
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o preventivku , chybová hláška pri spustení RSIT
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
-
- Návštěvník
- Příspěvky: 88
- Registrován: 03 pro 2008 15:28
prosím o preventivku , chybová hláška pri spustení RSIT
Zdravím , chcel som sem postnúť log z RSIT, ale pri spustení mi vypíše nasledovnú chybovú hlášku:
Line 1 :
Error: Variable used without being declared.
Mimo tejto chyby mám podozrenie na virus.
Line 1 :
Error: Variable used without being declared.
Mimo tejto chyby mám podozrenie na virus.
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Zdravim
Poprosim o spusteni nasledujiciho
Aplikace ke stažení:
Po stažení FRSTLauncher spustte, objevi se mozna varovani od antiviru, ignorujte a nechte FRSTL spustit
Následně dojde ke stažení FRST a inicializaci

Poprosim o spusteni nasledujiciho



- Po spuštění FRST odsouhlasíme licenční podmínky kliknutím na Ano.
- Dooznačíme položku Addition.txt - viz obrázek.
- Klikneme na tlačítko Scan čímž spustíme skenování.
- Počkáme na dokončení skenování FRST a vytvoření doplňkových informací naší nástavbou.
- Otevře se nám textový soubor FRST.txt, což je požadovaný log a jehož obsah vložíme do svého tématu na fóru.
- Po uzavření logu se FRSTLauncher.exe ukončí a na ploše nám zbyde utilta FRST a dva logy FRST.txt a Addition.txt - nic z toho zatím nemažeme.
-
- Návštěvník
- Příspěvky: 88
- Registrován: 03 pro 2008 15:28
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Tu je ten log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-08-2013 01
Ran by Matúš (administrator) on 13-08-2013 21:31:29
Running from C:\Users\Matúš\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe
(Nalpeiron Ltd.) C:\windows\system32\NLSSRV32.EXE
(Software 2000 Limited) C:\windows\system32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Vimicro) C:\Program Files\USB Camera\VM331_STI.EXE
(Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\windows\System32\IgrsSvcs.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [694816 2010-04-20] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [331BigDog] - C:\Program Files\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro)
HKLM\...\Run: [EnergyUtility] - C:\Program Files\Lenovo\Energy Management\utility.exe [4204448 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files\Lenovo\Energy Management\Energy Management.exe [6285216 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] ()
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [273528 2011-09-23] (RealNetworks, Inc.)
HKLM\...\Run: [avast] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [4858456 2013-05-02] (AVAST Software)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [seznam-listicka-distribuce] - "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKCU\...\Run: [Facebook Update] - C:\Users\Matúš\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-08-04] (Facebook Inc.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - "C:\Users\Matúš\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKCU\...\Run: [cz.seznam.software.szndesktop] - "C:\Users\Matúš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKU\MAMA - požičané\...\Run: [Google Update] - C:\Users\MAMA - požičané\AppData\Local\Google\Update\GoogleUpdate.exe [ 2012-06-21] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKCU - {44A9A374-9227-49BF-98D1-3671E8C72E6B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {52D1C9AE-31FE-49B5-A503-D192195376D0} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {6AF92AD8-9193-492D-9D8A-50E68A39DC7E} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {87D65BB2-F69E-47E8-8143-8811E47F8F0A} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {88C444FB-48C4-4668-8CD0-A831D6CFBB7F} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {B93C4ACC-35A5-489D-B1BA-6E13E467FA17} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {F611790B-9BD4-4781-B488-4DD4494DF28D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {F614C607-E06F-47CE-A20C-AE1F5F7D38A2} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF - C:\Program Files\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin: @real.com/nppl3260;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Matúš\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Matúš\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Matúš\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Matúš\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Matúš\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Matúš\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Matúš\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Matúš\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wikipedia-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\zoznam-sk.xml
FF Extension: Seznam lištička - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: jid1-4P0kohSJxU1qGg - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF HKLM\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF Extension: DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://searchfunmoods.com/?f=1&a=nv1&cd=2XzuyEtN2Y1L1Qzu0FtD0D0E0FtCtByEtD0FtC0FtC0EtCzytN0D0Tzu0CyEtBtAtN1L2XzutBtFtBtFtCtFyDtDtAtN1L1Czu1G2XtC&cr=470772197&ir="
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mat\u00FA\u0161\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll No File
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mat\u00FA\u0161\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mat\u00FA\u0161\AppData\Roaming\Mozilla\plugins\npo1d.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Nitro PDF plugin for Firefox and Chrome) - C:\Program Files\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Unity Player) - C:\Users\Mat\u00FA\u0161\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Plugin: (Facebook Desktop) - C:\Users\Mat\u00FA\u0161\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll No File
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Mat\u00FA\u0161\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
CHR Plugin: (Shockwave for Director) - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
CHR Extension: (Beatlab) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnfdikmbdfgkcbdodjcbmedanjinmkk\1.0.1_0
CHR Extension: (Google Docs) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Tennis) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekkomjfglgnfeeachhdckcbgjhfiahco\2.0_0
CHR Extension: (Baseball) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\njneehkdlobpllhkldmhhephffnniaec\1.0_0
CHR Extension: (Gmail) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\MAT~1\AppData\Local\funmoods_2.0.1.crx
CHR HKLM\...\Chrome\Extension: [bgnnidmnbdkmhfkjgdnngciimpdgohok] - C:\Program Files\LSHunter.TV\stv12.crx
CHR HKLM\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [46808 2013-05-02] (AVAST Software)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [615712 2010-04-20] (Broadcom Corporation.)
