08 - Drive Check: Disabled
07 3 2013 12:33:08 - All Drive Check :Enabled
07 3 2013 12:33:08 - Folder Check: Disabled
07 3 2013 12:33:08 - SCAN: All_Files
07 3 2013 12:33:08 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
07 3 2013 12:33:09 - Scanning DNS Records...
07 3 2013 12:33:09 - Scanning Master Boot Record (User)...
07 3 2013 12:33:09 - Scanning Logical Boot Records...
07 3 2013 12:33:09 - ***** Scanning For Hidden Rootkit Processes *****
07 3 2013 12:33:09 - ***** Scanning For Hidden Rootkit Services *****
07 3 2013 12:33:15 - ***** Scanning Memory Files *****
07 3 2013 12:33:19 - ***** Scanning Registry Files *****
07 3 2013 12:33:23 - ***** Scanning StartUp Folders *****
07 3 2013 12:34:52 - Scanning File C:\ProgramData\Premium\MagniPic\MagniPic.exe
07 3 2013 12:34:52 - File C:\ProgramData\Premium\MagniPic\MagniPic.exe infected by "Trojan.Agent.AYUV (DB)" Virus! Action Taken: File Deleted.
07 3 2013 12:36:04 - Scanning File C:\ProgramData\..\hiberfil.sys
07 3 2013 12:36:04 - ERROR(3)!!! ScanFile fails for C:\ProgramData\..\hiberfil.sys
07 3 2013 12:36:04 - Scanning File C:\ProgramData\..\pagefile.sys
07 3 2013 12:36:04 - ERROR(3)!!! ScanFile fails for C:\ProgramData\..\pagefile.sys
07 3 2013 12:36:05 - ***** Scanning Service Files *****
07 3 2013 12:36:23 - ***** Scanning Registry and File system for Adware/Spyware *****
07 3 2013 12:36:24 - Loading Spyware Signatures from new External Database [Name: C:\Users\Ervd\AppData\Local\Temp\spydb.avs, Size: 463768]...
07 3 2013 12:36:24 - Indexed Spyware Databases Successfully Created...
07 3 2013 12:36:52 - Offending file found: C:\ProgramData\InstallMate\MagniPic\_Setupx.dll
07 3 2013 12:36:52 - System found infected with DealHelper.com Spyware/Adware (_Setupx.dll)! Action taken: File Deleted.
07 3 2013 12:36:52 - Object "DealHelper.com Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:52 - Offending file found: C:\ProgramData\InstallMate\{4831C39B-9776-496F-AB84-DF5493D2E16D}\_Setupx.dll
07 3 2013 12:36:52 - System found infected with DealHelper.com Spyware/Adware (_Setupx.dll)! Action taken: File Deleted.
07 3 2013 12:36:52 - Object "DealHelper.com Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:53 - Offending file found: C:\ProgramData\InstallMate\{9E0E9390-C57C-4A8C-A867-8D5E45EDB166}\_Setupx.dll
07 3 2013 12:36:53 - System found infected with DealHelper.com Spyware/Adware (_Setupx.dll)! Action taken: File Deleted.
07 3 2013 12:36:53 - Object "DealHelper.com Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:53 - Offending file found: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Logs\LU.dat
07 3 2013 12:36:53 - System found infected with ImIServer IEPlugin Spyware/Adware (LU.dat)! Action taken: File Deleted.
07 3 2013 12:36:53 - Object "ImIServer IEPlugin Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:54 - ***** Scanning Registry Files *****
07 3 2013 12:36:54 - Scanning File C:\ProgramData\MagniPic\511d307d9314a.dll (????)
07 3 2013 12:36:54 - Scanning File c:\Program Files (x86)\MagniPic\sprotector.dll (????)
07 3 2013 12:36:54 - Scanning File C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe (????)
07 3 2013 12:36:54 - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
07 3 2013 12:36:54 - ** Deleted Value of "NoActiveDesktop" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer". Its value was DWORD:1.
07 3 2013 12:36:54 - ** Deleted Value of "ForceActiveDesktopOn" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer". Its value was DWORD:0.
07 3 2013 12:36:54 - ** Deleted Value of "NoComponents" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop". Its value was DWORD:1.
07 3 2013 12:36:54 - ** Deleted Value of "NoAddingComponents" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop". Its value was DWORD:1.
07 3 2013 12:36:54 - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
07 3 2013 12:36:54 - ***** Scanning System32 Folders *****
07 3 2013 12:36:55 - Scanning File C:\windows\AutoKMS.exe
07 3 2013 12:36:55 - File C:\windows\AutoKMS.exe infected by "Application.Crack.PDE (DB)" Virus! Action Taken: File Renamed.
07 3 2013 12:38:18 - ***** Scanning All Drives *****
07 3 2013 12:38:18 - ***** C:,D:,E: *****
07 3 2013 12:38:18 - Scanning C:\ Drive
07 3 2013 12:38:20 - Scanning File C:\hp\HPQWare\Favs\da-DK\all\HP\Fa Skype – Hent det gratis.url
07 3 2013 12:38:20 - ERROR(3)!!! ScanFile fails for C:\hp\HPQWare\Favs\da-DK\all\HP\Fa Skype – Hent det gratis.url
07 3 2013 12:38:20 - Scanning File C:\hp\HPQWare\Favs\nb-NO\all\HP\Fa Skype – Last ned gratis.url
07 3 2013 12:38:20 - ERROR(3)!!! ScanFile fails for C:\hp\HPQWare\Favs\nb-NO\all\HP\Fa Skype – Last ned gratis.url
07 3 2013 12:38:21 - Scanning File C:\hp\HPQWare\StartMenuLink\tr-TR\all\Online Services\Huddle alanlari.lnk
07 3 2013 12:38:21 - ERROR(3)!!! ScanFile fails for C:\hp\HPQWare\StartMenuLink\tr-TR\all\Online Services\Huddle alanlari.lnk
07 3 2013 13:03:35 - ScanFile (C:\swsetup\ATISMRW7\Packages\Drivers\Display\W76A_INF\B126813\atioglxx.dl_) took 5008 ms
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{045a4300-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{045a4300-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{045a4459-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{045a4459-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{1dd949f5-8702-11e2-9904-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{1dd949f5-8702-11e2-9904-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{52d513d7-80e8-11e2-9154-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{52d513d7-80e8-11e2-9154-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{f16be377-85c4-11e2-b390-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{f16be377-85c4-11e2-b390-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:38 - C:\Users\Ervd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:05:38 - ERROR(3)!!! ScanFile fails for C:\Users\Ervd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
07 3 2013 13:10:52 - C:\Users\Ervd\ntuser.dat.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:10:52 - ERROR(3)!!! ScanFile fails for C:\Users\Ervd\ntuser.dat.LOG1
07 3 2013 13:15:47 - C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:15:47 - ERROR(3)!!! ScanFile fails for C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
07 3 2013 13:15:48 - C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:15:48 - ERROR(3)!!! ScanFile fails for C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
07 3 2013 13:17:54 - C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb not Scanned. Possibly password protected...
07 3 2013 13:17:54 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
07 3 2013 13:17:54 - C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb not Scanned. Possibly password protected...
07 3 2013 13:17:54 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
07 3 2013 13:36:32 - Please Wait Exiting Application...
07 3 2013 13:36:32 - Scanning D:\ Drive
07 3 2013 13:36:32 - ***** Scanning complete. *****
07 3 2013 13:36:32 - Total Objects Scanned: 267422
07 3 2013 13:36:32 - Total Critical Objects: 6
07 3 2013 13:36:32 - Total Disinfected Objects: 0
07 3 2013 13:36:32 - Total Objects Renamed: 1
07 3 2013 13:36:32 - Total Deleted Objects: 5
07 3 2013 13:36:32 - Total Errors: 0
07 3 2013 13:36:32 - Time Elapsed: 01:02:31
07 3 2013 13:36:32 - Virus Database Date: 07 Mar 2013
07 3 2013 13:36:32 - Virus Database Count: 9224033
07 3 2013 13:36:32 - Scan Completed.
07 3 2013 13:36:56 - Virus Database Date: 07 Mar 2013
07 3 2013 13:36:56 - Virus Database Count: 9224033
07 3 2013 13:36:56 - Scheduler Service not enabled. Scheduler Feature Disabled.
07 3 2013 13:37:01 - Uninitializing Scanner (3)...
07 3 2013 13:37:02 - Freeing Libraries (3)...
07 3 2013 13:37:02 - AV Library Unloaded (3)...
07 3 2013 13:37:03 - [Made copy of PINFECT.ZIP (3962822 Bytes) as C:\Users\Ervd\Documents\pinfect.zip]
07 3 2013 13:46:52 - **********************************************************
07 3 2013 13:46:52 - MWAV - eScanAV AntiVirus Toolkit.
07 3 2013 13:46:52 - Copyright © MicroWorld Technologies
07 3 2013 13:46:52 - **********************************************************
07 3 2013 13:46:52 - Version 14.0.51 (C:\USERS\ERVD\APPDATA\LOCAL\TEMP\MWAVSCAN.EXE)
07 3 2013 13:46:52 - Log File: C:\Users\Ervd\AppData\Local\Temp\MWAV.LOG
07 3 2013 13:46:52 - Last Scan Date and Time: 07.03.2013 12:33:08
07 3 2013 13:46:52 - MWAV Registered: TRUE
07 3 2013 13:46:52 - User Account: Ervd (Administrator Mode)
07 3 2013 13:46:52 - OS Type: Windows Workstation
07 3 2013 13:46:52 - OS: Windows 7 64-Bit
07 3 2013 13:46:52 - Ver: Personal Service Pack 1 (Build 7601)
07 3 2013 13:46:52 - System Up Time: 1 Hour, 40 Minutes, 21 Seconds
07 3 2013 13:46:52 - Parent Process Name : c:\Windows\explorer.exe
07 3 2013 13:46:52 - Windows Root Folder: C:\windows
07 3 2013 13:46:52 - Windows Sys32 Folder: C:\windows\system32
07 3 2013 13:46:52 - DHCP NameServer: 8.8.8.8 8.8.4.4
07 3 2013 13:46:52 - Interface0 DHCPNameServer: 192.168.42.129
07 3 2013 13:46:52 - Interface1 DHCPNameServer: 8.8.8.8 8.8.4.4
07 3 2013 13:46:52 - Interface2 DHCPNameServer: 192.168.42.129
07 3 2013 13:46:52 - Interface3 DHCPNameServer: 192.168.42.129
07 3 2013 13:46:52 - Local Fixed Drives: c:\,d:\,e:\
07 3 2013 13:46:52 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
07 3 2013 13:46:52 - [CREATED ZIP FILE: C:\Users\Ervd\AppData\Local\Temp\pinfect.zip]
07 3 2013 13:46:52 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
07 3 2013 13:46:53 - C:\windows\system32\d2d1.dll (3419136), 27-Feb-2013
07 3 2013 13:46:53 - C:\windows\system32\d3d10.dll (1080832), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\d3d10core.dll (220160), 27-Feb-2013 [Added C:\windows\system32\d3d10core.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d10level9.dll (604160), 27-Feb-2013 [Added C:\windows\system32\d3d10level9.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d10warp.dll (1988096), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\d3d10_1.dll (161792), 27-Feb-2013 [Added C:\windows\system32\d3d10_1.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d10_1core.dll (249856), 27-Feb-2013 [Added C:\windows\system32\d3d10_1core.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d11.dll (1504768), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\deployJava1.dll (782240), 24-Feb-2013 [Added C:\windows\system32\deployJava1.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\DWrite.dll (1247744), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\dxgi.dll (293376), 27-Feb-2013 [Added C:\windows\system32\dxgi.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 13:46:54 - C:\windows\system32\FlashPlayerApp.exe (691568), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerApp.exe to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\FlashPlayerCPLApp.cpl (71024), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerCPLApp.cpl to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\javaw.exe (174496), 24-Feb-2013 [Added C:\windows\system32\javaw.exe to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\msmpeg2vdec.dll (2284544), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 13:46:54 - C:\windows\system32\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 13:46:54 - C:\windows\system32\npDeployJava1.dll (861088), 24-Feb-2013 [Added C:\windows\system32\npDeployJava1.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\UIAnimation.dll (187392), 27-Feb-2013 [Added C:\windows\system32\UIAnimation.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\WindowsAccessBridge-32.dll (95648), 24-Feb-2013 [Added C:\windows\system32\WindowsAccessBridge-32.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\WindowsCodecs.dll (1230336), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\WindowsCodecsExt.dll (207872), 27-Feb-2013 [Added C:\windows\system32\WindowsCodecsExt.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\windows\system32\WMPhoto.dll (417792), 27-Feb-2013 [Added C:\windows\system32\WMPhoto.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\windows\system32\XpsGdiConverter.dll (364544), 27-Feb-2013 [Added C:\windows\system32\XpsGdiConverter.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\windows\system32\XpsPrint.dll (1158144), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll (495776), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll (548288), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\BACKUP.12518614.mexe.com (775976), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdc.exe (182792), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdfltlib2k.dll (231944), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus32.dll (85288), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus64.dll (91944), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\DEVCON.EXE (61184), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\encdec.dll (254696), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\erootdrv.sys (22920), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\HxFD03.tmp (877368), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\mexe.com (776488), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\mexe.com to ZIP FILE]
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\msvclnt.dll (201448), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\mwavdwnl.exe (990952), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\MWAVSCAN.COM (775976), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\red32.dll (11496), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Reload.exe (153832), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\setpriv.exe (81640), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\trufos.dll (394408), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.dll to ZIP FILE]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\trufos.sys (350160), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.sys to ZIP FILE]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\unregx.exe (83176), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\UPDLL10.DLL (1121512), 02-Mar-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\viewtcp.exe (576744), 27-Feb-2013
07 3 2013 13:46:56 - C:\windows\Fonts, 14-Jul-2009 [SR] [Folder]
07 3 2013 13:46:56 - C:\windows\logo_1.exe, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\Media, 14-Jul-2009 [SR] [Folder]
07 3 2013 13:46:56 - C:\windows\PCHEALTH, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\RUNDL132.EXE, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\VDLL.DLL, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\system32\runouce.exe, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 13:46:56 - C:\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 13:46:56 - C:\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 13:46:56 - C:\office, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 13:46:56 - C:\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\AVCBack, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\comtypes_cache, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\FBackUp, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\FtpTemp, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\FtpTempF, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\LOCK, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Log, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Low, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\plugins, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Setup000005ac, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Setup000009e4, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Setup00001dd4, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\TempBK, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\WPDNSE, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Roaming\Microsoft, 09-Jun-2012 [S] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Application Data, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\ArcSoft, 09-Jun-2012 [H] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Desktop, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Documents, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Microsoft, 14-Jul-2009 [S] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Start Menu, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Templates, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\office, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Java, 24-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Analysis Services, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Sync Framework, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Synchronization Services, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Visual Studio 8, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\DESIGNER, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\DW, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\EURO, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Filters, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Help, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\IME14, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSClientDataMgr, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Portal, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\RRLoc14, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Smart Tag, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\THEMES14, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\TRANSLAT, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\VBA, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Server Extensions, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\WORDBRKR, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - *********************************************************************************************
07 3 2013 13:47:41 - Latest Date of files inside MWAV: Thu Mar 7 12:27:45 2013.
07 3 2013 13:47:41 - Sign Version: 7.45890
07 3 2013 13:47:41 - Loading/Creating FileScan Cache Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\Ervd\AppData\Local\Temp\ESCANDB.LOG]
07 3 2013 13:47:42 - Loaded/Created FileScan Cache Database...
07 3 2013 13:47:42 - Loading AV Library [DB]...
07 3 2013 13:47:53 - ArchiveScan: ENABLED
07 3 2013 13:47:55 - AV Library Loaded [DB-DIRECT].
07 3 2013 13:47:55 - MWAV doing self scanning...
07 3 2013 13:47:56 - MWAV files are clean.
07 3 2013 13:47:56 - ArchiveScan: ENABLED
07 3 2013 13:47:56 - Virus Database Date: 07 Mar 2013
07 3 2013 13:47:56 - Virus Database Count: 9224033
07 3 2013 13:47:56 - Scheduler Service not enabled. Scheduler Feature Disabled.
2)
Dále jsem v adresáři C:\Users\Ervd\AppData\Local\Temp\Log objevil (při hledání logu z MWAV) soubor download.txt, v němž je tento text:
*******************************************************************************
Automatic HTTP Downloader Ver 4.0.2.209.
-------------------------------------------------------------------------------
Check eUpdate.ini Settings.
7.3.2013 12:28:47 Starting Manual HTTP session to host http://www.microworldsystems.com/pub/update
07-3-2013 12:28:47 Trying to connect with Ini Settings.
07-3-2013 12:28:47 Connection Successful with Ini Settings.
Connecting to HTTP host <Direct connection>
Requested file name and size information...
Starting Anti-Virus Download...