R2 EPSON_EB_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [153600 2009-09-14] (SEIKO EPSON CORPORATION)
R2 EPSON_PM_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [121856 2009-09-14] (SEIKO EPSON CORPORATION)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®)
S3 IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited)
R2 NitroDriverReadSpool8; C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe [196616 2013-04-30] (Nitro PDF Software)
S3 PS_MDP; C:\Program Files\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
R2 ReadyComm.DirectRouter; C:\Program Files\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [21256 2009-09-03] (Lenovo Corporation)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5281792 2010-01-14] (ATI Technologies Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-02] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [66336 2013-05-02] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [61680 2013-05-02] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-02] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-05-02] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368944 2013-05-02] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-02] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [174664 2013-05-02] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2011-03-06] ()
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [63240 2009-07-28] (Lenovo)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [218688 2011-04-28] (DT Soft Ltd)
R0 LHDmgr; C:\Windows\System32\DRIVERS\LhdX86.sys [32352 2010-01-15] (Lenovo.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-03-06] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [50704 2009-10-20] (CACE Technologies, Inc.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [185344 2010-01-27] (Vimicro Corporation)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\Windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
U3 BcmSqlStartupSvc;
S3 catchme; \??\C:\Users\MAT~1\AppData\Local\Temp\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\MAT~1\AppData\Local\Temp\CFcatchme.sys [x]
U2 IAStorDataMgrSvc;
U2 IviRegMgr;
U2 RichVideo;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-13 21:30 - 2013-08-13 21:30 - 00000000 ____D C:\Users\MAT~1\AppData\Local\qb439972.42
2013-08-13 21:30 - 2013-08-13 15:36 - 01068613 _____ (Farbar) C:\Users\Matúš\Desktop\FRST.exe
2013-08-13 20:30 - 2013-08-13 20:31 - 00781909 _____ C:\Users\Matúš\Downloads\RSIT.exe
2013-08-11 14:30 - 2013-08-11 14:30 - 00068540 _____ C:\Users\Matúš\Downloads\Suits-S03E04(0000222043).srt
2013-08-11 12:17 - 2013-08-11 12:17 - 00066338 _____ C:\Users\Matúš\Downloads\Suits-S03E03(0000221667).srt
2013-08-11 11:18 - 2013-08-11 11:28 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E03 HDTV x264-EVOLVE[ettv]
2013-08-11 10:52 - 2013-08-11 11:14 - 279653501 _____ C:\Users\Matúš\Downloads\Suits.S03E04.HDTV.x264-ASAP.mp4
2013-08-10 18:27 - 2013-08-10 18:41 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E02 HDTV x264-EVOLVE[ettv]
2013-08-10 18:00 - 2013-08-10 18:00 - 00015477 _____ C:\ComboFix.txt
2013-08-10 17:34 - 2013-08-13 20:17 - 00001796 _____ C:\windows\PFRO.log
2013-08-10 17:34 - 2013-08-13 20:17 - 00000112 _____ C:\windows\setupact.log
2013-08-10 17:34 - 2013-08-10 17:34 - 283040130 _____ C:\windows\MEMORY.DMP
2013-08-10 17:34 - 2013-08-10 17:34 - 00149760 _____ C:\windows\Minidump\081013-23930-01.dmp
2013-08-10 17:34 - 2013-08-10 17:34 - 00000000 _____ C:\windows\setuperr.log
2013-08-10 17:25 - 2013-08-10 17:27 - 05102523 _____ (Swearware) C:\Users\Matúš\Downloads\ComboFix.exe
2013-08-10 17:16 - 2013-08-10 17:16 - 00002197 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 17:13 - 2013-08-13 21:18 - 00000922 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-10 17:13 - 2013-08-13 20:17 - 00000918 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-10 17:12 - 2013-08-10 17:13 - 00784880 _____ (Google Inc.) C:\Users\Matúš\Downloads\ChromeSetup.exe
2013-08-10 16:57 - 2013-08-10 17:27 - 314385560 _____ C:\Users\Matúš\Downloads\Suits.S03E01.HDTV.x264-EVOLVE.mp4
2013-08-10 08:43 - 2013-08-10 08:44 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Win7codecs
2013-08-10 08:43 - 2013-08-10 08:43 - 00000000 ____D C:\Program Files\Win7codecs
2013-08-10 08:40 - 2013-08-10 08:44 - 00000000 ____D C:\ProgramData\Win7codecs
2013-08-10 08:34 - 2013-08-10 08:35 - 27958458 _____ C:\Users\Matúš\Downloads\Win7codecs_v412.exe
2013-08-10 08:16 - 2013-08-10 08:16 - 00001151 _____ C:\Users\Public\Desktop\GOM Player.lnk
2013-08-10 08:11 - 2013-08-10 08:14 - 11158200 _____ (Gretech Corporation) C:\Users\Matúš\Downloads\GOMPLAYERENSETUP.EXE
2013-08-09 17:53 - 2013-08-09 17:57 - 00000000 ____D C:\windows\system32\MRT
2013-08-09 16:27 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-09 16:27 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-09 16:27 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-09 16:27 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-09 16:10 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2013-08-09 16:10 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2013-08-09 16:09 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-09 16:09 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-09 16:09 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-09 16:09 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2013-08-09 16:09 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2013-08-09 16:08 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-09 16:08 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2013-08-09 16:07 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-08-09 16:07 - 2013-05-08 07:38 - 01293672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-09 16:07 - 2013-05-06 07:06 - 03968872 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-08-09 16:07 - 2013-05-06 07:06 - 03913576 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-09 16:07 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2013-08-09 16:07 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2013-08-09 16:06 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2013-07-31 10:02 - 2013-07-31 10:02 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna august september oktober
2013-07-29 21:05 - 2013-07-29 21:07 - 216361230 _____ C:\Users\Matúš\Desktop\dievca dna.rar
2013-07-29 20:08 - 2013-07-29 20:08 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna
2013-07-29 19:57 - 2013-07-29 20:07 - 169711090 _____ C:\Users\Matúš\Downloads\dievca dna.rar
2013-07-26 05:32 - 2013-07-26 06:36 - 576733184 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin) (1).avi
2013-07-25 22:10 - 2013-07-26 05:30 - 527668208 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin).avi
2013-07-21 22:12 - 2013-05-17 13:36 - 00000000 ____D C:\Users\Matúš\Desktop\Injustice_god_among
2013-07-21 20:57 - 2013-07-21 21:26 - 208245192 _____ C:\Users\Matúš\Downloads\Injustice_god_among.zip
2013-07-21 10:22 - 2013-04-13 02:06 - 00000000 ____D C:\Users\Matúš\Desktop\BLES01673
2013-07-21 09:54 - 2013-07-22 21:36 - 00000000 ____D C:\Users\Matúš\Desktop\sumvision
2013-07-18 19:27 - 2013-07-18 19:27 - 00060588 _____ C:\Users\Matúš\Downloads\00150.zip
2013-07-14 12:04 - 2013-07-14 12:04 - 00104771 _____ C:\Users\Matúš\Desktop\jafoto.xps
2013-07-14 10:00 - 2013-07-14 12:00 - 00000000 ____D C:\Users\Matúš\Desktop\11930713
==================== One Month Modified Files and Folders =======
2013-08-13 21:31 - 2013-08-13 21:31 - 00000000 ____D C:\FRST
2013-08-13 21:30 - 2013-08-13 21:30 - 00000000 ____D C:\Users\MAT~1\AppData\Local\qb439972.42
2013-08-13 21:18 - 2013-08-10 17:13 - 00000922 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-13 20:43 - 2011-04-12 20:36 - 00000000 ____D C:\Program Files\trend micro
2013-08-13 20:32 - 2011-03-09 20:22 - 15227467 _____ C:\FaceProv.log
2013-08-13 20:31 - 2013-08-13 20:30 - 00781909 _____ C:\Users\Matúš\Downloads\RSIT.exe
2013-08-13 20:29 - 2012-03-11 23:27 - 00000000 ____D C:\windows\ERDNT
2013-08-13 20:27 - 2010-10-25 22:45 - 01480488 _____ C:\windows\WindowsUpdate.log
2013-08-13 20:27 - 2009-07-14 06:34 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-13 20:27 - 2009-07-14 06:34 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-13 20:17 - 2013-08-10 17:34 - 00001796 _____ C:\windows\PFRO.log
2013-08-13 20:17 - 2013-08-10 17:34 - 00000112 _____ C:\windows\setupact.log
2013-08-13 20:17 - 2013-08-10 17:13 - 00000918 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-13 20:17 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-13 15:36 - 2013-08-13 21:30 - 01068613 _____ (Farbar) C:\Users\Matúš\Desktop\FRST.exe
2013-08-11 16:47 - 2011-02-13 17:00 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\uTorrent
2013-08-11 14:30 - 2013-08-11 14:30 - 00068540 _____ C:\Users\Matúš\Downloads\Suits-S03E04(0000222043).srt
2013-08-11 12:17 - 2013-08-11 12:17 - 00066338 _____ C:\Users\Matúš\Downloads\Suits-S03E03(0000221667).srt
2013-08-11 11:28 - 2013-08-11 11:18 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E03 HDTV x264-EVOLVE[ettv]
2013-08-11 11:14 - 2013-08-11 10:52 - 279653501 _____ C:\Users\Matúš\Downloads\Suits.S03E04.HDTV.x264-ASAP.mp4
2013-08-11 10:25 - 2010-10-25 22:55 - 00730448 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-10 22:24 - 2011-05-24 23:02 - 00000000 ____D C:\Program Files\Google
2013-08-10 18:41 - 2013-08-10 18:27 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E02 HDTV x264-EVOLVE[ettv]
2013-08-10 18:00 - 2013-08-10 18:00 - 00015477 _____ C:\ComboFix.txt
2013-08-10 17:56 - 2009-07-14 04:04 - 00000231 _____ C:\windows\system.ini
2013-08-10 17:34 - 2013-08-10 17:34 - 283040130 _____ C:\windows\MEMORY.DMP
2013-08-10 17:34 - 2013-08-10 17:34 - 00149760 _____ C:\windows\Minidump\081013-23930-01.dmp
2013-08-10 17:34 - 2013-08-10 17:34 - 00000000 _____ C:\windows\setuperr.log
2013-08-10 17:34 - 2011-06-10 05:23 - 00000000 ____D C:\windows\Minidump
2013-08-10 17:27 - 2013-08-10 17:25 - 05102523 _____ (Swearware) C:\Users\Matúš\Downloads\ComboFix.exe
2013-08-10 17:27 - 2013-08-10 16:57 - 314385560 _____ C:\Users\Matúš\Downloads\Suits.S03E01.HDTV.x264-EVOLVE.mp4
2013-08-10 17:16 - 2013-08-10 17:16 - 00002197 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 17:13 - 2013-08-10 17:12 - 00784880 _____ (Google Inc.) C:\Users\Matúš\Downloads\ChromeSetup.exe
2013-08-10 13:42 - 2011-02-17 09:18 - 00000000 ____D C:\Users\MAT~1\AppData\Local\Adobe
2013-08-10 13:41 - 2012-10-11 18:48 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-08-10 13:41 - 2011-11-25 08:02 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-10 13:03 - 2009-07-14 04:37 - 00000000 ____D C:\windows\rescache
2013-08-10 08:44 - 2013-08-10 08:43 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Win7codecs
2013-08-10 08:44 - 2013-08-10 08:40 - 00000000 ____D C:\ProgramData\Win7codecs
2013-08-10 08:43 - 2013-08-10 08:43 - 00000000 ____D C:\Program Files\Win7codecs
2013-08-10 08:42 - 2011-02-12 19:46 - 00000000 ____D C:\Users\Matúš
2013-08-10 08:35 - 2013-08-10 08:34 - 27958458 _____ C:\Users\Matúš\Downloads\Win7codecs_v412.exe
2013-08-10 08:16 - 2013-08-10 08:16 - 00001151 _____ C:\Users\Public\Desktop\GOM Player.lnk
2013-08-10 08:16 - 2011-02-13 17:12 - 00001175 _____ C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2013-08-10 08:14 - 2013-08-10 08:11 - 11158200 _____ (Gretech Corporation) C:\Users\Matúš\Downloads\GOMPLAYERENSETUP.EXE
2013-08-09 18:53 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-08-09 17:57 - 2013-08-09 17:53 - 00000000 ____D C:\windows\system32\MRT
2013-08-09 16:41 - 2009-07-14 06:33 - 00411064 _____ C:\windows\system32\FNTCACHE.DAT
2013-08-09 16:38 - 2009-07-29 12:50 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-09 16:38 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-09 16:38 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\sk-SK
2013-08-09 16:26 - 2011-02-18 17:50 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-09 15:43 - 2012-03-11 12:31 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Mozilla
2013-08-07 15:03 - 2011-06-07 11:17 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\vlc
2013-07-31 10:02 - 2013-07-31 10:02 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna august september oktober
2013-07-29 21:07 - 2013-07-29 21:05 - 216361230 _____ C:\Users\Matúš\Desktop\dievca dna.rar
2013-07-29 20:08 - 2013-07-29 20:08 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna
2013-07-29 20:07 - 2013-07-29 19:57 - 169711090 _____ C:\Users\Matúš\Downloads\dievca dna.rar
2013-07-26 19:55 - 2011-02-12 19:46 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-26 06:36 - 2013-07-26 05:32 - 576733184 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin) (1).avi
2013-07-26 05:30 - 2013-07-25 22:10 - 527668208 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin).avi
2013-07-22 21:36 - 2013-07-21 09:54 - 00000000 ____D C:\Users\Matúš\Desktop\sumvision
2013-07-21 21:26 - 2013-07-21 20:57 - 208245192 _____ C:\Users\Matúš\Downloads\Injustice_god_among.zip
2013-07-21 15:40 - 2011-05-04 23:41 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\FileZilla
2013-07-19 08:17 - 2011-02-12 19:48 - 00000000 ____D C:\Users\Matúš\Documents\Bluetooth Exchange Folder
2013-07-18 19:27 - 2013-07-18 19:27 - 00060588 _____ C:\Users\Matúš\Downloads\00150.zip
2013-07-14 12:04 - 2013-07-14 12:04 - 00104771 _____ C:\Users\Matúš\Desktop\jafoto.xps
2013-07-14 12:00 - 2013-07-14 10:00 - 00000000 ____D C:\Users\Matúš\Desktop\11930713
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-10 12:58
==================== Scheduled Tasks (whitelisted) ===========
Task: {2C48961A-552A-4A85-873A-57906D239506} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: {37F9D418-E7B3-470E-828F-2DB62523ED50} - System32\Tasks\{AADB26D5-9386-4DBC-A6FF-9210202660D6} => c:\users\matúš\appdata\local\google\chrome\application\chrome.exe No File
Task: {51C13E08-0BA4-4C18-AA08-A3EC4149FDAE} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {63F6CCBE-2E85-43AA-80EF-4B23411CCCEF} - System32\Tasks\{6AE4A0EE-84E5-436E-BCAC-D28827AC9631} => C:\Program Files\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.)
Task: {66020611-EAB4-4390-95DE-8989411225D2} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-89691612-3455193979-517274971-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {693BEAC3-FEC9-4366-9D92-6C4C4ED77614} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-89691612-3455193979-517274971-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {82553E2F-8A0A-4E7B-88D0-9A1803C3A218} - System32\Tasks\Funmoods => C:\Users\MAT~1\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE No File
Task: {A1CB714B-B52C-4B76-ADFC-458D38A628D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-10] (Google Inc.)
Task: {B3183442-4637-4D05-89E6-BFFCBADF0C60} - System32\Tasks\User_Feed_Synchronization-{38646286-8E28-4E66-A31C-43744E7C130A} => C:\windows\system32\msfeedssync.exe [2013-04-26] (Microsoft Corporation)
Task: {CE20B373-A776-4111-A769-8A2E4747DA7B} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2013-05-02] (AVAST Software)
Task: {CF98FE28-EE9E-48BB-9257-0A7E15224A60} - System32\Tasks\RealCreateProcessScheduledTask83435356S-1-5-21-89691612-3455193979-517274971-1000 => c:\program files\real\realplayer\update\realsched.exe [2011-09-23] (RealNetworks, Inc.)
Task: {E45C4696-D78E-460F-8DA7-00E21E92BFFB} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-89691612-3455193979-517274971-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {EC90FDDA-FD9C-49A0-906F-B90658F8CCFB} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-89691612-3455193979-517274971-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {F3506F84-02A5-411E-9A05-89B60F9ABD24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-10] (Google Inc.)