Successfully Downloaded file - update.txt (130)
Successfully Downloaded file - emalware.053 (160758)
Successfully Downloaded file - emalware.041 (134538)
Successfully Downloaded file - emalware.090 (104697)
Successfully Downloaded file - emalware.524 (298560)
Successfully Downloaded file - emalware.113 (146414)
Successfully Downloaded file - instyler.xmd (25197)
Successfully Downloaded file - emalware.073 (162488)
Successfully Downloaded file - emalware.025 (132546)
Successfully Downloaded file - emalware.012 (116551)
Successfully Downloaded file - emalware.111 (212781)
Successfully Downloaded file - emalware.054 (181380)
Successfully Downloaded file - emalware.350 (87713)
Successfully Downloaded file - emalware.080 (51691)
Successfully Downloaded file - emalware.325 (98299)
Successfully Downloaded file - cran.ivd (67613)
Successfully Downloaded file - emalware.015 (96268)
Successfully Downloaded file - emalware.028 (103805)
Successfully Downloaded file - cevakrnl.ivd (54171)
Successfully Downloaded file - emalware.330 (77009)
Successfully Downloaded file - emalware.022 (124431)
Successfully Downloaded file - emalware.320 (125146)
Successfully Downloaded file - emalware.522 (325772)
Successfully Downloaded file - emalware.085 (64272)
Successfully Downloaded file - emalware.345 (151848)
Successfully Downloaded file - emalware.321 (112786)
Successfully Downloaded file - disp.xmd (29123)
Successfully Downloaded file - e_spyw.i00 (177085)
Successfully Downloaded file - cevakrnl.rv5 (222128)
Successfully Downloaded file - emalware.319 (120443)
Successfully Downloaded file - emalware.068 (116348)
Successfully Downloaded file - emalware.032 (84126)
Successfully Downloaded file - emalware.317 (107755)
Successfully Downloaded file - emalware.029 (103857)
Successfully Downloaded file - emalware.007 (142680)
Successfully Downloaded file - emalware.360 (108398)
Successfully Downloaded file - emalware.016 (103103)
Successfully Downloaded file - emalware.327 (98629)
Successfully Downloaded file - e_spyw.i20 (114846)
Successfully Downloaded file - emalware.078 (151697)
Successfully Downloaded file - emalware.056 (207950)
Successfully Downloaded file - emalware.003 (148096)
Successfully Downloaded file - emalware.115 (162324)
Successfully Downloaded file - emalware.309 (99972)
Successfully Downloaded file - e_spyw.i07 (333779)
Successfully Downloaded file - emalware.083 (65382)
Successfully Downloaded file - emalware.368 (143094)
Successfully Downloaded file - emalware.116 (156366)
Successfully Downloaded file - emalware.058 (150356)
Successfully Downloaded file - emalware.358 (122622)
Successfully Downloaded file - emalware.020 (136919)
Successfully Downloaded file - e_spyw.i15 (160870)
Successfully Downloaded file - e_spyw.i17 (185224)
Successfully Downloaded file - emalware.337 (99388)
Successfully Downloaded file - emalware.341 (125223)
Successfully Downloaded file - emalware.338 (113350)
Successfully Downloaded file - e_spyw.i12 (176794)
Successfully Downloaded file - emalware.086 (52172)
Successfully Downloaded file - emalware.017 (115747)
Successfully Downloaded file - emalware.063 (230311)
Successfully Downloaded file - emalware.031 (75843)
Successfully Downloaded file - e_spyw.i10 (161995)
Successfully Downloaded file - cevakrnl.rv3 (758058)
Successfully Downloaded file - emalware.064 (199955)
Successfully Downloaded file - emalware.347 (131010)
Successfully Downloaded file - emalware.322 (113318)
Successfully Downloaded file - emalware.042 (119724)
Successfully Downloaded file - emalware.043 (142291)
Successfully Downloaded file - emalware.070 (139483)
Successfully Downloaded file - emalware.076 (162805)
Successfully Downloaded file - emalware.014 (122245)
Successfully Downloaded file - emalware.097 (329232)
Successfully Downloaded file - emalware.100 (185139)
Successfully Downloaded file - emalware.108 (142873)
Successfully Downloaded file - emalware.059 (222408)
Successfully Downloaded file - emalware.035 (117289)
Successfully Downloaded file - emalware.102 (116189)
Successfully Downloaded file - emalware.027 (186169)
Successfully Downloaded file - emalware.335 (101885)
Successfully Downloaded file - emalware.066 (167782)
Successfully Downloaded file - emalware.362 (182337)
Successfully Downloaded file - cevakrnl.rv1 (125901)
Successfully Downloaded file - emalware.039 (175989)
Successfully Downloaded file - e_spyw.i02 (237616)
Successfully Downloaded file - emalware.044 (129585)
Successfully Downloaded file - emalware.101 (144549)
Successfully Downloaded file - emalware.312 (140678)
Successfully Downloaded file - e_spyw.i04 (198378)
Successfully Downloaded file - zip.xmd (41182)
Successfully Downloaded file - emalware.092 (162274)
Successfully Downloaded file - emalware.359 (123762)
Successfully Downloaded file - emalware.098 (309449)
Successfully Downloaded file - emalware.033 (82297)
Successfully Downloaded file - emalware.026 (116146)
Successfully Downloaded file - emalware.331 (119295)
Successfully Downloaded file - emalware.011 (109119)
Successfully Downloaded file - emalware.055 (208988)
Successfully Downloaded file - emalware.313 (106611)
Successfully Downloaded file - emalware.529 (322010)
Successfully Downloaded file - emalware.316 (140777)
Successfully Downloaded file - emalware.088 (46601)
Successfully Downloaded file - emalware.046 (122051)
Successfully Downloaded file - emalware.030 (98926)
Successfully Downloaded file - emalware.334 (120300)
Successfully Downloaded file - e_spyw.i16 (162390)
Successfully Downloaded file - e_spyw.i03 (241062)
Successfully Downloaded file - emalware.339 (124073)
Successfully Downloaded file - emalware.021 (90826)
Successfully Downloaded file - emalware.103 (132431)
Successfully Downloaded file - emalware.095 (172588)
Successfully Downloaded file - emalware.365 (214937)
Successfully Downloaded file - emalware.308 (107313)
Successfully Downloaded file - emalware.075 (192229)
Successfully Downloaded file - emalware.001 (76550)
Successfully Downloaded file - emalware.038 (118810)
Successfully Downloaded file - emalware.344 (103725)
Successfully Downloaded file - emalware.023 (145434)
Successfully Downloaded file - emalware.061 (131552)
Successfully Downloaded file - emalware.060 (117123)
Successfully Downloaded file - emalware.081 (76719)
Successfully Downloaded file - emalware.328 (84266)
Successfully Downloaded file - emalware.062 (176895)
Successfully Downloaded file - sdx.ivd (156098)
Successfully Downloaded file - emalware.361 (212039)
Successfully Downloaded file - e_spyw.i05 (258162)
Successfully Downloaded file - variant.c01 (2707775)
Successfully Downloaded file - emalware.047 (121551)
Successfully Downloaded file - emalware.040 (106706)
Successfully Downloaded file - emalware.528 (302368)
Successfully Downloaded file - emalware.110 (117865)
Successfully Downloaded file - emalware.527 (269315)
Successfully Downloaded file - emalware.329 (98544)
Successfully Downloaded file - pdftok.cvd (28367)
Successfully Downloaded file - emalware.307 (107340)
Successfully Downloaded file - emalware.366 (121774)
Successfully Downloaded file - emalware.093 (166430)
Successfully Downloaded file - emalware.019 (129409)
Successfully Downloaded file - emalware.318 (136874)
Successfully Downloaded file - emalware.084 (70291)
Successfully Downloaded file - e_spyw.i06 (303699)
Successfully Downloaded file - cevakrnl.rv8 (458016)
Successfully Downloaded file - htmltok.cvd (36609)
Successfully Downloaded file - emalware.087 (50165)
Successfully Downloaded file - emalware.112 (181575)
Successfully Downloaded file - emalware.009 (126302)
Successfully Downloaded file - emalware.354 (176014)
Successfully Downloaded file - emalware.000 (918076)
Successfully Downloaded file - emalware.357 (141438)
Successfully Downloaded file - emalware.526 (295950)
Successfully Downloaded file - emalware.037 (141954)
Successfully Downloaded file - emalware.051 (138736)
Successfully Downloaded file - emalware.105 (124332)
Successfully Downloaded file - emalware.036 (87270)
Successfully Downloaded file - emalware.096 (179194)
Successfully Downloaded file - emalware.323 (94870)
Successfully Downloaded file - emalware.332 (90587)
Successfully Downloaded file - e_spyw.i28 (293706)
Successfully Downloaded file - emalware.117 (212275)
Successfully Downloaded file - emalware.082 (90141)
Successfully Downloaded file - emalware.352 (172203)
Successfully Downloaded file - emalware.521 (290799)
Successfully Downloaded file - emalware.005 (177401)
Successfully Downloaded file - e_spyw.i08 (169333)
Successfully Downloaded file - emalware.356 (153269)
Successfully Downloaded file - emalware.531 (264078)
Successfully Downloaded file - emalware.024 (136672)
Successfully Downloaded file - e_spyw.i22 (302933)
Successfully Downloaded file - emalware.069 (102190)
Successfully Downloaded file - emalware.525 (282598)
Successfully Downloaded file - emalware.369 (201324)
Successfully Downloaded file - emalware.010 (134011)
Successfully Downloaded file - emalware.052 (179758)
Successfully Downloaded file - emalware.367 (123327)
Successfully Downloaded file - emalware.342 (116333)
Successfully Downloaded file - emalware.324 (108954)
Successfully Downloaded file - emalware.034 (123629)
Successfully Downloaded file - emalware.351 (163203)
Successfully Downloaded file - emalware.340 (108766)
Successfully Downloaded file - emalware.114 (145169)
Successfully Downloaded file - e_spyw.i01 (270394)
Successfully Downloaded file - emalware.530 (283127)
Successfully Downloaded file - emalware.089 (68521)
Successfully Downloaded file - emalware.311 (77977)
Successfully Downloaded file - emalware.333 (195436)
Successfully Downloaded file - e_spyw.i18 (165324)
Successfully Downloaded file - emalware.071 (132415)
Successfully Downloaded file - cevakrnl.rv0 (283441)
Successfully Downloaded file - e_spyw.i25 (310558)
Successfully Downloaded file - emalware.109 (146078)
Successfully Downloaded file - emalware.091 (155598)
Successfully Downloaded file - emalware.346 (137321)
Successfully Downloaded file - e_spyw.i24 (325748)
Successfully Downloaded file - emalware.336 (85191)
Successfully Downloaded file - e_spyw.i26 (332850)
Successfully Downloaded file - e_spyw.i19 (122095)
Successfully Downloaded file - emalware.315 (105612)
Successfully Downloaded file - emalware.343 (146020)
Successfully Downloaded file - emalware.072 (121570)
Successfully Downloaded file - emalware.045 (153993)
Successfully Downloaded file - emalware.049 (192374)
Successfully Downloaded file - emalware.106 (138108)
Successfully Downloaded file - emalware.094 (155610)
Successfully Downloaded file - emalware.326 (123805)
Successfully Downloaded file - emalware.099 (160105)
Successfully Downloaded file - e_spyw.i14 (168588)
Successfully Downloaded file - emalware.353 (159228)
Successfully Downloaded file - emalware.050 (133700)
Successfully Downloaded file - emalware.364 (211575)
Successfully Downloaded file - e_spyw.i09 (198157)
Successfully Downloaded file - e_spyw.i11 (150986)
Successfully Downloaded file - emalware.002 (258582)
Successfully Downloaded file - emalware.348 (122348)
Successfully Downloaded file - emalware.067 (125067)
Successfully Downloaded file - emalware.523 (282520)
Successfully Downloaded file - emalware.004 (162327)
Successfully Downloaded file - e_spyw.i23 (270249)
Successfully Downloaded file - emalware.048 (140714)
Successfully Downloaded file - dalvik.cvd (121970)
Successfully Downloaded file - emalware.079 (185390)
Successfully Downloaded file - jpeg.cvd (11934)
Successfully Downloaded file - emalware.363 (220022)
Successfully Downloaded file - emalware.013 (129660)
Successfully Downloaded file - emalware.006 (141036)
Successfully Downloaded file - emalware.355 (134758)
Successfully Downloaded file - e_spyw.i13 (165472)
Successfully Downloaded file - e_spyw.i27 (321821)
Successfully Downloaded file - emalware.057 (187429)
Successfully Downloaded file - emalware.077 (177720)
Successfully Downloaded file - emalware.065 (144928)
Successfully Downloaded file - emalware.107 (123970)
Successfully Downloaded file - emalware.008 (138884)
Successfully Downloaded file - emalware.074 (144843)
Successfully Downloaded file - emalware.349 (316610)
Successfully Downloaded file - e_spyw.i21 (128666)
Successfully Downloaded file - emalware.018 (198970)
Successfully Downloaded file - emalware.310 (107332)
Successfully Downloaded file - dalvik.xmd (17310)
Successfully Downloaded file - avc3_installer.st (1810)
Successfully Downloaded file - avc3.hx (131435)
Successfully Downloaded file - avc3_main.st (70228)
Successfully Downloaded file - avc3.ic (39296)
Successfully Downloaded file - update.bin (35)
Successfully Downloaded file - avc3.fr (234882)
Successfully Downloaded file - settings.avc3 (569)
Successfully Downloaded file - avc3.rd (662)
Successfully Downloaded file - avcuf64.dll (249508)
Successfully Downloaded file - exploits.avc3 (452)
Successfully Downloaded file - avcuf32.dll (226800)
Successfully Downloaded file - avc3.mx (12448)
Successfully Downloaded file - avc3.qx (1737)
Successfully Downloaded file - avc3.hxi (7521)
Successfully Downloaded file - update.bin (35)
Total number of Anti-Virus files downloaded is 252
Connecting to HTTP host <Direct connection>
Connecting to http://www.microworldsystems.com ...
Requested file name and size information...
Successfully Downloaded file - clnsign2.avs (7880)
Successfully Downloaded file - cloudig.avs (1641)
Successfully Downloaded file - httpsite.txt (189)
Successfully Downloaded file - iplist.ini (90)
Successfully Downloaded file - phlist17.avs (192872)
Successfully Downloaded file - remove.ini (1943)
Successfully Downloaded file - update.txt (1304)
Successfully Downloaded file - updll10.dlz (1116603)
Successfully Downloaded file - url1a.avs (230643)
Successfully Downloaded file - url1d.avs (229930)
Successfully Downloaded file - url2c.avs (228215)
Successfully Downloaded file - url2d.avs (238511)
Successfully Downloaded file - url2e.avs (160386)
Successfully Downloaded file - url4.avs (164970)
Successfully Downloaded file - url5.avs (199650)
Successfully Downloaded file - urla.avs (201546)
Successfully Downloaded file - urld.avs (236909)
Successfully Downloaded file - vsignj.avs (79724)
KLB comparison started
There is no file found in KLB comparison
Downloaded 18 files.Terminating session...
----------------------------------------------------------------------
7.3.2013 12:31:37 Terminating HTTP Session
objevil jsem, že mi do počítače rodinný příslušník před týdnem naistaloval nelegalni office 2010 s nějakym virem, snažil jsem se je odinstalovat, ale během odistalace zamrznul počítač. Jsou nějak napůl odinstalované, v seznamu nainstalovaných programů teď nejsou.
1)
Projel jsem pc v nouzovem režimu pomocí programu MWAV, který našel a smazal trojana a 5 spyware. Pak se pc sekl a jediný log, který jsem poté našel je tento:
07 3 2013 12:32:18 - **********************************************************
07 3 2013 12:32:18 - MWAV - eScanAV AntiVirus Toolkit.