Task: {FB6EC054-B7CC-498B-9CC7-D6655FE5512A} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Supplementary Scan (All) ================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray
"C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files\Steam\Steam.exe" -silent ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu
"C:\Program Files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager
C:\Program Files\Lenovo\VeriFace\PManage.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirror Tray icon
"C:\Program Files\Lenovo\YouCam\YouCamTray.exe" /s ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mat��^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mat��^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000000
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000000
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"FirewallDisableNotify"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Users\\Mat��\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe"="C:\\Users\\Mat��\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe:*:Enabled:cacaoweb"
"C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"="C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe:*:Enabled:Flashget3"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"VIDC.YVU9"="tsbyuv.dll"
"msacm.l3acm"="C:\\Windows\\System32\\l3codeca.acm"
"vidc.cvid"="iccvid.dll"
"MSVideo8"="VfWWDM32.dll"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"aux"="wdmaud.drv"
"wave2"="wdmaud.drv"
"midi2"="wdmaud.drv"
"mixer2"="wdmaud.drv"
"msacm.divxa32"="msaud32_divx.acm"
"wave3"="wdmaud.drv"
"midi3"="wdmaud.drv"
"mixer3"="wdmaud.drv"
"wave4"="wdmaud.drv"
"midi4"="wdmaud.drv"
"mixer4"="wdmaud.drv"
"wave5"="wdmaud.drv"
"midi5"="wdmaud.drv"
"mixer5"="wdmaud.drv"
"wave6"="wdmaud.drv"
"midi6"="wdmaud.drv"
"mixer6"="wdmaud.drv"
"wave7"="wdmaud.drv"
"midi7"="wdmaud.drv"
"mixer7"="wdmaud.drv"
"VIDC.CSCD"="camcodec.dll"
"msacm.l3pacm"="l3codecp.acm"
"msacm.aacacm"="AACACM.acm"
"msacm.lameacm"="lameACM.acm"
"msacm.ac3acm"="ac3acm.acm"
"VIDC.LAGS"="lagarith.dll"
"VIDC.FFDS"="ff_vfw.dll"
"VIDC.X264"="x264vfw.dll"
"msacm.ac3filter"="ac3filter.acm"
"VIDC.MLCY"="mlc.dll"
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:188.94 GB) (Free:67.43 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:6.15 GB) NTFS
Available physical RAM: 771.77 MB
Total physical RAM: 1790.17 MB
Percentage of memory in use: 56%
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-08-2013 01
Ran by Matúš (administrator) on 13-08-2013 21:31:29
Running from C:\Users\Matúš\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\windows\system32\atiesrxx.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe
(Nalpeiron Ltd.) C:\windows\system32\NLSSRV32.EXE
(Software 2000 Limited) C:\windows\system32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Vimicro) C:\Program Files\USB Camera\VM331_STI.EXE
(Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Microsoft Corporation) C:\windows\System32\IgrsSvcs.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8555040 2010-04-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [694816 2010-04-20] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1594664 2009-12-10] (Synaptics Incorporated)
HKLM\...\Run: [331BigDog] - C:\Program Files\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro)
HKLM\...\Run: [EnergyUtility] - C:\Program Files\Lenovo\Energy Management\utility.exe [4204448 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files\Lenovo\Energy Management\Energy Management.exe [6285216 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] ()
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [273528 2011-09-23] (RealNetworks, Inc.)
HKLM\...\Run: [avast] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [4858456 2013-05-02] (AVAST Software)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [seznam-listicka-distribuce] - "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKCU\...\Run: [Facebook Update] - C:\Users\Matúš\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-08-04] (Facebook Inc.)
HKCU\...\Run: [cz.seznam.software.autoupdate] - "C:\Users\Matúš\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKCU\...\Run: [cz.seznam.software.szndesktop] - "C:\Users\Matúš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKU\MAMA - požičané\...\Run: [Google Update] - C:\Users\MAMA - požičané\AppData\Local\Google\Update\GoogleUpdate.exe [ 2012-06-21] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKCU - {44A9A374-9227-49BF-98D1-3671E8C72E6B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {52D1C9AE-31FE-49B5-A503-D192195376D0} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {6AF92AD8-9193-492D-9D8A-50E68A39DC7E} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {87D65BB2-F69E-47E8-8143-8811E47F8F0A} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {88C444FB-48C4-4668-8CD0-A831D6CFBB7F} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {B93C4ACC-35A5-489D-B1BA-6E13E467FA17} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {F611790B-9BD4-4781-B488-4DD4494DF28D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {F614C607-E06F-47CE-A20C-AE1F5F7D38A2} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: DivX HiQ - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Pomocník pri prihlasovaní v sieti Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU -No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nitropdf.com/NitroPDF - C:\Program Files\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin: @real.com/nppl3260;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.666 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=12.0.1.666 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Matúš\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Matúš\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Matúš\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Matúš\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Matúš\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Matúš\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Matúš\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Matúš\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\wikipedia-sk.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\zoznam-sk.xml
FF Extension: Seznam lištička - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: jid1-4P0kohSJxU1qGg - C:\Users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default\Extensions\jid1-4P0kohSJxU1qGg@jetpack.xpi
FF Extension: Default - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video
FF HKLM\...\Firefox\Extensions: [{6904342A-8307-11DF-A508-4AE2DFD72085}] C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF Extension: DivX HiQ - C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://searchfunmoods.com/?f=1&a=nv1&cd=2XzuyEtN2Y1L1Qzu0FtD0D0E0FtCtByEtD0FtC0FtC0EtCzytN0D0Tzu0CyEtBtAtN1L2XzutBtFtBtFtCtFyDtDtAtN1L1Czu1G2XtC&cr=470772197&ir="
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.240.7) - C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U24) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Talk Plugin) - C:\Users\Mat\u00FA\u0161\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll No File
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Mat\u00FA\u0161\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Mat\u00FA\u0161\AppData\Roaming\Mozilla\plugins\npo1d.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Nitro PDF plugin for Firefox and Chrome) - C:\Program Files\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Unity Player) - C:\Users\Mat\u00FA\u0161\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Plugin: (Facebook Desktop) - C:\Users\Mat\u00FA\u0161\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll No File
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Mat\u00FA\u0161\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File
CHR Plugin: (Shockwave for Director) - C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
CHR Extension: (Beatlab) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnfdikmbdfgkcbdodjcbmedanjinmkk\1.0.1_0
CHR Extension: (Google Docs) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Tennis) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekkomjfglgnfeeachhdckcbgjhfiahco\2.0_0
CHR Extension: (Baseball) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\njneehkdlobpllhkldmhhephffnniaec\1.0_0
CHR Extension: (Gmail) - C:\Users\MAT~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\MAT~1\AppData\Local\funmoods_2.0.1.crx
CHR HKLM\...\Chrome\Extension: [bgnnidmnbdkmhfkjgdnngciimpdgohok] - C:\Program Files\LSHunter.TV\stv12.crx
CHR HKLM\...\Chrome\Extension: [fnjbmmemklcjgepojigaapkoodmkgbae] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\wpa\wpa.crx
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [46808 2013-05-02] (AVAST Software)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [615712 2010-04-20] (Broadcom Corporation.)
R2 EPSON_EB_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [153600 2009-09-14] (SEIKO EPSON CORPORATION)
R2 EPSON_PM_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [121856 2009-09-14] (SEIKO EPSON CORPORATION)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1253376 2009-08-27] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [3276800 2008-08-07] (MAGIX®)
S3 IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited)
R2 NitroDriverReadSpool8; C:\Program Files\Nitro\Pro 8\NitroPDFDriverService8.exe [196616 2013-04-30] (Nitro PDF Software)
S3 PS_MDP; C:\Program Files\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
R2 ReadyComm.DirectRouter; C:\Program Files\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited)
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [21256 2009-09-03] (Lenovo Corporation)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5281792 2010-01-14] (ATI Technologies Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-02] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [66336 2013-05-02] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [61680 2013-05-02] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-02] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-05-02] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368944 2013-05-02] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-02] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [174664 2013-05-02] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2011-03-06] ()
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [63240 2009-07-28] (Lenovo)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [218688 2011-04-28] (DT Soft Ltd)
R0 LHDmgr; C:\Windows\System32\DRIVERS\LhdX86.sys [32352 2010-01-15] (Lenovo.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-03-06] ()
R2 NPF; C:\Windows\System32\drivers\npf.sys [50704 2009-10-20] (CACE Technologies, Inc.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [185344 2010-01-27] (Vimicro Corporation)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\Windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
U3 BcmSqlStartupSvc;
S3 catchme; \??\C:\Users\MAT~1\AppData\Local\Temp\catchme.sys [x]
S3 CFcatchme; \??\C:\Users\MAT~1\AppData\Local\Temp\CFcatchme.sys [x]
U2 IAStorDataMgrSvc;
U2 IviRegMgr;
U2 RichVideo;
U3 SQLWriter;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-13 21:30 - 2013-08-13 21:30 - 00000000 ____D C:\Users\MAT~1\AppData\Local\qb439972.42
2013-08-13 21:30 - 2013-08-13 15:36 - 01068613 _____ (Farbar) C:\Users\Matúš\Desktop\FRST.exe
2013-08-13 20:30 - 2013-08-13 20:31 - 00781909 _____ C:\Users\Matúš\Downloads\RSIT.exe
2013-08-11 14:30 - 2013-08-11 14:30 - 00068540 _____ C:\Users\Matúš\Downloads\Suits-S03E04(0000222043).srt
2013-08-11 12:17 - 2013-08-11 12:17 - 00066338 _____ C:\Users\Matúš\Downloads\Suits-S03E03(0000221667).srt
2013-08-11 11:18 - 2013-08-11 11:28 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E03 HDTV x264-EVOLVE[ettv]
2013-08-11 10:52 - 2013-08-11 11:14 - 279653501 _____ C:\Users\Matúš\Downloads\Suits.S03E04.HDTV.x264-ASAP.mp4
2013-08-10 18:27 - 2013-08-10 18:41 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E02 HDTV x264-EVOLVE[ettv]
2013-08-10 18:00 - 2013-08-10 18:00 - 00015477 _____ C:\ComboFix.txt
2013-08-10 17:34 - 2013-08-13 20:17 - 00001796 _____ C:\windows\PFRO.log
2013-08-10 17:34 - 2013-08-13 20:17 - 00000112 _____ C:\windows\setupact.log
2013-08-10 17:34 - 2013-08-10 17:34 - 283040130 _____ C:\windows\MEMORY.DMP
2013-08-10 17:34 - 2013-08-10 17:34 - 00149760 _____ C:\windows\Minidump\081013-23930-01.dmp
2013-08-10 17:34 - 2013-08-10 17:34 - 00000000 _____ C:\windows\setuperr.log
2013-08-10 17:25 - 2013-08-10 17:27 - 05102523 _____ (Swearware) C:\Users\Matúš\Downloads\ComboFix.exe
2013-08-10 17:16 - 2013-08-10 17:16 - 00002197 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 17:13 - 2013-08-13 21:18 - 00000922 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-10 17:13 - 2013-08-13 20:17 - 00000918 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-10 17:12 - 2013-08-10 17:13 - 00784880 _____ (Google Inc.) C:\Users\Matúš\Downloads\ChromeSetup.exe
2013-08-10 16:57 - 2013-08-10 17:27 - 314385560 _____ C:\Users\Matúš\Downloads\Suits.S03E01.HDTV.x264-EVOLVE.mp4
2013-08-10 08:43 - 2013-08-10 08:44 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Win7codecs
2013-08-10 08:43 - 2013-08-10 08:43 - 00000000 ____D C:\Program Files\Win7codecs
2013-08-10 08:40 - 2013-08-10 08:44 - 00000000 ____D C:\ProgramData\Win7codecs
2013-08-10 08:34 - 2013-08-10 08:35 - 27958458 _____ C:\Users\Matúš\Downloads\Win7codecs_v412.exe
2013-08-10 08:16 - 2013-08-10 08:16 - 00001151 _____ C:\Users\Public\Desktop\GOM Player.lnk
2013-08-10 08:11 - 2013-08-10 08:14 - 11158200 _____ (Gretech Corporation) C:\Users\Matúš\Downloads\GOMPLAYERENSETUP.EXE
2013-08-09 17:53 - 2013-08-09 17:57 - 00000000 ____D C:\windows\system32\MRT
2013-08-09 16:27 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-09 16:27 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-08-09 16:27 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-08-09 16:27 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-08-09 16:27 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-08-09 16:27 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-09 16:10 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\cryptdlg.dll
2013-08-09 16:10 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2013-08-09 16:09 - 2013-05-13 06:45 - 01160192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-09 16:09 - 2013-05-13 06:45 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-09 16:09 - 2013-05-13 06:45 - 00103936 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-09 16:09 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\windows\system32\certutil.exe
2013-08-09 16:09 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\certenc.dll
2013-08-09 16:08 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-09 16:08 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2013-08-09 16:07 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-08-09 16:07 - 2013-05-08 07:38 - 01293672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-09 16:07 - 2013-05-06 07:06 - 03968872 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2013-08-09 16:07 - 2013-05-06 07:06 - 03913576 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-09 16:07 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2013-08-09 16:07 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2013-08-09 16:06 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2013-07-31 10:02 - 2013-07-31 10:02 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna august september oktober
2013-07-29 21:05 - 2013-07-29 21:07 - 216361230 _____ C:\Users\Matúš\Desktop\dievca dna.rar
2013-07-29 20:08 - 2013-07-29 20:08 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna
2013-07-29 19:57 - 2013-07-29 20:07 - 169711090 _____ C:\Users\Matúš\Downloads\dievca dna.rar
2013-07-26 05:32 - 2013-07-26 06:36 - 576733184 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin) (1).avi
2013-07-25 22:10 - 2013-07-26 05:30 - 527668208 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin).avi
2013-07-21 22:12 - 2013-05-17 13:36 - 00000000 ____D C:\Users\Matúš\Desktop\Injustice_god_among
2013-07-21 20:57 - 2013-07-21 21:26 - 208245192 _____ C:\Users\Matúš\Downloads\Injustice_god_among.zip