07 3 2013 12:32:18 - Copyright © MicroWorld Technologies
07 3 2013 12:32:18 - **********************************************************
07 3 2013 12:32:18 - Source: C:\Users\Ervd\Desktop\mwav.exe
07 3 2013 12:32:18 - Version 14.0.51 (C:\USERS\ERVD\APPDATA\LOCAL\TEMP\MEXETMP.EX~)
07 3 2013 12:32:18 - Log File: C:\Users\Ervd\AppData\Local\Temp\MWAV.LOG
07 3 2013 12:32:18 - MWAV Registered: TRUE
07 3 2013 12:32:18 - User Account: Ervd (Administrator Mode)
07 3 2013 12:32:18 - OS Type: Windows Workstation
07 3 2013 12:32:18 - OS: Windows 7 64-Bit
07 3 2013 12:32:18 - Ver: Personal Service Pack 1 (Build 7601)
07 3 2013 12:32:18 - System Up Time: 25 Minutes, 47 Seconds
07 3 2013 12:32:18 - Parent Process Name : C:\Users\Ervd\AppData\Local\Temp\mexe.com
07 3 2013 12:32:18 - Windows Root Folder: C:\windows
07 3 2013 12:32:18 - Windows Sys32 Folder: C:\windows\system32
07 3 2013 12:32:18 - DHCP NameServer: 8.8.8.8 8.8.4.4
07 3 2013 12:32:18 - Interface0 DHCPNameServer: 192.168.42.129
07 3 2013 12:32:18 - Interface1 DHCPNameServer: 8.8.8.8 8.8.4.4
07 3 2013 12:32:18 - Interface2 DHCPNameServer: 192.168.42.129
07 3 2013 12:32:18 - Interface3 DHCPNameServer: 192.168.42.129
07 3 2013 12:32:18 - Local Fixed Drives: c:\,d:\,e:\
07 3 2013 12:32:18 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
07 3 2013 12:32:18 - [CREATED ZIP FILE: C:\Users\Ervd\AppData\Local\Temp\pinfect.zip]
07 3 2013 12:32:18 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
07 3 2013 12:32:20 - C:\windows\AutoKMS.exe (614400), 26-Feb-2013 [Added C:\windows\AutoKMS.exe to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d2d1.dll (3419136), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\d3d10.dll (1080832), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\d3d10core.dll (220160), 27-Feb-2013 [Added C:\windows\system32\d3d10core.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d10level9.dll (604160), 27-Feb-2013 [Added C:\windows\system32\d3d10level9.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d10warp.dll (1988096), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\d3d10_1.dll (161792), 27-Feb-2013 [Added C:\windows\system32\d3d10_1.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d10_1core.dll (249856), 27-Feb-2013 [Added C:\windows\system32\d3d10_1core.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\d3d11.dll (1504768), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\deployJava1.dll (782240), 24-Feb-2013 [Added C:\windows\system32\deployJava1.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\DWrite.dll (1247744), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\dxgi.dll (293376), 27-Feb-2013 [Added C:\windows\system32\dxgi.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 12:32:20 - C:\windows\system32\FlashPlayerApp.exe (691568), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerApp.exe to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\FlashPlayerCPLApp.cpl (71024), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerCPLApp.cpl to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\javaw.exe (174496), 24-Feb-2013 [Added C:\windows\system32\javaw.exe to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\msmpeg2vdec.dll (2284544), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 12:32:20 - C:\windows\system32\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 12:32:20 - C:\windows\system32\npDeployJava1.dll (861088), 24-Feb-2013 [Added C:\windows\system32\npDeployJava1.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\UIAnimation.dll (187392), 27-Feb-2013 [Added C:\windows\system32\UIAnimation.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\WindowsAccessBridge-32.dll (95648), 24-Feb-2013 [Added C:\windows\system32\WindowsAccessBridge-32.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\WindowsCodecs.dll (1230336), 27-Feb-2013
07 3 2013 12:32:20 - C:\windows\system32\WindowsCodecsExt.dll (207872), 27-Feb-2013 [Added C:\windows\system32\WindowsCodecsExt.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\WMPhoto.dll (417792), 27-Feb-2013 [Added C:\windows\system32\WMPhoto.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\XpsGdiConverter.dll (364544), 27-Feb-2013 [Added C:\windows\system32\XpsGdiConverter.dll to ZIP FILE]
07 3 2013 12:32:20 - C:\windows\system32\XpsPrint.dll (1158144), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll (495776), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll (548288), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\BACKUP.12518614.mexe.com (775976), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdc.exe (182792), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdfltlib2k.dll (231944), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus32.dll (85288), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus64.dll (91944), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\DEVCON.EXE (61184), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\encdec.dll (254696), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\erootdrv.sys (22920), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\HxFD03.tmp (877368), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\mexe.com (776488), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\mexe.com to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\msvclnt.dll (201448), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\mwavdwnl.exe (990952), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\MWAVSCAN.COM (775976), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\red32.dll (11496), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Reload.exe (153832), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\setpriv.exe (81640), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\trufos.dll (394408), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.dll to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\trufos.sys (350160), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.sys to ZIP FILE]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\unregx.exe (83176), 27-Feb-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\UPDLL10.DLL (1121512), 02-Mar-2013
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\viewtcp.exe (576744), 27-Feb-2013
07 3 2013 12:32:21 - C:\windows\Fonts, 14-Jul-2009 [SR] [Folder]
07 3 2013 12:32:21 - C:\windows\Media, 14-Jul-2009 [SR] [Folder]
07 3 2013 12:32:21 - C:\windows\PCHEALTH, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 12:32:21 - C:\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 12:32:21 - C:\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 12:32:21 - C:\office, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 12:32:21 - C:\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\AVCBack, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\comtypes_cache, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\FtpTemp, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\FtpTempF, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\LOCK, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Log, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Low, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\plugins, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Setup000005ac, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Setup000009e4, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\Setup00001dd4, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\TempBK, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Local\Temp\WPDNSE, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Users\Ervd\AppData\Roaming\Microsoft, 09-Jun-2012 [S] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Application Data, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\ArcSoft, 09-Jun-2012 [H] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Desktop, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Documents, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Microsoft, 14-Jul-2009 [S] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Start Menu, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\Templates, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\office, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 12:32:21 - C:\ProgramData\..\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Java, 24-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Analysis Services, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Sync Framework, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Synchronization Services, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Microsoft Visual Studio 8, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\DESIGNER, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\DW, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\EURO, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Filters, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Help, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\IME14, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSClientDataMgr, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Portal, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\RRLoc14, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Smart Tag, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\THEMES14, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\TRANSLAT, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\VBA, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Server Extensions, 07-Mar-2013 [Folder]
07 3 2013 12:32:21 - C:\Program Files (x86)\Common Files\Microsoft Shared\WORDBRKR, 26-Feb-2013 [Folder]
07 3 2013 12:32:21 - *********************************************************************************************
07 3 2013 12:32:21 - Command Line Options Given: /xsign
07 3 2013 12:32:29 - Latest Date of files inside MWAV: Thu Mar 7 12:27:45 2013.
07 3 2013 12:32:29 - Sign Version: 7.45890
07 3 2013 12:32:29 - Loading/Creating FileScan Cache Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\Ervd\AppData\Local\Temp\ESCANDB.LOG]
07 3 2013 12:32:29 - Loaded/Created FileScan Cache Database...
07 3 2013 12:32:29 - Loading AV Library [DB]...
07 3 2013 12:32:32 - ArchiveScan: DISABLED
07 3 2013 12:32:34 - AV Library Loaded [DB-DIRECT].
07 3 2013 12:32:34 - MWAV doing self scanning...
07 3 2013 12:32:34 - MWAV files are clean.
07 3 2013 12:32:38 - ArchiveScan: DISABLED
07 3 2013 12:32:38 - Virus Database Date: 07 Mar 2013
07 3 2013 12:32:38 - Virus Database Count: 9224033
07 3 2013 12:32:38 - Scheduler Service not enabled. Scheduler Feature Disabled.
07 3 2013 12:33:00 - ArchiveScan: ENABLED
07 3 2013 12:33:01 - **********************************************************
07 3 2013 12:33:01 - MWAV - eScanAV AntiVirus Toolkit.
07 3 2013 12:33:01 - Copyright © MicroWorld Technologies
07 3 2013 12:33:01 -
07 3 2013 12:33:01 - Support: support@escanav.com
07 3 2013 12:33:01 - Web: http://www.escanav.com
07 3 2013 12:33:01 - **********************************************************
07 3 2013 12:33:01 - Version 14.0.51[DB] (C:\USERS\ERVD\APPDATA\LOCAL\TEMP\MEXETMP.EX~)
07 3 2013 12:33:01 - Log File: C:\Users\Ervd\AppData\Local\Temp\MWAV.LOG
07 3 2013 12:33:01 - User Account: Ervd (Administrator Mode)
07 3 2013 12:33:01 - Parent Process Name : C:\Users\Ervd\AppData\Local\Temp\mexe.com
07 3 2013 12:33:01 - Windows Root Folder: C:\windows
07 3 2013 12:33:01 - Windows Sys32 Folder: C:\windows\system32
07 3 2013 12:33:01 - OS: Windows 7 64-Bit
07 3 2013 12:33:01 - Ver: Personal Service Pack 1 (Build 7601)
07 3 2013 12:33:01 - Latest Date of files inside MWAV: Thu Mar 7 12:27:45 2013.
07 3 2013 12:33:01 - Sign Version: 7.45890
07 3 2013 12:33:08 - Scheduler Service not enabled. Scheduler Feature Disabled.
07 3 2013 12:33:08 - Options Selected by User:
07 3 2013 12:33:08 - Memory Check: Enabled
07 3 2013 12:33:08 - Registry Check: Enabled
07 3 2013 12:33:08 - StartUp Folder Check: Enabled
07 3 2013 12:33:08 - System Folder Check: Enabled
07 3 2013 12:33:08 - Services Check: Enabled
07 3 2013 12:33:08 - Scan Spyware: Enabled
07 3 2013 12:33:08 - Scan Archives: Enabled
07 3 2013 12:33:08 - Drive Check: Disabled
07 3 2013 12:33:08 - All Drive Check :Enabled
07 3 2013 12:33:08 - Folder Check: Disabled
07 3 2013 12:33:08 - SCAN: All_Files
07 3 2013 12:33:08 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
07 3 2013 12:33:09 - Scanning DNS Records...
07 3 2013 12:33:09 - Scanning Master Boot Record (User)...
07 3 2013 12:33:09 - Scanning Logical Boot Records...
07 3 2013 12:33:09 - ***** Scanning For Hidden Rootkit Processes *****
07 3 2013 12:33:09 - ***** Scanning For Hidden Rootkit Services *****
07 3 2013 12:33:15 - ***** Scanning Memory Files *****
07 3 2013 12:33:19 - ***** Scanning Registry Files *****
07 3 2013 12:33:23 - ***** Scanning StartUp Folders *****
07 3 2013 12:34:52 - Scanning File C:\ProgramData\Premium\MagniPic\MagniPic.exe
07 3 2013 12:34:52 - File C:\ProgramData\Premium\MagniPic\MagniPic.exe infected by "Trojan.Agent.AYUV (DB)" Virus! Action Taken: File Deleted.
07 3 2013 12:36:04 - Scanning File C:\ProgramData\..\hiberfil.sys
07 3 2013 12:36:04 - ERROR(3)!!! ScanFile fails for C:\ProgramData\..\hiberfil.sys
07 3 2013 12:36:04 - Scanning File C:\ProgramData\..\pagefile.sys
07 3 2013 12:36:04 - ERROR(3)!!! ScanFile fails for C:\ProgramData\..\pagefile.sys
07 3 2013 12:36:05 - ***** Scanning Service Files *****
07 3 2013 12:36:23 - ***** Scanning Registry and File system for Adware/Spyware *****
07 3 2013 12:36:24 - Loading Spyware Signatures from new External Database [Name: C:\Users\Ervd\AppData\Local\Temp\spydb.avs, Size: 463768]...
07 3 2013 12:36:24 - Indexed Spyware Databases Successfully Created...
07 3 2013 12:36:52 - Offending file found: C:\ProgramData\InstallMate\MagniPic\_Setupx.dll
07 3 2013 12:36:52 - System found infected with DealHelper.com Spyware/Adware (_Setupx.dll)! Action taken: File Deleted.
07 3 2013 12:36:52 - Object "DealHelper.com Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:52 - Offending file found: C:\ProgramData\InstallMate\{4831C39B-9776-496F-AB84-DF5493D2E16D}\_Setupx.dll
07 3 2013 12:36:52 - System found infected with DealHelper.com Spyware/Adware (_Setupx.dll)! Action taken: File Deleted.
07 3 2013 12:36:52 - Object "DealHelper.com Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:53 - Offending file found: C:\ProgramData\InstallMate\{9E0E9390-C57C-4A8C-A867-8D5E45EDB166}\_Setupx.dll
07 3 2013 12:36:53 - System found infected with DealHelper.com Spyware/Adware (_Setupx.dll)! Action taken: File Deleted.
07 3 2013 12:36:53 - Object "DealHelper.com Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:53 - Offending file found: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Logs\LU.dat
07 3 2013 12:36:53 - System found infected with ImIServer IEPlugin Spyware/Adware (LU.dat)! Action taken: File Deleted.
07 3 2013 12:36:53 - Object "ImIServer IEPlugin Spyware/Adware" found in File System! Action Taken: File Deleted.
07 3 2013 12:36:54 - ***** Scanning Registry Files *****
07 3 2013 12:36:54 - Scanning File C:\ProgramData\MagniPic\511d307d9314a.dll (????)
07 3 2013 12:36:54 - Scanning File c:\Program Files (x86)\MagniPic\sprotector.dll (????)
07 3 2013 12:36:54 - Scanning File C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe (????)
07 3 2013 12:36:54 - ** Value in HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\main/Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
07 3 2013 12:36:54 - ** Deleted Value of "NoActiveDesktop" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer". Its value was DWORD:1.
07 3 2013 12:36:54 - ** Deleted Value of "ForceActiveDesktopOn" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer". Its value was DWORD:0.
07 3 2013 12:36:54 - ** Deleted Value of "NoComponents" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop". Its value was DWORD:1.
07 3 2013 12:36:54 - ** Deleted Value of "NoAddingComponents" in "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop". Its value was DWORD:1.
07 3 2013 12:36:54 - ** Value in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main/Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
07 3 2013 12:36:54 - ***** Scanning System32 Folders *****
07 3 2013 12:36:55 - Scanning File C:\windows\AutoKMS.exe
07 3 2013 12:36:55 - File C:\windows\AutoKMS.exe infected by "Application.Crack.PDE (DB)" Virus! Action Taken: File Renamed.
07 3 2013 12:38:18 - ***** Scanning All Drives *****
07 3 2013 12:38:18 - ***** C:,D:,E: *****
07 3 2013 12:38:18 - Scanning C:\ Drive
07 3 2013 12:38:20 - Scanning File C:\hp\HPQWare\Favs\da-DK\all\HP\Fa Skype – Hent det gratis.url
07 3 2013 12:38:20 - ERROR(3)!!! ScanFile fails for C:\hp\HPQWare\Favs\da-DK\all\HP\Fa Skype – Hent det gratis.url
07 3 2013 12:38:20 - Scanning File C:\hp\HPQWare\Favs\nb-NO\all\HP\Fa Skype – Last ned gratis.url
07 3 2013 12:38:20 - ERROR(3)!!! ScanFile fails for C:\hp\HPQWare\Favs\nb-NO\all\HP\Fa Skype – Last ned gratis.url
07 3 2013 12:38:21 - Scanning File C:\hp\HPQWare\StartMenuLink\tr-TR\all\Online Services\Huddle alanlari.lnk
07 3 2013 12:38:21 - ERROR(3)!!! ScanFile fails for C:\hp\HPQWare\StartMenuLink\tr-TR\all\Online Services\Huddle alanlari.lnk
07 3 2013 13:03:35 - ScanFile (C:\swsetup\ATISMRW7\Packages\Drivers\Display\W76A_INF\B126813\atioglxx.dl_) took 5008 ms
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{045a4300-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{045a4300-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{045a4459-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{045a4459-801c-11e2-a34c-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{1dd949f5-8702-11e2-9904-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{1dd949f5-8702-11e2-9904-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{52d513d7-80e8-11e2-9154-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{52d513d7-80e8-11e2-9154-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - Scanning File C:\System Volume Information\{f16be377-85c4-11e2-b390-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:31 - ERROR(3)!!! ScanFile fails for C:\System Volume Information\{f16be377-85c4-11e2-b390-e4115b30fe5c}{3808876b-c176-4e48-b7ae-04046e6cc752}
07 3 2013 13:05:38 - C:\Users\Ervd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:05:38 - ERROR(3)!!! ScanFile fails for C:\Users\Ervd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
07 3 2013 13:10:52 - C:\Users\Ervd\ntuser.dat.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:10:52 - ERROR(3)!!! ScanFile fails for C:\Users\Ervd\ntuser.dat.LOG1
07 3 2013 13:15:47 - C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:15:47 - ERROR(3)!!! ScanFile fails for C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1
07 3 2013 13:15:48 - C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 not Scanned. Possibly password protected...
07 3 2013 13:15:48 - ERROR(3)!!! ScanFile fails for C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1
07 3 2013 13:17:54 - C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb not Scanned. Possibly password protected...
07 3 2013 13:17:54 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
07 3 2013 13:17:54 - C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb not Scanned. Possibly password protected...
07 3 2013 13:17:54 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
07 3 2013 13:21:09 - C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl not Scanned. Possibly password protected...
07 3 2013 13:21:09 - ERROR(3)!!! ScanFile fails for C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
07 3 2013 13:36:32 - Please Wait Exiting Application...
07 3 2013 13:36:32 - Scanning D:\ Drive
07 3 2013 13:36:32 - ***** Scanning complete. *****
07 3 2013 13:36:32 - Total Objects Scanned: 267422
07 3 2013 13:36:32 - Total Critical Objects: 6
07 3 2013 13:36:32 - Total Disinfected Objects: 0
07 3 2013 13:36:32 - Total Objects Renamed: 1
07 3 2013 13:36:32 - Total Deleted Objects: 5
07 3 2013 13:36:32 - Total Errors: 0
07 3 2013 13:36:32 - Time Elapsed: 01:02:31
07 3 2013 13:36:32 - Virus Database Date: 07 Mar 2013
07 3 2013 13:36:32 - Virus Database Count: 9224033
07 3 2013 13:36:32 - Scan Completed.