2013-07-21 10:22 - 2013-04-13 02:06 - 00000000 ____D C:\Users\Matúš\Desktop\BLES01673
2013-07-21 09:54 - 2013-07-22 21:36 - 00000000 ____D C:\Users\Matúš\Desktop\sumvision
2013-07-18 19:27 - 2013-07-18 19:27 - 00060588 _____ C:\Users\Matúš\Downloads\00150.zip
2013-07-14 12:04 - 2013-07-14 12:04 - 00104771 _____ C:\Users\Matúš\Desktop\jafoto.xps
2013-07-14 10:00 - 2013-07-14 12:00 - 00000000 ____D C:\Users\Matúš\Desktop\11930713
==================== One Month Modified Files and Folders =======
2013-08-13 21:31 - 2013-08-13 21:31 - 00000000 ____D C:\FRST
2013-08-13 21:30 - 2013-08-13 21:30 - 00000000 ____D C:\Users\MAT~1\AppData\Local\qb439972.42
2013-08-13 21:18 - 2013-08-10 17:13 - 00000922 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-13 20:43 - 2011-04-12 20:36 - 00000000 ____D C:\Program Files\trend micro
2013-08-13 20:32 - 2011-03-09 20:22 - 15227467 _____ C:\FaceProv.log
2013-08-13 20:31 - 2013-08-13 20:30 - 00781909 _____ C:\Users\Matúš\Downloads\RSIT.exe
2013-08-13 20:29 - 2012-03-11 23:27 - 00000000 ____D C:\windows\ERDNT
2013-08-13 20:27 - 2010-10-25 22:45 - 01480488 _____ C:\windows\WindowsUpdate.log
2013-08-13 20:27 - 2009-07-14 06:34 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-13 20:27 - 2009-07-14 06:34 - 00018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-13 20:17 - 2013-08-10 17:34 - 00001796 _____ C:\windows\PFRO.log
2013-08-13 20:17 - 2013-08-10 17:34 - 00000112 _____ C:\windows\setupact.log
2013-08-13 20:17 - 2013-08-10 17:13 - 00000918 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-13 20:17 - 2009-07-14 06:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-13 15:36 - 2013-08-13 21:30 - 01068613 _____ (Farbar) C:\Users\Matúš\Desktop\FRST.exe
2013-08-11 16:47 - 2011-02-13 17:00 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\uTorrent
2013-08-11 14:30 - 2013-08-11 14:30 - 00068540 _____ C:\Users\Matúš\Downloads\Suits-S03E04(0000222043).srt
2013-08-11 12:17 - 2013-08-11 12:17 - 00066338 _____ C:\Users\Matúš\Downloads\Suits-S03E03(0000221667).srt
2013-08-11 11:28 - 2013-08-11 11:18 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E03 HDTV x264-EVOLVE[ettv]
2013-08-11 11:14 - 2013-08-11 10:52 - 279653501 _____ C:\Users\Matúš\Downloads\Suits.S03E04.HDTV.x264-ASAP.mp4
2013-08-11 10:25 - 2010-10-25 22:55 - 00730448 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-10 22:24 - 2011-05-24 23:02 - 00000000 ____D C:\Program Files\Google
2013-08-10 18:41 - 2013-08-10 18:27 - 00000000 ____D C:\Users\Matúš\Downloads\Suits S03E02 HDTV x264-EVOLVE[ettv]
2013-08-10 18:00 - 2013-08-10 18:00 - 00015477 _____ C:\ComboFix.txt
2013-08-10 17:56 - 2009-07-14 04:04 - 00000231 _____ C:\windows\system.ini
2013-08-10 17:34 - 2013-08-10 17:34 - 283040130 _____ C:\windows\MEMORY.DMP
2013-08-10 17:34 - 2013-08-10 17:34 - 00149760 _____ C:\windows\Minidump\081013-23930-01.dmp
2013-08-10 17:34 - 2013-08-10 17:34 - 00000000 _____ C:\windows\setuperr.log
2013-08-10 17:34 - 2011-06-10 05:23 - 00000000 ____D C:\windows\Minidump
2013-08-10 17:27 - 2013-08-10 17:25 - 05102523 _____ (Swearware) C:\Users\Matúš\Downloads\ComboFix.exe
2013-08-10 17:27 - 2013-08-10 16:57 - 314385560 _____ C:\Users\Matúš\Downloads\Suits.S03E01.HDTV.x264-EVOLVE.mp4
2013-08-10 17:16 - 2013-08-10 17:16 - 00002197 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-08-10 17:13 - 2013-08-10 17:12 - 00784880 _____ (Google Inc.) C:\Users\Matúš\Downloads\ChromeSetup.exe
2013-08-10 13:42 - 2011-02-17 09:18 - 00000000 ____D C:\Users\MAT~1\AppData\Local\Adobe
2013-08-10 13:41 - 2012-10-11 18:48 - 00692104 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2013-08-10 13:41 - 2011-11-25 08:02 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-10 13:03 - 2009-07-14 04:37 - 00000000 ____D C:\windows\rescache
2013-08-10 08:44 - 2013-08-10 08:43 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Win7codecs
2013-08-10 08:44 - 2013-08-10 08:40 - 00000000 ____D C:\ProgramData\Win7codecs
2013-08-10 08:43 - 2013-08-10 08:43 - 00000000 ____D C:\Program Files\Win7codecs
2013-08-10 08:42 - 2011-02-12 19:46 - 00000000 ____D C:\Users\Matúš
2013-08-10 08:35 - 2013-08-10 08:34 - 27958458 _____ C:\Users\Matúš\Downloads\Win7codecs_v412.exe
2013-08-10 08:16 - 2013-08-10 08:16 - 00001151 _____ C:\Users\Public\Desktop\GOM Player.lnk
2013-08-10 08:16 - 2011-02-13 17:12 - 00001175 _____ C:\Users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2013-08-10 08:14 - 2013-08-10 08:11 - 11158200 _____ (Gretech Corporation) C:\Users\Matúš\Downloads\GOMPLAYERENSETUP.EXE
2013-08-09 18:53 - 2009-07-14 04:37 - 00000000 ____D C:\windows\Microsoft.NET
2013-08-09 17:57 - 2013-08-09 17:53 - 00000000 ____D C:\windows\system32\MRT
2013-08-09 16:41 - 2009-07-14 06:33 - 00411064 _____ C:\windows\system32\FNTCACHE.DAT
2013-08-09 16:38 - 2009-07-29 12:50 - 00000000 ____D C:\Program Files\Windows Journal
2013-08-09 16:38 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-08-09 16:38 - 2009-07-14 04:37 - 00000000 ____D C:\windows\system32\sk-SK
2013-08-09 16:26 - 2011-02-18 17:50 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-08-09 15:43 - 2012-03-11 12:31 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\Mozilla
2013-08-07 15:03 - 2011-06-07 11:17 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\vlc
2013-07-31 10:02 - 2013-07-31 10:02 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna august september oktober
2013-07-29 21:07 - 2013-07-29 21:05 - 216361230 _____ C:\Users\Matúš\Desktop\dievca dna.rar
2013-07-29 20:08 - 2013-07-29 20:08 - 00000000 ____D C:\Users\Matúš\Desktop\dievca dna
2013-07-29 20:07 - 2013-07-29 19:57 - 169711090 _____ C:\Users\Matúš\Downloads\dievca dna.rar
2013-07-26 19:55 - 2011-02-12 19:46 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-26 06:36 - 2013-07-26 05:32 - 576733184 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin) (1).avi
2013-07-26 05:30 - 2013-07-25 22:10 - 527668208 _____ C:\Users\Matúš\Downloads\(cyril-a-metodej---apostolove-slovanu)-01-bratri-ze-solune---13'-DVBT_CZ-(romin).avi
2013-07-22 21:36 - 2013-07-21 09:54 - 00000000 ____D C:\Users\Matúš\Desktop\sumvision
2013-07-21 21:26 - 2013-07-21 20:57 - 208245192 _____ C:\Users\Matúš\Downloads\Injustice_god_among.zip
2013-07-21 15:40 - 2011-05-04 23:41 - 00000000 ____D C:\Users\Matúš\AppData\Roaming\FileZilla
2013-07-19 08:17 - 2011-02-12 19:48 - 00000000 ____D C:\Users\Matúš\Documents\Bluetooth Exchange Folder
2013-07-18 19:27 - 2013-07-18 19:27 - 00060588 _____ C:\Users\Matúš\Downloads\00150.zip
2013-07-14 12:04 - 2013-07-14 12:04 - 00104771 _____ C:\Users\Matúš\Desktop\jafoto.xps
2013-07-14 12:00 - 2013-07-14 10:00 - 00000000 ____D C:\Users\Matúš\Desktop\11930713
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-10 12:58
==================== Scheduled Tasks (whitelisted) ===========
Task: {2C48961A-552A-4A85-873A-57906D239506} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: {37F9D418-E7B3-470E-828F-2DB62523ED50} - System32\Tasks\{AADB26D5-9386-4DBC-A6FF-9210202660D6} => c:\users\matúš\appdata\local\google\chrome\application\chrome.exe No File
Task: {51C13E08-0BA4-4C18-AA08-A3EC4149FDAE} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {63F6CCBE-2E85-43AA-80EF-4B23411CCCEF} - System32\Tasks\{6AE4A0EE-84E5-436E-BCAC-D28827AC9631} => C:\Program Files\Skype\\Phone\Skype.exe [2012-07-13] (Skype Technologies S.A.)