07 3 2013 13:36:56 - Virus Database Date: 07 Mar 2013
07 3 2013 13:36:56 - Virus Database Count: 9224033
07 3 2013 13:36:56 - Scheduler Service not enabled. Scheduler Feature Disabled.
07 3 2013 13:37:01 - Uninitializing Scanner (3)...
07 3 2013 13:37:02 - Freeing Libraries (3)...
07 3 2013 13:37:02 - AV Library Unloaded (3)...
07 3 2013 13:37:03 - [Made copy of PINFECT.ZIP (3962822 Bytes) as C:\Users\Ervd\Documents\pinfect.zip]
07 3 2013 13:46:52 - **********************************************************
07 3 2013 13:46:52 - MWAV - eScanAV AntiVirus Toolkit.
07 3 2013 13:46:52 - Copyright © MicroWorld Technologies
07 3 2013 13:46:52 - **********************************************************
07 3 2013 13:46:52 - Version 14.0.51 (C:\USERS\ERVD\APPDATA\LOCAL\TEMP\MWAVSCAN.EXE)
07 3 2013 13:46:52 - Log File: C:\Users\Ervd\AppData\Local\Temp\MWAV.LOG
07 3 2013 13:46:52 - Last Scan Date and Time: 07.03.2013 12:33:08
07 3 2013 13:46:52 - MWAV Registered: TRUE
07 3 2013 13:46:52 - User Account: Ervd (Administrator Mode)
07 3 2013 13:46:52 - OS Type: Windows Workstation
07 3 2013 13:46:52 - OS: Windows 7 64-Bit
07 3 2013 13:46:52 - Ver: Personal Service Pack 1 (Build 7601)
07 3 2013 13:46:52 - System Up Time: 1 Hour, 40 Minutes, 21 Seconds
07 3 2013 13:46:52 - Parent Process Name : c:\Windows\explorer.exe
07 3 2013 13:46:52 - Windows Root Folder: C:\windows
07 3 2013 13:46:52 - Windows Sys32 Folder: C:\windows\system32
07 3 2013 13:46:52 - DHCP NameServer: 8.8.8.8 8.8.4.4
07 3 2013 13:46:52 - Interface0 DHCPNameServer: 192.168.42.129
07 3 2013 13:46:52 - Interface1 DHCPNameServer: 8.8.8.8 8.8.4.4
07 3 2013 13:46:52 - Interface2 DHCPNameServer: 192.168.42.129
07 3 2013 13:46:52 - Interface3 DHCPNameServer: 192.168.42.129
07 3 2013 13:46:52 - Local Fixed Drives: c:\,d:\,e:\
07 3 2013 13:46:52 - MWAV Mode: Scan and Clean files (for viruses, adware and spyware)
07 3 2013 13:46:52 - [CREATED ZIP FILE: C:\Users\Ervd\AppData\Local\Temp\pinfect.zip]
07 3 2013 13:46:52 - ****** Files/Folders created/modified during last fortnight in Windows and ROOT Folder ******
07 3 2013 13:46:53 - C:\windows\system32\d2d1.dll (3419136), 27-Feb-2013
07 3 2013 13:46:53 - C:\windows\system32\d3d10.dll (1080832), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\d3d10core.dll (220160), 27-Feb-2013 [Added C:\windows\system32\d3d10core.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d10level9.dll (604160), 27-Feb-2013 [Added C:\windows\system32\d3d10level9.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d10warp.dll (1988096), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\d3d10_1.dll (161792), 27-Feb-2013 [Added C:\windows\system32\d3d10_1.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d10_1core.dll (249856), 27-Feb-2013 [Added C:\windows\system32\d3d10_1core.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\d3d11.dll (1504768), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\deployJava1.dll (782240), 24-Feb-2013 [Added C:\windows\system32\deployJava1.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\DWrite.dll (1247744), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\dxgi.dll (293376), 27-Feb-2013 [Added C:\windows\system32\dxgi.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 13:46:54 - C:\windows\system32\FlashPlayerApp.exe (691568), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerApp.exe to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\FlashPlayerCPLApp.cpl (71024), 27-Feb-2013 [Added C:\windows\system32\FlashPlayerCPLApp.cpl to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\javaw.exe (174496), 24-Feb-2013 [Added C:\windows\system32\javaw.exe to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\msmpeg2vdec.dll (2284544), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 13:46:54 - C:\windows\system32\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 13:46:54 - C:\windows\system32\npDeployJava1.dll (861088), 24-Feb-2013 [Added C:\windows\system32\npDeployJava1.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\UIAnimation.dll (187392), 27-Feb-2013 [Added C:\windows\system32\UIAnimation.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\WindowsAccessBridge-32.dll (95648), 24-Feb-2013 [Added C:\windows\system32\WindowsAccessBridge-32.dll to ZIP FILE]
07 3 2013 13:46:54 - C:\windows\system32\WindowsCodecs.dll (1230336), 27-Feb-2013
07 3 2013 13:46:54 - C:\windows\system32\WindowsCodecsExt.dll (207872), 27-Feb-2013 [Added C:\windows\system32\WindowsCodecsExt.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\windows\system32\WMPhoto.dll (417792), 27-Feb-2013 [Added C:\windows\system32\WMPhoto.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\windows\system32\XpsGdiConverter.dll (364544), 27-Feb-2013 [Added C:\windows\system32\XpsGdiConverter.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\windows\system32\XpsPrint.dll (1158144), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll (495776), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf32.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll (548288), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\avcuf64.dll to ZIP FILE]
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\BACKUP.12518614.mexe.com (775976), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdc.exe (182792), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdfltlib2k.dll (231944), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus32.dll (85288), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\bdnimbus64.dll (91944), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\DEVCON.EXE (61184), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\eEmpty.exe (34048), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\encdec.dll (254696), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\erootdrv.sys (22920), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\HxFD03.tmp (877368), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\mexe.com (776488), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\mexe.com to ZIP FILE]
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\msvclnt.dll (201448), 27-Feb-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\msvcp90.dll (572928), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\msvcr90.dll (655872), 07-Mar-2013
07 3 2013 13:46:55 - C:\Users\Ervd\AppData\Local\Temp\mwavdwnl.exe (990952), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\MWAVSCAN.COM (775976), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\red32.dll (11496), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Reload.exe (153832), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\setpriv.exe (81640), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\trufos.dll (394408), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.dll to ZIP FILE]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\trufos.sys (350160), 07-Mar-2013 [Added C:\Users\Ervd\AppData\Local\Temp\trufos.sys to ZIP FILE]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\unregx.exe (83176), 27-Feb-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\UPDLL10.DLL (1121512), 02-Mar-2013
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\viewtcp.exe (576744), 27-Feb-2013
07 3 2013 13:46:56 - C:\windows\Fonts, 14-Jul-2009 [SR] [Folder]
07 3 2013 13:46:56 - C:\windows\logo_1.exe, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\Media, 14-Jul-2009 [SR] [Folder]
07 3 2013 13:46:56 - C:\windows\PCHEALTH, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\RUNDL132.EXE, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\VDLL.DLL, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\windows\system32\runouce.exe, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 13:46:56 - C:\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 13:46:56 - C:\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 13:46:56 - C:\office, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 13:46:56 - C:\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\AVCBack, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\comtypes_cache, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\FBackUp, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\FtpTemp, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\FtpTempF, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\LOCK, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Log, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Low, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\plugins, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Setup000005ac, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Setup000009e4, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\Setup00001dd4, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\TempBK, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Local\Temp\WPDNSE, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Users\Ervd\AppData\Roaming\Microsoft, 09-Jun-2012 [S] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Application Data, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\ArcSoft, 09-Jun-2012 [H] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Desktop, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Documents, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Microsoft, 14-Jul-2009 [S] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Start Menu, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\Templates, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\boot, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\Config.Msi, 07-Mar-2013 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\Documents and Settings, 14-Jul-2009 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\hp, 02-Jan-2012 [H] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\MSOCache, 27-Sep-2012 [HR] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\office, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\ProgramData, 14-Jul-2009 [H] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\Recovery, 11-Feb-2011 [HS] [Folder]
07 3 2013 13:46:56 - C:\ProgramData\..\SYSTEM.SAV, 14-Sep-2010 [H] [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Java, 24-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Analysis Services, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Sync Framework, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Synchronization Services, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Microsoft Visual Studio 8, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\DESIGNER, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\MicroWorld, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\DW, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\EURO, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Filters, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Help, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\IME14, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSClientDataMgr, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\MSEnv, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Portal, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\PROOF, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\RRLoc14, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Smart Tag, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\THEMES14, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\TRANSLAT, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\VBA, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Server Extensions, 07-Mar-2013 [Folder]
07 3 2013 13:46:56 - C:\Program Files (x86)\Common Files\Microsoft Shared\WORDBRKR, 26-Feb-2013 [Folder]
07 3 2013 13:46:56 - *********************************************************************************************
07 3 2013 13:47:41 - Latest Date of files inside MWAV: Thu Mar 7 12:27:45 2013.
07 3 2013 13:47:41 - Sign Version: 7.45890
07 3 2013 13:47:41 - Loading/Creating FileScan Cache Database C:\ProgramData\MicroWorld\MWAV\ESCANDBX.MDB [Log: C:\Users\Ervd\AppData\Local\Temp\ESCANDB.LOG]
07 3 2013 13:47:42 - Loaded/Created FileScan Cache Database...
07 3 2013 13:47:42 - Loading AV Library [DB]...
07 3 2013 13:47:53 - ArchiveScan: ENABLED
07 3 2013 13:47:55 - AV Library Loaded [DB-DIRECT].
07 3 2013 13:47:55 - MWAV doing self scanning...
07 3 2013 13:47:56 - MWAV files are clean.
07 3 2013 13:47:56 - ArchiveScan: ENABLED
07 3 2013 13:47:56 - Virus Database Date: 07 Mar 2013
07 3 2013 13:47:56 - Virus Database Count: 9224033
07 3 2013 13:47:56 - Scheduler Service not enabled. Scheduler Feature Disabled.
2)
Dále jsem v adresáři C:\Users\Ervd\AppData\Local\Temp\Log objevil (při hledání logu z MWAV) soubor download.txt, v němž je tento text:
*******************************************************************************
Automatic HTTP Downloader Ver 4.0.2.209.
-------------------------------------------------------------------------------
Check eUpdate.ini Settings.
7.3.2013 12:28:47 Starting Manual HTTP session to host http://www.microworldsystems.com/pub/update
07-3-2013 12:28:47 Trying to connect with Ini Settings.
07-3-2013 12:28:47 Connection Successful with Ini Settings.
Connecting to HTTP host <Direct connection>
Requested file name and size information...
Starting Anti-Virus Download...
Successfully Downloaded file - update.txt (130)
Successfully Downloaded file - emalware.053 (160758)
Successfully Downloaded file - emalware.041 (134538)
Successfully Downloaded file - emalware.090 (104697)
Successfully Downloaded file - emalware.524 (298560)
Successfully Downloaded file - emalware.113 (146414)
Successfully Downloaded file - instyler.xmd (25197)
Successfully Downloaded file - emalware.073 (162488)
Successfully Downloaded file - emalware.025 (132546)
Successfully Downloaded file - emalware.012 (116551)
Successfully Downloaded file - emalware.111 (212781)
Successfully Downloaded file - emalware.054 (181380)
Successfully Downloaded file - emalware.350 (87713)
Successfully Downloaded file - emalware.080 (51691)
Successfully Downloaded file - emalware.325 (98299)
Successfully Downloaded file - cran.ivd (67613)
Successfully Downloaded file - emalware.015 (96268)
Successfully Downloaded file - emalware.028 (103805)
Successfully Downloaded file - cevakrnl.ivd (54171)
Successfully Downloaded file - emalware.330 (77009)
Successfully Downloaded file - emalware.022 (124431)
Successfully Downloaded file - emalware.320 (125146)
Successfully Downloaded file - emalware.522 (325772)
Successfully Downloaded file - emalware.085 (64272)
Successfully Downloaded file - emalware.345 (151848)
Successfully Downloaded file - emalware.321 (112786)
Successfully Downloaded file - disp.xmd (29123)
Successfully Downloaded file - e_spyw.i00 (177085)
Successfully Downloaded file - cevakrnl.rv5 (222128)
Successfully Downloaded file - emalware.319 (120443)
Successfully Downloaded file - emalware.068 (116348)
Successfully Downloaded file - emalware.032 (84126)
Successfully Downloaded file - emalware.317 (107755)
Successfully Downloaded file - emalware.029 (103857)
Successfully Downloaded file - emalware.007 (142680)
Successfully Downloaded file - emalware.360 (108398)
Successfully Downloaded file - emalware.016 (103103)
Successfully Downloaded file - emalware.327 (98629)
Successfully Downloaded file - e_spyw.i20 (114846)
Successfully Downloaded file - emalware.078 (151697)
Successfully Downloaded file - emalware.056 (207950)
Successfully Downloaded file - emalware.003 (148096)
Successfully Downloaded file - emalware.115 (162324)
Successfully Downloaded file - emalware.309 (99972)
Successfully Downloaded file - e_spyw.i07 (333779)
Successfully Downloaded file - emalware.083 (65382)
Successfully Downloaded file - emalware.368 (143094)
Successfully Downloaded file - emalware.116 (156366)
Successfully Downloaded file - emalware.058 (150356)
Successfully Downloaded file - emalware.358 (122622)
Successfully Downloaded file - emalware.020 (136919)
Successfully Downloaded file - e_spyw.i15 (160870)
Successfully Downloaded file - e_spyw.i17 (185224)
Successfully Downloaded file - emalware.337 (99388)
Successfully Downloaded file - emalware.341 (125223)
Successfully Downloaded file - emalware.338 (113350)
Successfully Downloaded file - e_spyw.i12 (176794)
Successfully Downloaded file - emalware.086 (52172)
Successfully Downloaded file - emalware.017 (115747)
Successfully Downloaded file - emalware.063 (230311)
Successfully Downloaded file - emalware.031 (75843)
Successfully Downloaded file - e_spyw.i10 (161995)
Successfully Downloaded file - cevakrnl.rv3 (758058)
Successfully Downloaded file - emalware.064 (199955)
Successfully Downloaded file - emalware.347 (131010)
Successfully Downloaded file - emalware.322 (113318)
Successfully Downloaded file - emalware.042 (119724)
Successfully Downloaded file - emalware.043 (142291)
Successfully Downloaded file - emalware.070 (139483)
Successfully Downloaded file - emalware.076 (162805)
Successfully Downloaded file - emalware.014 (122245)
Successfully Downloaded file - emalware.097 (329232)
Successfully Downloaded file - emalware.100 (185139)
Successfully Downloaded file - emalware.108 (142873)
Successfully Downloaded file - emalware.059 (222408)
Successfully Downloaded file - emalware.035 (117289)
Successfully Downloaded file - emalware.102 (116189)
Successfully Downloaded file - emalware.027 (186169)
Successfully Downloaded file - emalware.335 (101885)
Successfully Downloaded file - emalware.066 (167782)
Successfully Downloaded file - emalware.362 (182337)
Successfully Downloaded file - cevakrnl.rv1 (125901)
Successfully Downloaded file - emalware.039 (175989)
Successfully Downloaded file - e_spyw.i02 (237616)
Successfully Downloaded file - emalware.044 (129585)
Successfully Downloaded file - emalware.101 (144549)
Successfully Downloaded file - emalware.312 (140678)
Successfully Downloaded file - e_spyw.i04 (198378)
Successfully Downloaded file - zip.xmd (41182)
Successfully Downloaded file - emalware.092 (162274)
Successfully Downloaded file - emalware.359 (123762)
Successfully Downloaded file - emalware.098 (309449)
Successfully Downloaded file - emalware.033 (82297)
Successfully Downloaded file - emalware.026 (116146)
Successfully Downloaded file - emalware.331 (119295)
Successfully Downloaded file - emalware.011 (109119)
Successfully Downloaded file - emalware.055 (208988)
Successfully Downloaded file - emalware.313 (106611)
Successfully Downloaded file - emalware.529 (322010)
Successfully Downloaded file - emalware.316 (140777)
Successfully Downloaded file - emalware.088 (46601)
Successfully Downloaded file - emalware.046 (122051)
Successfully Downloaded file - emalware.030 (98926)
Successfully Downloaded file - emalware.334 (120300)
Successfully Downloaded file - e_spyw.i16 (162390)
Successfully Downloaded file - e_spyw.i03 (241062)
Successfully Downloaded file - emalware.339 (124073)
Successfully Downloaded file - emalware.021 (90826)
Successfully Downloaded file - emalware.103 (132431)
Successfully Downloaded file - emalware.095 (172588)
Successfully Downloaded file - emalware.365 (214937)
Successfully Downloaded file - emalware.308 (107313)
Successfully Downloaded file - emalware.075 (192229)