Task: {66020611-EAB4-4390-95DE-8989411225D2} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-89691612-3455193979-517274971-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {693BEAC3-FEC9-4366-9D92-6C4C4ED77614} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-89691612-3455193979-517274971-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {82553E2F-8A0A-4E7B-88D0-9A1803C3A218} - System32\Tasks\Funmoods => C:\Users\MAT~1\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE No File
Task: {A1CB714B-B52C-4B76-ADFC-458D38A628D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-10] (Google Inc.)
Task: {B3183442-4637-4D05-89E6-BFFCBADF0C60} - System32\Tasks\User_Feed_Synchronization-{38646286-8E28-4E66-A31C-43744E7C130A} => C:\windows\system32\msfeedssync.exe [2013-04-26] (Microsoft Corporation)
Task: {CE20B373-A776-4111-A769-8A2E4747DA7B} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2013-05-02] (AVAST Software)
Task: {CF98FE28-EE9E-48BB-9257-0A7E15224A60} - System32\Tasks\RealCreateProcessScheduledTask83435356S-1-5-21-89691612-3455193979-517274971-1000 => c:\program files\real\realplayer\update\realsched.exe [2011-09-23] (RealNetworks, Inc.)
Task: {E45C4696-D78E-460F-8DA7-00E21E92BFFB} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-89691612-3455193979-517274971-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {EC90FDDA-FD9C-49A0-906F-B90658F8CCFB} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-89691612-3455193979-517274971-1003 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2011-08-11] (RealNetworks, Inc.)
Task: {F3506F84-02A5-411E-9A05-89B60F9ABD24} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-10] (Google Inc.)
Task: {FB6EC054-B7CC-498B-9CC7-D6655FE5512A} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Supplementary Scan (All) ================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray
"C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files\Steam\Steam.exe" -silent ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu
"C:\Program Files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager
C:\Program Files\Lenovo\VeriFace\PManage.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirror Tray icon
"C:\Program Files\Lenovo\YouCam\YouCamTray.exe" /s ... soubor neexistuje.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mat��^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Mat��^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000000
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000000
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"FirewallDisableNotify"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Users\\Mat��\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe"="C:\\Users\\Mat��\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe:*:Enabled:cacaoweb"
"C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"="C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe:*:Enabled:Flashget3"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"VIDC.YVU9"="tsbyuv.dll"
"msacm.l3acm"="C:\\Windows\\System32\\l3codeca.acm"
"vidc.cvid"="iccvid.dll"
"MSVideo8"="VfWWDM32.dll"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"aux"="wdmaud.drv"
"wave2"="wdmaud.drv"
"midi2"="wdmaud.drv"
"mixer2"="wdmaud.drv"
"msacm.divxa32"="msaud32_divx.acm"
"wave3"="wdmaud.drv"
"midi3"="wdmaud.drv"
"mixer3"="wdmaud.drv"
"wave4"="wdmaud.drv"
"midi4"="wdmaud.drv"
"mixer4"="wdmaud.drv"
"wave5"="wdmaud.drv"
"midi5"="wdmaud.drv"
"mixer5"="wdmaud.drv"
"wave6"="wdmaud.drv"
"midi6"="wdmaud.drv"
"mixer6"="wdmaud.drv"
"wave7"="wdmaud.drv"
"midi7"="wdmaud.drv"
"mixer7"="wdmaud.drv"
"VIDC.CSCD"="camcodec.dll"
"msacm.l3pacm"="l3codecp.acm"
"msacm.aacacm"="AACACM.acm"
"msacm.lameacm"="lameACM.acm"
"msacm.ac3acm"="ac3acm.acm"
"VIDC.LAGS"="lagarith.dll"
"VIDC.FFDS"="ff_vfw.dll"
"VIDC.X264"="x264vfw.dll"
"msacm.ac3filter"="ac3filter.acm"
"VIDC.MLCY"="mlc.dll"
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:188.94 GB) (Free:67.43 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:6.15 GB) NTFS
Available physical RAM: 771.77 MB
Total physical RAM: 1790.17 MB
Percentage of memory in use: 56%
==================== End Of Log ==============================
Re: prosím o preventivku , chybová hláška pri spustení RSIT




- Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
- Maze stopy po haveti, takze v logu z RSIT neni nic videt
- Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
- CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
- CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
-
- Návštěvník
- Příspěvky: 88
- Registrován: 03 pro 2008 15:28
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Co sa ComboFixu tyka, pravidelne navstevujem toto forum a viem, ze ho smiem pouzivat iba pod dozorom odbornika. No na moje nestastie som zveril netbook do ruk pseudoodbornikovy, ktory tvrdil, ze sa v tom vyzna, no vobec mi nepomohol. Bol to priamy kontakt s nim nebolo to cez toto ani ine internetove forum.
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Dejte mi sem tedy jeho log, mel by byt c:\combofix.txt
-
- Návštěvník
- Příspěvky: 88
- Registrován: 03 pro 2008 15:28
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Tu je ten log, ospravedlňujem sa za prípadné nepríjemnosti.
ComboFix 13-08-09.02 - Matúš . 08. 2013 17:40:01.3.1 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.1790.1008 [GMT 2:00]
Running from: c:\users\Matúš\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
ADS - windows: deleted 192 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Funmoods
c:\program files\Funmoods\1.8.11.0\Sqlite3.dll
c:\program files\Funmoods\1.8.11.0\uninst.dat
c:\program files\Funmoods\1.8.11.0\uninstall.exe
c:\windows\TEMP\sig78E6.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-07-10 to 2013-08-10 )))))))))))))))))))))))))))))))
.
.