Successfully Downloaded file - emalware.001 (76550)
Successfully Downloaded file - emalware.038 (118810)
Successfully Downloaded file - emalware.344 (103725)
Successfully Downloaded file - emalware.023 (145434)
Successfully Downloaded file - emalware.061 (131552)
Successfully Downloaded file - emalware.060 (117123)
Successfully Downloaded file - emalware.081 (76719)
Successfully Downloaded file - emalware.328 (84266)
Successfully Downloaded file - emalware.062 (176895)
Successfully Downloaded file - sdx.ivd (156098)
Successfully Downloaded file - emalware.361 (212039)
Successfully Downloaded file - e_spyw.i05 (258162)
Successfully Downloaded file - variant.c01 (2707775)
Successfully Downloaded file - emalware.047 (121551)
Successfully Downloaded file - emalware.040 (106706)
Successfully Downloaded file - emalware.528 (302368)
Successfully Downloaded file - emalware.110 (117865)
Successfully Downloaded file - emalware.527 (269315)
Successfully Downloaded file - emalware.329 (98544)
Successfully Downloaded file - pdftok.cvd (28367)
Successfully Downloaded file - emalware.307 (107340)
Successfully Downloaded file - emalware.366 (121774)
Successfully Downloaded file - emalware.093 (166430)
Successfully Downloaded file - emalware.019 (129409)
Successfully Downloaded file - emalware.318 (136874)
Successfully Downloaded file - emalware.084 (70291)
Successfully Downloaded file - e_spyw.i06 (303699)
Successfully Downloaded file - cevakrnl.rv8 (458016)
Successfully Downloaded file - htmltok.cvd (36609)
Successfully Downloaded file - emalware.087 (50165)
Successfully Downloaded file - emalware.112 (181575)
Successfully Downloaded file - emalware.009 (126302)
Successfully Downloaded file - emalware.354 (176014)
Successfully Downloaded file - emalware.000 (918076)
Successfully Downloaded file - emalware.357 (141438)
Successfully Downloaded file - emalware.526 (295950)
Successfully Downloaded file - emalware.037 (141954)
Successfully Downloaded file - emalware.051 (138736)
Successfully Downloaded file - emalware.105 (124332)
Successfully Downloaded file - emalware.036 (87270)
Successfully Downloaded file - emalware.096 (179194)
Successfully Downloaded file - emalware.323 (94870)
Successfully Downloaded file - emalware.332 (90587)
Successfully Downloaded file - e_spyw.i28 (293706)
Successfully Downloaded file - emalware.117 (212275)
Successfully Downloaded file - emalware.082 (90141)
Successfully Downloaded file - emalware.352 (172203)
Successfully Downloaded file - emalware.521 (290799)
Successfully Downloaded file - emalware.005 (177401)
Successfully Downloaded file - e_spyw.i08 (169333)
Successfully Downloaded file - emalware.356 (153269)
Successfully Downloaded file - emalware.531 (264078)
Successfully Downloaded file - emalware.024 (136672)
Successfully Downloaded file - e_spyw.i22 (302933)
Successfully Downloaded file - emalware.069 (102190)
Successfully Downloaded file - emalware.525 (282598)
Successfully Downloaded file - emalware.369 (201324)
Successfully Downloaded file - emalware.010 (134011)
Successfully Downloaded file - emalware.052 (179758)
Successfully Downloaded file - emalware.367 (123327)
Successfully Downloaded file - emalware.342 (116333)
Successfully Downloaded file - emalware.324 (108954)
Successfully Downloaded file - emalware.034 (123629)
Successfully Downloaded file - emalware.351 (163203)
Successfully Downloaded file - emalware.340 (108766)
Successfully Downloaded file - emalware.114 (145169)
Successfully Downloaded file - e_spyw.i01 (270394)
Successfully Downloaded file - emalware.530 (283127)
Successfully Downloaded file - emalware.089 (68521)
Successfully Downloaded file - emalware.311 (77977)
Successfully Downloaded file - emalware.333 (195436)
Successfully Downloaded file - e_spyw.i18 (165324)
Successfully Downloaded file - emalware.071 (132415)
Successfully Downloaded file - cevakrnl.rv0 (283441)
Successfully Downloaded file - e_spyw.i25 (310558)
Successfully Downloaded file - emalware.109 (146078)
Successfully Downloaded file - emalware.091 (155598)
Successfully Downloaded file - emalware.346 (137321)
Successfully Downloaded file - e_spyw.i24 (325748)
Successfully Downloaded file - emalware.336 (85191)
Successfully Downloaded file - e_spyw.i26 (332850)
Successfully Downloaded file - e_spyw.i19 (122095)
Successfully Downloaded file - emalware.315 (105612)
Successfully Downloaded file - emalware.343 (146020)
Successfully Downloaded file - emalware.072 (121570)
Successfully Downloaded file - emalware.045 (153993)
Successfully Downloaded file - emalware.049 (192374)
Successfully Downloaded file - emalware.106 (138108)
Successfully Downloaded file - emalware.094 (155610)
Successfully Downloaded file - emalware.326 (123805)
Successfully Downloaded file - emalware.099 (160105)
Successfully Downloaded file - e_spyw.i14 (168588)
Successfully Downloaded file - emalware.353 (159228)
Successfully Downloaded file - emalware.050 (133700)
Successfully Downloaded file - emalware.364 (211575)
Successfully Downloaded file - e_spyw.i09 (198157)
Successfully Downloaded file - e_spyw.i11 (150986)
Successfully Downloaded file - emalware.002 (258582)
Successfully Downloaded file - emalware.348 (122348)
Successfully Downloaded file - emalware.067 (125067)
Successfully Downloaded file - emalware.523 (282520)
Successfully Downloaded file - emalware.004 (162327)
Successfully Downloaded file - e_spyw.i23 (270249)
Successfully Downloaded file - emalware.048 (140714)
Successfully Downloaded file - dalvik.cvd (121970)
Successfully Downloaded file - emalware.079 (185390)
Successfully Downloaded file - jpeg.cvd (11934)
Successfully Downloaded file - emalware.363 (220022)
Successfully Downloaded file - emalware.013 (129660)
Successfully Downloaded file - emalware.006 (141036)
Successfully Downloaded file - emalware.355 (134758)
Successfully Downloaded file - e_spyw.i13 (165472)
Successfully Downloaded file - e_spyw.i27 (321821)
Successfully Downloaded file - emalware.057 (187429)
Successfully Downloaded file - emalware.077 (177720)
Successfully Downloaded file - emalware.065 (144928)
Successfully Downloaded file - emalware.107 (123970)
Successfully Downloaded file - emalware.008 (138884)
Successfully Downloaded file - emalware.074 (144843)
Successfully Downloaded file - emalware.349 (316610)
Successfully Downloaded file - e_spyw.i21 (128666)
Successfully Downloaded file - emalware.018 (198970)
Successfully Downloaded file - emalware.310 (107332)
Successfully Downloaded file - dalvik.xmd (17310)
Successfully Downloaded file - avc3_installer.st (1810)
Successfully Downloaded file - avc3.hx (131435)
Successfully Downloaded file - avc3_main.st (70228)
Successfully Downloaded file - avc3.ic (39296)
Successfully Downloaded file - update.bin (35)
Successfully Downloaded file - avc3.fr (234882)
Successfully Downloaded file - settings.avc3 (569)
Successfully Downloaded file - avc3.rd (662)
Successfully Downloaded file - avcuf64.dll (249508)
Successfully Downloaded file - exploits.avc3 (452)
Successfully Downloaded file - avcuf32.dll (226800)
Successfully Downloaded file - avc3.mx (12448)
Successfully Downloaded file - avc3.qx (1737)
Successfully Downloaded file - avc3.hxi (7521)
Successfully Downloaded file - update.bin (35)
Total number of Anti-Virus files downloaded is 252
Connecting to HTTP host <Direct connection>
Connecting to http://www.microworldsystems.com ...
Requested file name and size information...
Successfully Downloaded file - clnsign2.avs (7880)
Successfully Downloaded file - cloudig.avs (1641)
Successfully Downloaded file - httpsite.txt (189)
Successfully Downloaded file - iplist.ini (90)
Successfully Downloaded file - phlist17.avs (192872)
Successfully Downloaded file - remove.ini (1943)
Successfully Downloaded file - update.txt (1304)
Successfully Downloaded file - updll10.dlz (1116603)
Successfully Downloaded file - url1a.avs (230643)
Successfully Downloaded file - url1d.avs (229930)
Successfully Downloaded file - url2c.avs (228215)
Successfully Downloaded file - url2d.avs (238511)
Successfully Downloaded file - url2e.avs (160386)
Successfully Downloaded file - url4.avs (164970)
Successfully Downloaded file - url5.avs (199650)
Successfully Downloaded file - urla.avs (201546)
Successfully Downloaded file - urld.avs (236909)
Successfully Downloaded file - vsignj.avs (79724)
KLB comparison started
There is no file found in KLB comparison
Downloaded 18 files.Terminating session...
----------------------------------------------------------------------
7.3.2013 12:31:37 Terminating HTTP Session
Re: Počítač zamrzá při startu
Posílám nový log z RSIT a zároveň se pokusím zkidnit a vyčkat rad zkušených 
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ervd at 2013-03-07 14:03:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 271 GB (60%) free of 455 GB
Total RAM: 4030 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:05:12, on 7.3.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\RapooV1Process.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files\trend micro\Ervd.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MagniPic - {CC6084C6-42BE-3EBE-22D0-66C55B335E6B} - C:\ProgramData\MagniPic\511d307d9314a.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [trustGTX14] "C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~2\magnipic\sprote~1.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Brother Resource manager service (brmfrsmg) - Unknown owner - C:\windows\system32\BrmfRsmg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Game Mouse Communication And Update Service V1 (KmGameMouseServiceV1) - UASSOFT.COM - C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MSC.Licensing_11.9 - Flexera Software, Inc. - C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14558 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
taskeng.exe {270F39A7-36B4-467D-B14E-8094A8BB60EA}
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxtray.exe"
taskeng.exe {83C23A31-F171-4A71-8DE5-ACB0B4B75F15}
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\windows\system32\BrmfRsmg.exe -service
C:\windows\system32\BrmfRsmg.exe -process -overmain -load -open
"C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE"
"C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe" RapooV1Process.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
RapooV1Process.exe
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /c /a /s UserSession2
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
WLIDSvcM.exe 3004
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
-Minimized
"C:\Users\Ervd\Desktop\RSITx64.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\sppsvc.exe
"C:\windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /taskrestart
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe" /taskschd
wmiadap.exe /F /T
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AutoKMS.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\HPCeeScheduleForERVD-HP$.job
C:\windows\tasks\HPCeeScheduleForErvd.job
C:\windows\tasks\MagniPicUpdaterTask{4B84FAAA-0663-4D31-BE8A-3190F52801C0}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-08-16 545264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-08-16 193520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL [2012-06-21 210400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-02-24 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC6084C6-42BE-3EBE-22D0-66C55B335E6B}]
MagniPic - C:\ProgramData\MagniPic\511d307d9314a.dll [2013-02-14 118272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-02-24 170912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-09-16 2828072]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-09-01 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-09-01 392472]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-09-01 416024]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-02-15 21709904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess]
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-09-17 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-08-03 1086376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08 18705664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-01-07 446648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-02-25 1602984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-12-10 5629312]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"trustGTX14"=C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe [2009-05-11 4832256]
"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-05-23 103992]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-09-01 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktopChanges"=1
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-03-07 12:36:24 ----AD---- C:\windows\VDLL.DLL
2013-03-07 12:36:24 ----AD---- C:\windows\SYSWOW64\runouce.exe
2013-03-07 12:36:24 ----AD---- C:\windows\RUNDL132.EXE
2013-03-07 12:36:24 ----AD---- C:\windows\logo_1.exe
2013-03-07 12:27:33 ----A---- C:\windows\system32\drivers\trufos.sys
2013-03-07 12:27:26 ----A---- C:\windows\SYSWOW64\msvcr80.dll
2013-03-07 12:27:25 ----A---- C:\windows\SYSWOW64\msvcp80.dll
2013-03-07 12:27:24 ----A---- C:\windows\SYSWOW64\msvcp90.dll
2013-03-07 12:27:23 ----A---- C:\windows\SYSWOW64\msvcr90.dll
2013-03-07 12:27:22 ----A---- C:\windows\SYSWOW64\eEmpty.exe
2013-03-07 12:27:12 ----D---- C:\ProgramData\MicroWorld
2013-03-07 12:04:34 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-03-07 12:04:09 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2013-03-07 12:02:15 ----D---- C:\windows\PCHEALTH
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2013-03-07 11:49:09 ----A---- C:\windows\ntbtlog.txt
2013-03-07 09:46:23 ----SHD---- C:\Config.Msi
2013-03-06 23:15:06 ----N---- C:\bootsqm.dat
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\msmpeg2vdec.dll
2013-02-28 00:00:36 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-02-28 00:00:36 ----A---- C:\windows\system32\WMPhoto.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10_1.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\d2d1.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\FntCache.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\d2d1.dll
2013-02-26 12:56:01 ----A---- C:\windows\AutoKMS.ini
2013-02-26 11:55:52 ----D---- C:\office
2013-02-24 13:32:44 ----A---- C:\windows\SYSWOW64\javaws.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\javaw.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\java.exe
2013-02-24 13:32:08 ----D---- C:\Program Files (x86)\Java
2013-02-17 15:45:23 ----D---- C:\ProgramData\Prometheus
2013-02-17 15:45:23 ----D---- C:\Program Files (x86)\Prometheus
2013-02-14 19:17:04 ----D---- C:\ProgramData\CLSoft LTD
2013-02-14 19:16:58 ----D---- C:\ProgramData\Premium
2013-02-14 19:16:53 ----D---- C:\Program Files (x86)\MagniPic
2013-02-14 19:16:48 ----D---- C:\ProgramData\MagniPic
2013-02-14 19:16:43 ----D---- C:\ProgramData\InstallMate
2013-02-14 19:16:37 ----A---- C:\prefs.js
2013-02-14 19:04:29 ----D---- C:\Program Files (x86)\Conduit
2013-02-14 19:02:26 ----D---- C:\Users\Ervd\AppData\Roaming\ExpressFiles
2013-02-13 11:38:48 ----D---- C:\ProgramData\Blizzard Entertainment
2013-02-13 11:38:48 ----D---- C:\Program Files (x86)\Diablo III
2013-02-13 11:37:24 ----D---- C:\ProgramData\Battle.net
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\ieui.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-02-13 11:26:20 ----A---- C:\windows\system32\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\ieUnatt.exe
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\wininet.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\vbscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\jscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\iertutil.dll
2013-02-13 11:26:16 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-02-13 11:26:14 ----A---- C:\windows\system32\mshtml.dll
2013-02-13 11:26:13 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-02-13 11:26:13 ----A---- C:\windows\system32\ieframe.dll
2013-02-13 11:10:51 ----A---- C:\windows\system32\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 11:10:45 ----A---- C:\windows\system32\win32k.sys
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\user.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-02-13 11:10:44 ----A---- C:\windows\system32\winsrv.dll
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-08 11:08:29 ----RD---- C:\Program Files (x86)\Skype
======List of files/folders modified in the last 1 month======
2013-03-07 14:04:49 ----D---- C:\Program Files\trend micro
2013-03-07 14:03:58 ----A---- C:\windows\SYSWOW64\log.txt
2013-03-07 14:03:46 ----D---- C:\windows\Temp
2013-03-07 14:01:37 ----D---- C:\Users\Ervd\AppData\Roaming\Dropbox
2013-03-07 14:01:17 ----D---- C:\ProgramData\PDFC
2013-03-07 13:47:41 ----D---- C:\Windows
2013-03-07 12:36:24 ----D---- C:\windows\SysWOW64
2013-03-07 12:28:52 ----A---- C:\windows\win.ini
2013-03-07 12:27:33 ----D---- C:\windows\system32\drivers
2013-03-07 12:27:18 ----D---- C:\Program Files (x86)\Common Files
2013-03-07 12:27:12 ----HD---- C:\ProgramData
2013-03-07 12:04:48 ----SHD---- C:\windows\Installer
2013-03-07 12:04:34 ----RSD---- C:\windows\Fonts
2013-03-07 12:04:34 ----RD---- C:\Program Files (x86)
2013-03-07 12:04:31 ----D---- C:\Program Files (x86)\MSBuild
2013-03-07 12:04:29 ----D---- C:\windows\ShellNew
2013-03-07 12:04:12 ----D---- C:\Program Files (x86)\Microsoft Office
2013-03-07 12:02:15 ----SD---- C:\ProgramData\Microsoft
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft.NET
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-03-07 11:59:47 ----RSD---- C:\windows\assembly
2013-03-07 11:49:09 ----D---- C:\Users\Ervd\AppData\Roaming\DAEMON Tools Lite
2013-03-07 11:46:42 ----D---- C:\windows\inf
2013-03-07 11:46:37 ----D---- C:\windows\SoftwareDistribution
2013-03-07 11:46:09 ----SD---- C:\Users\Ervd\AppData\Roaming\Microsoft
2013-03-07 10:06:37 ----D---- C:\windows\system32\config
2013-03-07 10:00:10 ----SHD---- C:\System Volume Information
2013-03-07 09:55:44 ----D---- C:\ProgramData\Microsoft Help
2013-03-07 09:50:24 ----RD---- C:\Program Files
2013-03-07 09:47:18 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-03-07 09:41:18 ----D---- C:\windows\Prefetch
2013-03-06 23:27:57 ----D---- C:\Program Files (x86)\Steam
2013-03-05 20:08:22 ----D---- C:\Users\Ervd\AppData\Roaming\Media Player Classic
2013-03-05 20:07:39 ----D---- C:\Program Files\CCleaner
2013-03-05 11:06:35 ----D---- C:\windows\System32
2013-03-05 11:06:35 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-03-04 16:23:33 ----D---- C:\windows\system32\catroot2
2013-03-04 01:29:37 ----D---- C:\ProgramData\FLEXnet
2013-03-03 15:56:35 ----D---- C:\Users\Ervd\AppData\Roaming\Skype
2013-03-01 21:08:51 ----D---- C:\Program Files (x86)\Google
2013-03-01 15:36:05 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-02-28 09:39:33 ----D---- C:\windows\winsxs
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\zh-HK
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-PT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-BR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pl-PL
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\ko-KR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\it-IT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\hu-HU
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\el-GR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-TW
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-CN
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\tr-TR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\sv-SE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ru-RU
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\nl-NL
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ja-JP
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fr-FR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fi-FI
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\es-ES
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\de-DE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\nb-NO
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\en-US
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\da-DK
2013-02-28 09:38:32 ----D---- C:\windows\system32\zh-HK
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-PT
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-BR
2013-02-28 09:38:32 ----D---- C:\windows\system32\pl-PL
2013-02-28 09:38:32 ----D---- C:\windows\system32\nl-NL
2013-02-28 09:38:32 ----D---- C:\windows\system32\ko-KR
2013-02-28 09:38:32 ----D---- C:\windows\system32\it-IT
2013-02-28 09:38:32 ----D---- C:\windows\system32\hu-HU
2013-02-28 09:38:32 ----D---- C:\windows\system32\el-GR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fr-FR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fi-FI
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-TW
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-CN
2013-02-28 09:38:29 ----D---- C:\windows\system32\tr-TR
2013-02-28 09:38:29 ----D---- C:\windows\system32\sv-SE
2013-02-28 09:38:29 ----D---- C:\windows\system32\es-ES
2013-02-28 09:38:29 ----D---- C:\windows\system32\de-DE
2013-02-28 09:38:29 ----D---- C:\windows\system32\cs-CZ
2013-02-28 09:38:28 ----D---- C:\windows\system32\ru-RU
2013-02-28 09:38:28 ----D---- C:\windows\system32\nb-NO
2013-02-28 09:38:28 ----D---- C:\windows\system32\ja-JP
2013-02-28 09:38:28 ----D---- C:\windows\system32\en-US
2013-02-28 09:38:28 ----D---- C:\windows\system32\da-DK
2013-02-28 00:03:16 ----D---- C:\windows\system32\catroot
2013-02-27 17:11:46 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2013-02-26 14:34:42 ----D---- C:\windows\Microsoft.NET
2013-02-26 13:25:20 ----D---- C:\Users\Ervd\AppData\Roaming\SoftGrid Client
2013-02-26 12:56:02 ----D---- C:\windows\system32\Tasks
2013-02-26 12:56:01 ----D---- C:\windows\Tasks
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\npDeployJava1.dll
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\deployJava1.dll
2013-02-18 11:03:56 ----D---- C:\ProgramData\Adobe
2013-02-14 01:01:29 ----D---- C:\windows\debug
2013-02-13 13:19:30 ----D---- C:\windows\SYSWOW64\migration
2013-02-13 13:19:30 ----D---- C:\windows\system32\migration
2013-02-13 13:19:30 ----D---- C:\windows\AppPatch
2013-02-13 13:19:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-13 13:19:29 ----D---- C:\Program Files\Internet Explorer
2013-02-13 11:34:08 ----A---- C:\windows\system32\MRT.exe
2013-02-11 12:04:38 ----D---- C:\windows\Logs
2013-02-08 11:08:39 ----D---- C:\ProgramData\Skype
2013-02-08 10:20:00 ----D---- C:\Program Files (x86)\Opera
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-03-29 451192]
R0 SymEFA;Symantec Extended File Attributes; C:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-01-16 1388120]
R1 ccSet_NIS;Norton Internet Security Settings Manager; C:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-21 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-01-19 484512]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20130306.001\IDSvia64.sys [2013-01-11 513184]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [2012-07-06 37536]
R1 SymIRON;Symantec Iron Driver; C:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
R1 SymNetS;Symantec Network Security WFP Driver; C:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-10-14 10496000]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-10-14 326656]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-01-19 138912]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys [2010-12-03 25912]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.035\ENG64.SYS [2013-01-19 126192]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.035\EX64.SYS [2013-01-19 2087664]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [2012-07-06 737952]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SymEvent;SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [2012-06-09 175736]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-09-16 392752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BrUsbScn;Ovladač skeneru Brother MFC USB; C:\windows\System32\Drivers\BrUsbScn.sys [2009-06-10 14336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-01-02 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-06-30 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2011-02-08 486144]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2013-01-16 27760]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-09-01 12306848]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 trufos;trufos; C:\windows\system32\drivers\trufos.sys [2013-03-07 350160]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-10-14 204288]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
R2 brmfrsmg;Brother Resource manager service; C:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
R2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1; C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-08-10 1001376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 251248]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-09 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S3 MSC.Licensing_11.9;MSC.Licensing_11.9; C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe [2011-03-15 1775440]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-08-01 724888]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------

Logfile of random's system information tool 1.09 (written by random/random)
Run by Ervd at 2013-03-07 14:03:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 271 GB (60%) free of 455 GB
Total RAM: 4030 MB (37% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:05:12, on 7.3.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal
Running processes:
C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe
C:\Program Files (x86)\Trust\GXT14 Mouse\RapooV1Process.exe
C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
C:\Program Files\trend micro\Ervd.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/?aff=7&uid=a261b29e ... 115b30fe5c
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MagniPic - {CC6084C6-42BE-3EBE-22D0-66C55B335E6B} - C:\ProgramData\MagniPic\511d307d9314a.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [trustGTX14] "C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\progra~2\magnipic\sprote~1.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Brother Resource manager service (brmfrsmg) - Unknown owner - C:\windows\system32\BrmfRsmg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Game Mouse Communication And Update Service V1 (KmGameMouseServiceV1) - UASSOFT.COM - C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MSC.Licensing_11.9 - Flexera Software, Inc. - C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14558 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\windows\system32\Hpservice.exe
C:\windows\system32\vcsFPService.exe
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
taskeng.exe {270F39A7-36B4-467D-B14E-8094A8BB60EA}
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\igfxtray.exe"
taskeng.exe {83C23A31-F171-4A71-8DE5-ACB0B4B75F15}
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\windows\system32\BrmfRsmg.exe -service
C:\windows\system32\BrmfRsmg.exe -process -overmain -load -open
"C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE"
"C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /s "NIS" /m "C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Program Files (x86)\Trust\GXT14 Mouse\StartAutorun.exe" RapooV1Process.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
RapooV1Process.exe
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe" /c /a /s UserSession2
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
WLIDSvcM.exe 3004
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
-Minimized
"C:\Users\Ervd\Desktop\RSITx64.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\sppsvc.exe
"C:\windows\system32\SearchFilterHost.exe" 0 512 516 524 65536 520
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe" /taskrestart
"C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\WSCStub.exe" /taskschd
wmiadap.exe /F /T
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AutoKMS.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\HPCeeScheduleForERVD-HP$.job
C:\windows\tasks\HPCeeScheduleForErvd.job
C:\windows\tasks\MagniPicUpdaterTask{4B84FAAA-0663-4D31-BE8A-3190F52801C0}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-08-16 545264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-08-16 193520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\IPS\IPSBHO.DLL [2012-06-21 210400]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-02-24 461216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC6084C6-42BE-3EBE-22D0-66C55B335E6B}]
MagniPic - C:\ProgramData\MagniPic\511d307d9314a.dll [2013-02-14 118272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-02-24 170912]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coIEPlg.dll [2013-02-01 512408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-09-16 2828072]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-09-01 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-09-01 392472]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-09-01 416024]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2011-01-27 835072]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-02-15 21709904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess]
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-09-17 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-08-03 1086376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-02-01 656920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08 18705664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-01-07 446648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-02-25 1602984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-12-10 5629312]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2011-01-29 299576]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"trustGTX14"=C:\Program Files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe [2009-05-11 4832256]
"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2011-05-23 103992]
""= []
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-09-01 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktopChanges"=1
"NoDriveTypeAutoRun"=153
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-03-07 12:36:24 ----AD---- C:\windows\VDLL.DLL
2013-03-07 12:36:24 ----AD---- C:\windows\SYSWOW64\runouce.exe
2013-03-07 12:36:24 ----AD---- C:\windows\RUNDL132.EXE
2013-03-07 12:36:24 ----AD---- C:\windows\logo_1.exe
2013-03-07 12:27:33 ----A---- C:\windows\system32\drivers\trufos.sys
2013-03-07 12:27:26 ----A---- C:\windows\SYSWOW64\msvcr80.dll
2013-03-07 12:27:25 ----A---- C:\windows\SYSWOW64\msvcp80.dll
2013-03-07 12:27:24 ----A---- C:\windows\SYSWOW64\msvcp90.dll
2013-03-07 12:27:23 ----A---- C:\windows\SYSWOW64\msvcr90.dll
2013-03-07 12:27:22 ----A---- C:\windows\SYSWOW64\eEmpty.exe
2013-03-07 12:27:12 ----D---- C:\ProgramData\MicroWorld
2013-03-07 12:04:34 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2013-03-07 12:04:09 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2013-03-07 12:02:15 ----D---- C:\windows\PCHEALTH
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2013-03-07 11:49:09 ----A---- C:\windows\ntbtlog.txt
2013-03-07 09:46:23 ----SHD---- C:\Config.Msi
2013-03-06 23:15:06 ----N---- C:\bootsqm.dat
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\UIAnimation.dll
2013-02-28 00:00:39 ----A---- C:\windows\system32\msmpeg2vdec.dll
2013-02-28 00:00:36 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-02-28 00:00:36 ----A---- C:\windows\system32\WMPhoto.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-28 00:00:33 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10warp.dll
2013-02-28 00:00:33 ----A---- C:\windows\system32\d3d10_1.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\SYSWOW64\d3d10.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\XpsPrint.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\dxgi.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d11.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10level9.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10_1core.dll
2013-02-28 00:00:32 ----A---- C:\windows\system32\d3d10.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\SYSWOW64\d2d1.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\WindowsCodecs.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\FntCache.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\DWrite.dll
2013-02-28 00:00:31 ----A---- C:\windows\system32\d2d1.dll
2013-02-26 12:56:01 ----A---- C:\windows\AutoKMS.ini
2013-02-26 11:55:52 ----D---- C:\office
2013-02-24 13:32:44 ----A---- C:\windows\SYSWOW64\javaws.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\javaw.exe
2013-02-24 13:32:22 ----A---- C:\windows\SYSWOW64\java.exe
2013-02-24 13:32:08 ----D---- C:\Program Files (x86)\Java
2013-02-17 15:45:23 ----D---- C:\ProgramData\Prometheus
2013-02-17 15:45:23 ----D---- C:\Program Files (x86)\Prometheus
2013-02-14 19:17:04 ----D---- C:\ProgramData\CLSoft LTD
2013-02-14 19:16:58 ----D---- C:\ProgramData\Premium
2013-02-14 19:16:53 ----D---- C:\Program Files (x86)\MagniPic
2013-02-14 19:16:48 ----D---- C:\ProgramData\MagniPic
2013-02-14 19:16:43 ----D---- C:\ProgramData\InstallMate
2013-02-14 19:16:37 ----A---- C:\prefs.js
2013-02-14 19:04:29 ----D---- C:\Program Files (x86)\Conduit
2013-02-14 19:02:26 ----D---- C:\Users\Ervd\AppData\Roaming\ExpressFiles
2013-02-13 11:38:48 ----D---- C:\ProgramData\Blizzard Entertainment
2013-02-13 11:38:48 ----D---- C:\Program Files (x86)\Diablo III
2013-02-13 11:37:24 ----D---- C:\ProgramData\Battle.net
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\mshtmled.dll
2013-02-13 11:26:21 ----A---- C:\windows\system32\ieui.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-02-13 11:26:20 ----A---- C:\windows\system32\urlmon.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\url.dll
2013-02-13 11:26:20 ----A---- C:\windows\system32\ieUnatt.exe
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-02-13 11:26:19 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\msfeeds.dll
2013-02-13 11:26:19 ----A---- C:\windows\system32\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-02-13 11:26:18 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\wininet.dll
2013-02-13 11:26:18 ----A---- C:\windows\system32\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-02-13 11:26:17 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\vbscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\jscript.dll
2013-02-13 11:26:17 ----A---- C:\windows\system32\iertutil.dll
2013-02-13 11:26:16 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-02-13 11:26:14 ----A---- C:\windows\system32\mshtml.dll
2013-02-13 11:26:13 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-02-13 11:26:13 ----A---- C:\windows\system32\ieframe.dll
2013-02-13 11:10:51 ----A---- C:\windows\system32\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-02-13 11:10:50 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 11:10:45 ----A---- C:\windows\system32\win32k.sys
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\user.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-02-13 11:10:44 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-02-13 11:10:44 ----A---- C:\windows\system32\winsrv.dll
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-02-13 11:10:43 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-08 11:08:29 ----RD---- C:\Program Files (x86)\Skype
======List of files/folders modified in the last 1 month======
2013-03-07 14:04:49 ----D---- C:\Program Files\trend micro
2013-03-07 14:03:58 ----A---- C:\windows\SYSWOW64\log.txt
2013-03-07 14:03:46 ----D---- C:\windows\Temp
2013-03-07 14:01:37 ----D---- C:\Users\Ervd\AppData\Roaming\Dropbox
2013-03-07 14:01:17 ----D---- C:\ProgramData\PDFC
2013-03-07 13:47:41 ----D---- C:\Windows
2013-03-07 12:36:24 ----D---- C:\windows\SysWOW64
2013-03-07 12:28:52 ----A---- C:\windows\win.ini
2013-03-07 12:27:33 ----D---- C:\windows\system32\drivers
2013-03-07 12:27:18 ----D---- C:\Program Files (x86)\Common Files
2013-03-07 12:27:12 ----HD---- C:\ProgramData
2013-03-07 12:04:48 ----SHD---- C:\windows\Installer
2013-03-07 12:04:34 ----RSD---- C:\windows\Fonts
2013-03-07 12:04:34 ----RD---- C:\Program Files (x86)
2013-03-07 12:04:31 ----D---- C:\Program Files (x86)\MSBuild
2013-03-07 12:04:29 ----D---- C:\windows\ShellNew
2013-03-07 12:04:12 ----D---- C:\Program Files (x86)\Microsoft Office
2013-03-07 12:02:15 ----SD---- C:\ProgramData\Microsoft
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft.NET
2013-03-07 12:02:15 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-03-07 11:59:47 ----RSD---- C:\windows\assembly
2013-03-07 11:49:09 ----D---- C:\Users\Ervd\AppData\Roaming\DAEMON Tools Lite
2013-03-07 11:46:42 ----D---- C:\windows\inf
2013-03-07 11:46:37 ----D---- C:\windows\SoftwareDistribution
2013-03-07 11:46:09 ----SD---- C:\Users\Ervd\AppData\Roaming\Microsoft
2013-03-07 10:06:37 ----D---- C:\windows\system32\config
2013-03-07 10:00:10 ----SHD---- C:\System Volume Information
2013-03-07 09:55:44 ----D---- C:\ProgramData\Microsoft Help
2013-03-07 09:50:24 ----RD---- C:\Program Files
2013-03-07 09:47:18 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-03-07 09:41:18 ----D---- C:\windows\Prefetch
2013-03-06 23:27:57 ----D---- C:\Program Files (x86)\Steam
2013-03-05 20:08:22 ----D---- C:\Users\Ervd\AppData\Roaming\Media Player Classic
2013-03-05 20:07:39 ----D---- C:\Program Files\CCleaner
2013-03-05 11:06:35 ----D---- C:\windows\System32
2013-03-05 11:06:35 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-03-04 16:23:33 ----D---- C:\windows\system32\catroot2
2013-03-04 01:29:37 ----D---- C:\ProgramData\FLEXnet
2013-03-03 15:56:35 ----D---- C:\Users\Ervd\AppData\Roaming\Skype
2013-03-01 21:08:51 ----D---- C:\Program Files (x86)\Google
2013-03-01 15:36:05 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-02-28 09:39:33 ----D---- C:\windows\winsxs
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\zh-HK
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-PT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pt-BR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\pl-PL
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\ko-KR
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\it-IT
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\hu-HU
2013-02-28 09:38:35 ----D---- C:\windows\SYSWOW64\el-GR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-TW
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\zh-CN
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\tr-TR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\sv-SE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ru-RU
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\nl-NL
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\ja-JP
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fr-FR
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\fi-FI
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\es-ES
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\de-DE
2013-02-28 09:38:34 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\nb-NO
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\en-US
2013-02-28 09:38:33 ----D---- C:\windows\SYSWOW64\da-DK
2013-02-28 09:38:32 ----D---- C:\windows\system32\zh-HK
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-PT
2013-02-28 09:38:32 ----D---- C:\windows\system32\pt-BR
2013-02-28 09:38:32 ----D---- C:\windows\system32\pl-PL
2013-02-28 09:38:32 ----D---- C:\windows\system32\nl-NL
2013-02-28 09:38:32 ----D---- C:\windows\system32\ko-KR
2013-02-28 09:38:32 ----D---- C:\windows\system32\it-IT
2013-02-28 09:38:32 ----D---- C:\windows\system32\hu-HU
2013-02-28 09:38:32 ----D---- C:\windows\system32\el-GR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fr-FR
2013-02-28 09:38:31 ----D---- C:\windows\system32\fi-FI
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-TW
2013-02-28 09:38:29 ----D---- C:\windows\system32\zh-CN
2013-02-28 09:38:29 ----D---- C:\windows\system32\tr-TR
2013-02-28 09:38:29 ----D---- C:\windows\system32\sv-SE
2013-02-28 09:38:29 ----D---- C:\windows\system32\es-ES
2013-02-28 09:38:29 ----D---- C:\windows\system32\de-DE
2013-02-28 09:38:29 ----D---- C:\windows\system32\cs-CZ
2013-02-28 09:38:28 ----D---- C:\windows\system32\ru-RU
2013-02-28 09:38:28 ----D---- C:\windows\system32\nb-NO
2013-02-28 09:38:28 ----D---- C:\windows\system32\ja-JP
2013-02-28 09:38:28 ----D---- C:\windows\system32\en-US
2013-02-28 09:38:28 ----D---- C:\windows\system32\da-DK
2013-02-28 00:03:16 ----D---- C:\windows\system32\catroot
2013-02-27 17:11:46 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2013-02-26 14:34:42 ----D---- C:\windows\Microsoft.NET
2013-02-26 13:25:20 ----D---- C:\Users\Ervd\AppData\Roaming\SoftGrid Client
2013-02-26 12:56:02 ----D---- C:\windows\system32\Tasks
2013-02-26 12:56:01 ----D---- C:\windows\Tasks
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\npDeployJava1.dll
2013-02-24 13:32:10 ----A---- C:\windows\SYSWOW64\deployJava1.dll
2013-02-18 11:03:56 ----D---- C:\ProgramData\Adobe
2013-02-14 01:01:29 ----D---- C:\windows\debug
2013-02-13 13:19:30 ----D---- C:\windows\SYSWOW64\migration
2013-02-13 13:19:30 ----D---- C:\windows\system32\migration
2013-02-13 13:19:30 ----D---- C:\windows\AppPatch
2013-02-13 13:19:30 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-13 13:19:29 ----D---- C:\Program Files\Internet Explorer
2013-02-13 11:34:08 ----A---- C:\windows\system32\MRT.exe
2013-02-11 12:04:38 ----D---- C:\windows\Logs
2013-02-08 11:08:39 ----D---- C:\ProgramData\Skype
2013-02-08 10:20:00 ----D---- C:\Program Files (x86)\Opera
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-03-29 451192]
R0 SymEFA;Symantec Extended File Attributes; C:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-01-16 1388120]
R1 ccSet_NIS;Norton Internet Security Settings Manager; C:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-21 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-01-19 484512]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20130306.001\IDSvia64.sys [2013-01-11 513184]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\windows\system32\drivers\NISx64\1309010.00E\SRTSPX64.SYS [2012-07-06 37536]
R1 SymIRON;Symantec Iron Driver; C:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
R1 SymNetS;Symantec Network Security WFP Driver; C:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-10-14 10496000]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-10-14 326656]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-01-19 138912]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys [2010-12-03 25912]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
R3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.035\ENG64.SYS [2013-01-19 126192]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\VirusDefs\20130306.035\EX64.SYS [2013-01-19 2087664]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\windows\System32\Drivers\NISx64\1309010.00E\SRTSP64.SYS [2012-07-06 737952]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2011-01-27 520192]
R3 SymEvent;SymEvent; \??\C:\windows\system32\Drivers\SYMEVENT64x86.SYS [2012-06-09 175736]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2011-09-16 392752]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BrUsbScn;Ovladač skeneru Brother MFC USB; C:\windows\System32\Drivers\BrUsbScn.sys [2009-06-10 14336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-01-02 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-06-30 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2011-02-08 486144]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2013-01-16 27760]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-09-01 12306848]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 trufos;trufos; C:\windows\system32\drivers\trufos.sys [2013-03-07 350160]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-18 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-12-18 65192]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-10-14 204288]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
R2 brmfrsmg;Brother Resource manager service; C:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-29 281656]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2011-05-13 30520]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
R2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1; C:\Program Files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 NIS;Norton Internet Security; C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2011-01-27 296448]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-08-10 1001376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
S2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-27 251248]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-09 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S3 MSC.Licensing_11.9;MSC.Licensing_11.9; C:\MSC.Software\MSC.Licensing\11.9\lmgrd.exe [2011-03-15 1775440]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-08-01 724888]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: Počítač zamrzá při startu
nuz vyckaj a napis cosi o nelegalnych produktoch tohto pocitaca



FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Počítač zamrzá při startu
Widows 7 jsou legalní.
Norton internet security je legální.
Včera jsem zjistil, že byl před týdnem do PC asi nainstalován vir (nevím jistě, jen domněnka) spolu s nelegalními microsoft office 2010.
Mám tam ještě nějaké nelegální svistvo?
NIS je zjevně zbytečný, když je uživatel vymaštěný
Norton internet security je legální.
Včera jsem zjistil, že byl před týdnem do PC asi nainstalován vir (nevím jistě, jen domněnka) spolu s nelegalními microsoft office 2010.
Mám tam ještě nějaké nelegální svistvo?
NIS je zjevně zbytečný, když je uživatel vymaštěný

Re: Počítač zamrzá při startu
odinstaluj nelegalny OFFice a potom spust ComboFix - log vloz
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Počítač zamrzá při startu
Mohu combofix spustit v nouzovém režimu?
Re: Počítač zamrzá při startu
ComboFix 13-03-05.01 - Ervd 07.03.2013 21:08:39.1.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4030.2559 [GMT 1:00]
Spuštěný z: c:\users\Ervd\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
C:\prefs.js
c:\programdata\Premium\MagniPic\run127C.tmp
c:\programdata\Premium\MagniPic\run1E6A.tmp
c:\programdata\Premium\MagniPic\run24CE.tmp
c:\programdata\Premium\MagniPic\run27B2.tmp
c:\programdata\Premium\MagniPic\run27DA.tmp
c:\programdata\Premium\MagniPic\run2E7F.tmp
c:\programdata\Premium\MagniPic\run2F.tmp
c:\programdata\Premium\MagniPic\run3A70.tmp
c:\programdata\Premium\MagniPic\run3C6B.tmp
c:\programdata\Premium\MagniPic\run3D92.tmp
c:\programdata\Premium\MagniPic\run55FB.tmp
c:\programdata\Premium\MagniPic\run56E6.tmp
c:\programdata\Premium\MagniPic\run5CA.tmp
c:\programdata\Premium\MagniPic\run5CC0.tmp
c:\programdata\Premium\MagniPic\run5D8A.tmp
c:\programdata\Premium\MagniPic\run63FF.tmp
c:\programdata\Premium\MagniPic\run667F.tmp
c:\programdata\Premium\MagniPic\run677B.tmp
c:\programdata\Premium\MagniPic\run6B6F.tmp
c:\programdata\Premium\MagniPic\run6D62.tmp
c:\programdata\Premium\MagniPic\run71D5.tmp
c:\programdata\Premium\MagniPic\run7242.tmp
c:\programdata\Premium\MagniPic\run752F.tmp
c:\programdata\Premium\MagniPic\run7797.tmp
c:\programdata\Premium\MagniPic\run7D3C.tmp
c:\programdata\Premium\MagniPic\run82B6.tmp
c:\programdata\Premium\MagniPic\run8507.tmp
c:\programdata\Premium\MagniPic\run87F4.tmp
c:\programdata\Premium\MagniPic\run88ED.tmp
c:\programdata\Premium\MagniPic\run8FA1.tmp
c:\programdata\Premium\MagniPic\run91F2.tmp
c:\programdata\Premium\MagniPic\run9321.tmp
c:\programdata\Premium\MagniPic\run9D1.tmp
c:\programdata\Premium\MagniPic\run9D67.tmp
c:\programdata\Premium\MagniPic\runA2CB.tmp
c:\programdata\Premium\MagniPic\runAAFD.tmp
c:\programdata\Premium\MagniPic\runAE67.tmp
c:\programdata\Premium\MagniPic\runAEB5.tmp
c:\programdata\Premium\MagniPic\runD26B.tmp
c:\programdata\Premium\MagniPic\runD2B9.tmp
c:\programdata\Premium\MagniPic\runD6F2.tmp
c:\programdata\Premium\MagniPic\runD9BF.tmp
c:\programdata\Premium\MagniPic\runDA57.tmp
c:\programdata\Premium\MagniPic\runE862.tmp
c:\programdata\Premium\MagniPic\runE9B2.tmp
c:\programdata\Premium\MagniPic\runEAD1.tmp
c:\programdata\Premium\MagniPic\runEF23.tmp
c:\programdata\Premium\MagniPic\runF20B.tmp
c:\programdata\Premium\MagniPic\runF3C.tmp
c:\programdata\Premium\MagniPic\runF823.tmp
c:\programdata\Premium\MagniPic\runF9B9.tmp
c:\programdata\Premium\MagniPic\runFC0A.tmp
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\logs
c:\windows\SysWow64\logs\Game - R3d Logs\2012-09-23_13-50-59_r3dlog.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-02-07 do 2013-03-07 )))))))))))))))))))))))))))))))
.
.
2013-03-07 20:16 . 2013-03-07 20:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\VDLL.DLL
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\SysWow64\runouce.exe
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\RUNDL132.EXE
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\logo_1.exe
2013-03-07 11:27 . 2013-03-07 11:27 350160 ----a-w- c:\windows\system32\drivers\trufos.sys
2013-03-07 11:27 . 2013-03-07 11:27 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2013-03-07 11:27 . 2013-03-07 11:27 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2013-03-07 11:27 . 2013-03-07 11:27 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2013-03-07 11:27 . 2013-03-07 11:27 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2013-03-07 11:27 . 2013-03-07 11:27 34048 ----a-w- c:\windows\SysWow64\eEmpty.exe
2013-03-07 11:27 . 2013-03-07 11:27 -------- d-----w- c:\program files (x86)\Common Files\MicroWorld
2013-03-07 11:27 . 2013-03-07 11:27 -------- d-----w- c:\programdata\MicroWorld
2013-03-07 11:04 . 2013-03-07 11:04 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2013-03-07 11:04 . 2013-03-07 11:04 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2013-03-07 11:02 . 2013-03-07 11:04 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2013-03-07 11:02 . 2013-03-07 11:02 -------- d-----w- c:\windows\PCHEALTH
2013-03-07 11:02 . 2013-03-07 11:02 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2013-02-27 23:06 . 2013-02-27 23:06 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2013-02-26 11:56 . 2013-02-26 11:56 614400 ----a-w- c:\windows\AutoKMS.exe.mwt
2013-02-26 10:55 . 2013-03-07 08:42 -------- d-----w- C:\office
2013-02-24 12:32 . 2013-02-24 12:32 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-24 12:32 . 2013-02-24 12:32 -------- d-----w- c:\program files (x86)\Java
2013-02-17 14:45 . 2013-02-17 14:45 -------- d-----w- c:\programdata\Prometheus
2013-02-17 14:45 . 2013-02-17 14:45 -------- d-----w- c:\program files (x86)\Prometheus
2013-02-15 22:31 . 2013-02-15 22:31 186432 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-02-14 18:17 . 2013-02-14 18:17 -------- d-----w- c:\programdata\CLSoft LTD
2013-02-14 18:16 . 2013-02-14 18:16 -------- d-----w- c:\programdata\Premium
2013-02-14 18:16 . 2013-02-14 18:16 -------- d-----w- c:\program files (x86)\MagniPic
2013-02-14 18:16 . 2013-02-14 18:18 -------- d-----w- c:\programdata\MagniPic
2013-02-14 18:16 . 2013-02-14 18:17 -------- d-----w- c:\programdata\InstallMate
2013-02-14 18:04 . 2013-02-14 18:04 -------- d-----w- c:\program files (x86)\Conduit
2013-02-14 18:04 . 2013-02-14 18:18 -------- d-----w- c:\users\Ervd\AppData\Local\Conduit
2013-02-14 18:02 . 2013-02-14 18:02 -------- d-----w- c:\users\Ervd\AppData\Roaming\ExpressFiles
2013-02-13 10:38 . 2013-02-13 12:16 -------- d-----w- c:\program files (x86)\Diablo III
2013-02-13 10:38 . 2013-02-13 10:39 -------- d-----w- c:\programdata\Blizzard Entertainment
2013-02-13 10:38 . 2013-02-13 10:39 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2013-02-13 10:37 . 2013-02-13 10:38 -------- d-----w- c:\programdata\Battle.net
2013-02-13 10:27 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 10:27 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 10:10 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-02-13 10:10 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-02-13 10:10 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-02-13 10:10 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-02-13 10:10 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-02-13 10:10 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-02-13 10:10 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-02-13 10:10 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-02-13 10:10 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-02-13 10:10 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-02-13 10:10 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-13 10:10 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-08 11:11 . 2013-02-08 11:11 -------- d-----w- c:\users\Ervd\AppData\Local\ElevatedDiagnostics
2013-02-08 10:08 . 2013-02-08 10:08 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-02-08 10:08 . 2013-02-08 10:08 -------- d-----r- c:\program files (x86)\Skype
2013-02-05 21:56 . 2013-02-06 08:34 -------- d-----w- c:\windows\system32\drivers\NISx64\1309010.00E
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-27 16:11 . 2012-06-09 17:42 71024 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-27 16:11 . 2012-06-09 17:42 691568 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-02-24 12:32 . 2012-08-16 15:44 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-02-24 12:32 . 2012-08-16 15:44 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-02-13 10:34 . 2012-06-09 16:29 70004024 ----a-w- c:\windows\system32\MRT.exe
2013-02-04 16:40 . 2013-02-04 16:40 165232 ---ha-w- c:\users\Ervd\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2013-01-16 19:39 . 2013-01-16 19:39 27760 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2013-01-16 19:39 . 2013-01-16 19:39 14448 ----a-w- c:\windows\system32\drivers\ggflt.sys
2013-01-04 04:43 . 2013-02-13 10:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-12-16 17:11 . 2012-12-22 02:01 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-22 02:01 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-22 02:01 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-22 02:01 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{CC6084C6-42BE-3EBE-22D0-66C55B335E6B}]
2013-02-14 18:44 118272 ----a-w- c:\programdata\MagniPic\511d307d9314a.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 299576]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-13 343168]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"="c:\program files (x86)\HP HD Webcam [Fixed]\monitor.exe" [2010-11-26 11:31 267128]
"trustGTX14"="c:\program files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" [2009-05-11 4832256]
"HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-05-23 103992]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804]
IME File REG_SZ IMSC14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0210804]
IME File REG_SZ IMSCE14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412]
Ime File REG_SZ IMKR14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200411]
Ime File REG_SZ imjp14.ime
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00c0404]
IME File REG_SZ IMTCP14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00d0404]
IME File REG_SZ IMTCC14.IME
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
R3 BrUsbScn;Ovladač skeneru Brother MFC USB;c:\windows\system32\Drivers\BrUsbScn.sys [2009-06-10 14336]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [2010-06-30 52736]
R3 BTMNET;Motorola Bluetooth Network Adapter Service;c:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
R3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [2011-02-08 486144]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
R3 MSC.Licensing_11.9;MSC.Licensing_11.9;c:\msc.software\MSC.Licensing\11.9\lmgrd.exe [2011-03-14 1775440]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-03-29 451192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-01-16 1388120]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-21 283200]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20130306.001\IDSvia64.sys [2013-01-11 513184]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-18 140672]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-10-14 204288]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
S2 brmfrsmg;Brother Resource manager service;c:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
S2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-28 281656]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 30520]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
S2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
S2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1;c:\program files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-01-19 138912]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
S3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
S3 SPUVCbv;SPUVCb Driver Service;c:\windows\system32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-03-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-09 16:11]
.
2013-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 18:35]
.
2013-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 18:35]
.
2013-02-15 c:\windows\Tasks\HPCeeScheduleForERVD-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2013-02-16 c:\windows\Tasks\HPCeeScheduleForErvd.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-09-01 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-09-01 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-09-01 416024]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-27 835072]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
------- Doplňkový sken -------
.
uStart Page = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c
mDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c
mSearch Page = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\€‰.`ž*€‘Ď€VDEST]
@="????F????"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\* ]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-03-07 21:18:23
ComboFix-quarantined-files.txt 2013-03-07 20:18
.
Před spuštěním: Volných bajtů: 284 313 870 336
Po spuštění: Volných bajtů: 284 900 741 120
.
- - End Of File - - 92E20AF0B659DA1B135DC594B853D7CB
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.4030.2559 [GMT 1:00]
Spuštěný z: c:\users\Ervd\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
C:\prefs.js
c:\programdata\Premium\MagniPic\run127C.tmp
c:\programdata\Premium\MagniPic\run1E6A.tmp
c:\programdata\Premium\MagniPic\run24CE.tmp
c:\programdata\Premium\MagniPic\run27B2.tmp
c:\programdata\Premium\MagniPic\run27DA.tmp
c:\programdata\Premium\MagniPic\run2E7F.tmp
c:\programdata\Premium\MagniPic\run2F.tmp
c:\programdata\Premium\MagniPic\run3A70.tmp
c:\programdata\Premium\MagniPic\run3C6B.tmp
c:\programdata\Premium\MagniPic\run3D92.tmp
c:\programdata\Premium\MagniPic\run55FB.tmp
c:\programdata\Premium\MagniPic\run56E6.tmp
c:\programdata\Premium\MagniPic\run5CA.tmp
c:\programdata\Premium\MagniPic\run5CC0.tmp
c:\programdata\Premium\MagniPic\run5D8A.tmp
c:\programdata\Premium\MagniPic\run63FF.tmp
c:\programdata\Premium\MagniPic\run667F.tmp
c:\programdata\Premium\MagniPic\run677B.tmp
c:\programdata\Premium\MagniPic\run6B6F.tmp
c:\programdata\Premium\MagniPic\run6D62.tmp
c:\programdata\Premium\MagniPic\run71D5.tmp
c:\programdata\Premium\MagniPic\run7242.tmp
c:\programdata\Premium\MagniPic\run752F.tmp
c:\programdata\Premium\MagniPic\run7797.tmp
c:\programdata\Premium\MagniPic\run7D3C.tmp
c:\programdata\Premium\MagniPic\run82B6.tmp
c:\programdata\Premium\MagniPic\run8507.tmp
c:\programdata\Premium\MagniPic\run87F4.tmp
c:\programdata\Premium\MagniPic\run88ED.tmp
c:\programdata\Premium\MagniPic\run8FA1.tmp
c:\programdata\Premium\MagniPic\run91F2.tmp
c:\programdata\Premium\MagniPic\run9321.tmp
c:\programdata\Premium\MagniPic\run9D1.tmp
c:\programdata\Premium\MagniPic\run9D67.tmp
c:\programdata\Premium\MagniPic\runA2CB.tmp
c:\programdata\Premium\MagniPic\runAAFD.tmp
c:\programdata\Premium\MagniPic\runAE67.tmp
c:\programdata\Premium\MagniPic\runAEB5.tmp
c:\programdata\Premium\MagniPic\runD26B.tmp
c:\programdata\Premium\MagniPic\runD2B9.tmp
c:\programdata\Premium\MagniPic\runD6F2.tmp
c:\programdata\Premium\MagniPic\runD9BF.tmp
c:\programdata\Premium\MagniPic\runDA57.tmp
c:\programdata\Premium\MagniPic\runE862.tmp
c:\programdata\Premium\MagniPic\runE9B2.tmp
c:\programdata\Premium\MagniPic\runEAD1.tmp
c:\programdata\Premium\MagniPic\runEF23.tmp
c:\programdata\Premium\MagniPic\runF20B.tmp
c:\programdata\Premium\MagniPic\runF3C.tmp
c:\programdata\Premium\MagniPic\runF823.tmp
c:\programdata\Premium\MagniPic\runF9B9.tmp
c:\programdata\Premium\MagniPic\runFC0A.tmp
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\logs
c:\windows\SysWow64\logs\Game - R3d Logs\2012-09-23_13-50-59_r3dlog.txt
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-02-07 do 2013-03-07 )))))))))))))))))))))))))))))))
.
.
2013-03-07 20:16 . 2013-03-07 20:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\VDLL.DLL
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\SysWow64\runouce.exe
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\RUNDL132.EXE
2013-03-07 11:36 . 2013-03-07 11:36 -------- d---a-w- c:\windows\logo_1.exe
2013-03-07 11:27 . 2013-03-07 11:27 350160 ----a-w- c:\windows\system32\drivers\trufos.sys
2013-03-07 11:27 . 2013-03-07 11:27 632064 ----a-w- c:\windows\SysWow64\msvcr80.dll
2013-03-07 11:27 . 2013-03-07 11:27 554240 ----a-w- c:\windows\SysWow64\msvcp80.dll
2013-03-07 11:27 . 2013-03-07 11:27 572928 ----a-w- c:\windows\SysWow64\msvcp90.dll
2013-03-07 11:27 . 2013-03-07 11:27 655872 ----a-w- c:\windows\SysWow64\msvcr90.dll
2013-03-07 11:27 . 2013-03-07 11:27 34048 ----a-w- c:\windows\SysWow64\eEmpty.exe
2013-03-07 11:27 . 2013-03-07 11:27 -------- d-----w- c:\program files (x86)\Common Files\MicroWorld
2013-03-07 11:27 . 2013-03-07 11:27 -------- d-----w- c:\programdata\MicroWorld
2013-03-07 11:04 . 2013-03-07 11:04 -------- d-----w- c:\program files (x86)\Microsoft Synchronization Services
2013-03-07 11:04 . 2013-03-07 11:04 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2013-03-07 11:02 . 2013-03-07 11:04 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 8
2013-03-07 11:02 . 2013-03-07 11:02 -------- d-----w- c:\windows\PCHEALTH
2013-03-07 11:02 . 2013-03-07 11:02 -------- d-----w- c:\program files (x86)\Microsoft Sync Framework
2013-02-27 23:06 . 2013-02-27 23:06 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2013-02-26 11:56 . 2013-02-26 11:56 614400 ----a-w- c:\windows\AutoKMS.exe.mwt
2013-02-26 10:55 . 2013-03-07 08:42 -------- d-----w- C:\office
2013-02-24 12:32 . 2013-02-24 12:32 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-24 12:32 . 2013-02-24 12:32 -------- d-----w- c:\program files (x86)\Java
2013-02-17 14:45 . 2013-02-17 14:45 -------- d-----w- c:\programdata\Prometheus
2013-02-17 14:45 . 2013-02-17 14:45 -------- d-----w- c:\program files (x86)\Prometheus
2013-02-15 22:31 . 2013-02-15 22:31 186432 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\nppdf32.dll
2013-02-14 18:17 . 2013-02-14 18:17 -------- d-----w- c:\programdata\CLSoft LTD
2013-02-14 18:16 . 2013-02-14 18:16 -------- d-----w- c:\programdata\Premium
2013-02-14 18:16 . 2013-02-14 18:16 -------- d-----w- c:\program files (x86)\MagniPic
2013-02-14 18:16 . 2013-02-14 18:18 -------- d-----w- c:\programdata\MagniPic
2013-02-14 18:16 . 2013-02-14 18:17 -------- d-----w- c:\programdata\InstallMate
2013-02-14 18:04 . 2013-02-14 18:04 -------- d-----w- c:\program files (x86)\Conduit
2013-02-14 18:04 . 2013-02-14 18:18 -------- d-----w- c:\users\Ervd\AppData\Local\Conduit
2013-02-14 18:02 . 2013-02-14 18:02 -------- d-----w- c:\users\Ervd\AppData\Roaming\ExpressFiles
2013-02-13 10:38 . 2013-02-13 12:16 -------- d-----w- c:\program files (x86)\Diablo III
2013-02-13 10:38 . 2013-02-13 10:39 -------- d-----w- c:\programdata\Blizzard Entertainment
2013-02-13 10:38 . 2013-02-13 10:39 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2013-02-13 10:37 . 2013-02-13 10:38 -------- d-----w- c:\programdata\Battle.net
2013-02-13 10:27 . 2013-01-09 01:10 996352 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 10:27 . 2013-01-08 22:01 768000 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-13 10:10 . 2013-01-05 05:53 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-02-13 10:10 . 2013-01-05 05:00 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-02-13 10:10 . 2013-01-05 05:00 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-02-13 10:10 . 2013-01-04 03:26 3153408 ----a-w- c:\windows\system32\win32k.sys
2013-02-13 10:10 . 2013-01-04 05:46 215040 ----a-w- c:\windows\system32\winsrv.dll
2013-02-13 10:10 . 2013-01-04 04:51 5120 ----a-w- c:\windows\SysWow64\wow32.dll
2013-02-13 10:10 . 2013-01-04 02:47 25600 ----a-w- c:\windows\SysWow64\setup16.exe
2013-02-13 10:10 . 2013-01-04 02:47 7680 ----a-w- c:\windows\SysWow64\instnm.exe
2013-02-13 10:10 . 2013-01-04 02:47 2048 ----a-w- c:\windows\SysWow64\user.exe
2013-02-13 10:10 . 2013-01-04 02:47 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
2013-02-13 10:10 . 2013-01-03 06:00 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-13 10:10 . 2013-01-03 06:00 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-08 11:11 . 2013-02-08 11:11 -------- d-----w- c:\users\Ervd\AppData\Local\ElevatedDiagnostics
2013-02-08 10:08 . 2013-02-08 10:08 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-02-08 10:08 . 2013-02-08 10:08 -------- d-----r- c:\program files (x86)\Skype
2013-02-05 21:56 . 2013-02-06 08:34 -------- d-----w- c:\windows\system32\drivers\NISx64\1309010.00E
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-27 16:11 . 2012-06-09 17:42 71024 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-27 16:11 . 2012-06-09 17:42 691568 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-02-24 12:32 . 2012-08-16 15:44 861088 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-02-24 12:32 . 2012-08-16 15:44 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-02-13 10:34 . 2012-06-09 16:29 70004024 ----a-w- c:\windows\system32\MRT.exe
2013-02-04 16:40 . 2013-02-04 16:40 165232 ---ha-w- c:\users\Ervd\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2013-01-16 19:39 . 2013-01-16 19:39 27760 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2013-01-16 19:39 . 2013-01-16 19:39 14448 ----a-w- c:\windows\system32\drivers\ggflt.sys
2013-01-04 04:43 . 2013-02-13 10:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-12-16 17:11 . 2012-12-22 02:01 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-12-16 14:45 . 2012-12-22 02:01 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-22 02:01 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-12-16 14:13 . 2012-12-22 02:01 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{CC6084C6-42BE-3EBE-22D0-66C55B335E6B}]
2013-02-14 18:44 118272 ----a-w- c:\programdata\MagniPic\511d307d9314a.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 299576]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-10-13 343168]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"="c:\program files (x86)\HP HD Webcam [Fixed]\monitor.exe" [2010-11-26 11:31 267128]
"trustGTX14"="c:\program files (x86)\Trust\GXT14 Mouse\POINTERGHOST.exe" [2009-05-11 4832256]
"HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-05-23 103992]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804]
IME File REG_SZ IMSC14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0210804]
IME File REG_SZ IMSCE14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412]
Ime File REG_SZ IMKR14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200411]
Ime File REG_SZ imjp14.ime
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00c0404]
IME File REG_SZ IMTCP14.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00d0404]
IME File REG_SZ IMTCC14.IME
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-01-08 161536]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
R3 BrUsbScn;Ovladač skeneru Brother MFC USB;c:\windows\system32\Drivers\BrUsbScn.sys [2009-06-10 14336]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [2010-06-30 52736]
R3 BTMNET;Motorola Bluetooth Network Adapter Service;c:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
R3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [2011-02-08 486144]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
R3 MSC.Licensing_11.9;MSC.Licensing_11.9;c:\msc.software\MSC.Licensing\11.9\lmgrd.exe [2011-03-14 1775440]
R3 nmwcdnsucx64;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1309010.00E\SYMDS64.SYS [2012-03-29 451192]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1309010.00E\SYMEFA64.SYS [2012-05-22 1129120]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\BASHDefs\20130301.001\BHDrvx64.sys [2013-01-16 1388120]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1309010.00E\ccSetx64.sys [2012-06-07 167072]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-21 283200]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.7.1.5\Definitions\IPSDefs\20130306.001\IDSvia64.sys [2013-01-11 513184]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1309010.00E\Ironx64.SYS [2012-04-18 190072]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1309010.00E\SYMNETS.SYS [2012-04-18 405624]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-09-18 140672]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-10-14 204288]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
S2 brmfrsmg;Brother Resource manager service;c:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
S2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-08-10 197536]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-28 281656]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2011-05-13 30520]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
S2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
S2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1;c:\program files (x86)\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe [2012-06-16 138272]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2011-02-01 1127448]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2011-01-21 3154224]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-01-19 138912]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
S3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2011-01-31 174168]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
S3 SPUVCbv;SPUVCb Driver Service;c:\windows\system32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-03-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-09 16:11]
.
2013-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 18:35]
.
2013-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 18:35]
.
2013-02-15 c:\windows\Tasks\HPCeeScheduleForERVD-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2013-02-16 c:\windows\Tasks\HPCeeScheduleForErvd.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 162552 ----a-w- c:\users\Ervd\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-09-01 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-09-01 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-09-01 416024]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-01-27 835072]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
FontCache
.
------- Doplňkový sken -------
.
uStart Page = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c
mDefault_Search_URL = hxxp://www.google.com
mStart Page = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c
mSearch Page = hxxp://www.google.com
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{EE202411-2C26-49E8-9784-1BC1DBF7DE96} - c:\program files (x86)\InstallShield Installation Information\{EE202411-2C26-49E8-9784-1BC1DBF7DE96}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_171.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\€‰.`ž*€‘Ď€VDEST]
@="????F????"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\* ]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\software\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*]
@="?"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-03-07 21:18:23
ComboFix-quarantined-files.txt 2013-03-07 20:18
.
Před spuštěním: Volných bajtů: 284 313 870 336
Po spuštění: Volných bajtů: 284 900 741 120
.
- - End Of File - - 92E20AF0B659DA1B135DC594B853D7CB
Re: Počítač zamrzá při startu
vycisti PC s ADWCleanerom - volba delete
a napis ako sa sprava PC
a napis ako sa sprava PC

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Počítač zamrzá při startu
# AdwCleaner v2.114 - Logfile created 03/08/2013 at 09:20:49
# Updated 05/03/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Ervd - ERVD-HP
# Boot Mode : Normal
# Running from : C:\Users\Ervd\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\END
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\MagniPic
Folder Deleted : C:\ProgramData\clsoft ltd
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\MagniPic
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagniPic
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\Users\Ervd\AppData\Local\Conduit
Folder Deleted : C:\Users\Ervd\AppData\LocalLow\Conduit
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16464
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c --> hxxp://www.google.com
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Ervd\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v12.14.1738.0
File : C:\Users\Ervd\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [2789 octets] - [08/03/2013 09:20:49]
########## EOF - C:\AdwCleaner[S1].txt - [2849 octets] ##########
Počítač se chová zdravě
# Updated 05/03/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Ervd - ERVD-HP
# Boot Mode : Normal
# Running from : C:\Users\Ervd\Desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\END
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\MagniPic
Folder Deleted : C:\ProgramData\clsoft ltd
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\MagniPic
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MagniPic
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\Users\Ervd\AppData\Local\Conduit
Folder Deleted : C:\Users\Ervd\AppData\LocalLow\Conduit
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16464
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c --> hxxp://www.google.com
Replaced : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main - Start Page] = hxxp://searchab.com/?aff=7&uid=a261b29e-76d2-11e2-a46e-e4115b30fe5c --> hxxp://www.google.com
-\\ Google Chrome v [Unable to get version]
File : C:\Users\Ervd\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v12.14.1738.0
File : C:\Users\Ervd\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [2789 octets] - [08/03/2013 09:20:49]
########## EOF - C:\AdwCleaner[S1].txt - [2849 octets] ##########
Počítač se chová zdravě

Re: Počítač zamrzá při startu
citat:
Odinstalujte Combofix
• Prejmenujte ComboFix na Uninstall
• Spustte jej
• Tohle smaze Combofix a jeho slozky
a hotovo
Odinstalujte Combofix
• Prejmenujte ComboFix na Uninstall
• Spustte jej
• Tohle smaze Combofix a jeho slozky
a hotovo

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
Re: Počítač zamrzá při startu
za malo 

FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/