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Mat˙Ü\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\MAMA - požičané\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-10 10:51 . 2013-08-10 15:47 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FD5F3EFC-C381-4270-A41A-D7DF2EA57380}\offreg.dll
2013-08-10 10:47 . 2013-07-02 06:54 7143960 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FD5F3EFC-C381-4270-A41A-D7DF2EA57380}\mpengine.dll
2013-08-10 06:43 . 2013-08-10 06:44 -------- d-----w- c:\users\Matúš\AppData\Roaming\Win7codecs
2013-08-10 06:43 . 2013-08-10 06:43 -------- d-----w- c:\program files\Win7codecs
2013-08-10 06:42 . 2013-08-10 06:42 -------- d-----w- c:\users\Matúš\Local Settings
2013-08-10 06:42 . 2013-08-10 06:42 -------- d-----w- c:\program files\Seznam.cz
2013-08-10 06:41 . 2013-08-10 06:42 -------- d-----w- c:\users\Matúš\AppData\Roaming\Seznam.cz
2013-08-10 06:40 . 2013-08-10 06:44 -------- d-----w- c:\programdata\Win7codecs
2013-08-09 15:53 . 2013-08-09 15:57 -------- d-----w- c:\windows\system32\MRT
2013-08-09 14:10 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-09 14:10 . 2013-05-10 03:20 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-08-09 14:09 . 2013-05-13 03:08 903168 ----a-w- c:\windows\system32\certutil.exe
2013-08-09 14:09 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\system32\crypt32.dll
2013-08-09 14:09 . 2013-05-13 04:45 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-09 14:09 . 2013-05-13 04:45 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-09 14:09 . 2013-05-13 03:08 43008 ----a-w- c:\windows\system32\certenc.dll
2013-08-09 14:08 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-08-09 14:08 . 2013-05-06 04:56 1620480 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-09 14:07 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\system32\DWrite.dll
2013-08-09 14:07 . 2013-04-10 05:03 936448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-09 14:07 . 2013-04-10 05:03 988672 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2013-08-09 14:07 . 2013-04-10 05:03 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2013-08-09 14:07 . 2013-04-10 05:04 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2013-08-09 14:07 . 2013-05-06 05:06 3968872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-09 14:07 . 2013-05-06 05:06 3913576 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-09 14:07 . 2013-05-08 05:38 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-09 14:07 . 2013-06-05 03:05 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-08-09 14:07 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-08-09 14:06 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-08-09 14:06 . 2013-05-27 04:57 680960 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-09 14:06 . 2013-05-27 04:57 392704 ----a-w- c:\program files\Windows Defender\MpClient.dll
2013-08-09 14:06 . 2013-05-27 04:57 224768 ----a-w- c:\program files\Windows Defender\MpCommu.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-10 11:41 . 2012-10-11 16:48 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-10 11:41 . 2011-11-25 06:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-15 05:47 . 2013-03-15 05:47 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-01 23:33 121968 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2010-10-25 21:41 1410400 ----a-w- c:\windows\System32\IcnOvrly.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Facebook Update"="c:\users\Matúš\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-08-04 138096]
"cz.seznam.software.autoupdate"="c:\users\Matúš\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\Matúš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-20 8555040]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2010-04-20 694816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-12-10 1594664]
"331BigDog"="c:\program files\USB Camera\VM331_STI.EXE" [2010-01-15 536576]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2010-04-12 4204448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 6285216]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-09-23 273528]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2013-05-01 4858456]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2010-4-20 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer7"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Matúš^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Matúš^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-12-21 09:53 1483264 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2010-04-12 08:40 180224 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-08-08 20:17 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2009-05-19 22:16 222504 ------w- c:\program files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
2010-10-25 21:41 3122528 ----a-w- c:\program files\Lenovo\VeriFace\PManage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirror Tray icon]
2010-03-02 22:37 171104 ------w- c:\program files\Lenovo\YouCam\YouCamTray.exe
.
R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 116648]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-08 45736]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 CFcatchme;CFcatchme;c:\users\MAT~1\AppData\Local\Temp\CFcatchme.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 116648]
R3 IGRS;IGRS;c:\program files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-15 38152]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-11-17 575304]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-11-11 181792]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-13 1343400]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-28 218688]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-01-14 172032]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-01 66336]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [2009-09-14 153600]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2009-09-14 121856]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8;c:\program files\Nitro\Pro 8\NitroPDFDriverService8.exe [2013-04-30 196616]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NLSSRV32.EXE [2013-04-30 70152]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2009-09-03 21256]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-02-22 66600]
S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [2010-01-27 185344]
S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc
IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-10 15:16 1173456 ----a-w- c:\program files\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 15:13]
.
2013-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 15:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.seznam.cz/?clid=13415
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-funmoods - c:\program files\Funmoods\1.8.11.0\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-08-10 18:00:26
ComboFix-quarantined-files.txt 2013-08-10 16:00
ComboFix2.txt 2012-03-12 07:17
ComboFix3.txt 2012-03-11 21:48
.
Pre-Run: 65 779 441 664 bytes free
Post-Run: 66 110 029 824 bytes free
.
- - End Of File - - 5B436ACEC4D5842440BE0DC8F68AD057
5C616939100B85E558DA92B899A0FC36
ComboFix 13-08-09.02 - Matúš . 08. 2013 17:40:01.3.1 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.421.1051.18.1790.1008 [GMT 2:00]
Running from: c:\users\Matúš\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
ADS - windows: deleted 192 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Funmoods
c:\program files\Funmoods\1.8.11.0\Sqlite3.dll
c:\program files\Funmoods\1.8.11.0\uninst.dat
c:\program files\Funmoods\1.8.11.0\uninstall.exe
c:\windows\TEMP\sig78E6.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-07-10 to 2013-08-10 )))))))))))))))))))))))))))))))
.
.
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Mat˙Ü\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\MAMA - požičané\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Guest\AppData\Local\temp
2013-08-10 15:53 . 2013-08-10 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-08-10 10:51 . 2013-08-10 15:47 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FD5F3EFC-C381-4270-A41A-D7DF2EA57380}\offreg.dll
2013-08-10 10:47 . 2013-07-02 06:54 7143960 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FD5F3EFC-C381-4270-A41A-D7DF2EA57380}\mpengine.dll
2013-08-10 06:43 . 2013-08-10 06:44 -------- d-----w- c:\users\Matúš\AppData\Roaming\Win7codecs
2013-08-10 06:43 . 2013-08-10 06:43 -------- d-----w- c:\program files\Win7codecs
2013-08-10 06:42 . 2013-08-10 06:42 -------- d-----w- c:\users\Matúš\Local Settings
2013-08-10 06:42 . 2013-08-10 06:42 -------- d-----w- c:\program files\Seznam.cz
2013-08-10 06:41 . 2013-08-10 06:42 -------- d-----w- c:\users\Matúš\AppData\Roaming\Seznam.cz
2013-08-10 06:40 . 2013-08-10 06:44 -------- d-----w- c:\programdata\Win7codecs
2013-08-09 15:53 . 2013-08-09 15:57 -------- d-----w- c:\windows\system32\MRT
2013-08-09 14:10 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-09 14:10 . 2013-05-10 03:20 24576 ----a-w- c:\windows\system32\cryptdlg.dll
2013-08-09 14:09 . 2013-05-13 03:08 903168 ----a-w- c:\windows\system32\certutil.exe
2013-08-09 14:09 . 2013-05-13 04:45 1160192 ----a-w- c:\windows\system32\crypt32.dll
2013-08-09 14:09 . 2013-05-13 04:45 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-08-09 14:09 . 2013-05-13 04:45 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-08-09 14:09 . 2013-05-13 03:08 43008 ----a-w- c:\windows\system32\certenc.dll
2013-08-09 14:08 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\system32\d3d11.dll
2013-08-09 14:08 . 2013-05-06 04:56 1620480 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-09 14:07 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\system32\DWrite.dll
2013-08-09 14:07 . 2013-04-10 05:03 936448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-08-09 14:07 . 2013-04-10 05:03 988672 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2013-08-09 14:07 . 2013-04-10 05:03 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2013-08-09 14:07 . 2013-04-10 05:04 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2013-08-09 14:07 . 2013-05-06 05:06 3968872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-09 14:07 . 2013-05-06 05:06 3913576 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-08-09 14:07 . 2013-05-08 05:38 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-09 14:07 . 2013-06-05 03:05 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-08-09 14:07 . 2013-04-26 04:55 492544 ----a-w- c:\windows\system32\win32spl.dll
2013-08-09 14:06 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll
2013-08-09 14:06 . 2013-05-27 04:57 680960 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-08-09 14:06 . 2013-05-27 04:57 392704 ----a-w- c:\program files\Windows Defender\MpClient.dll
2013-08-09 14:06 . 2013-05-27 04:57 224768 ----a-w- c:\program files\Windows Defender\MpCommu.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-10 11:41 . 2012-10-11 16:48 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-08-10 11:41 . 2011-11-25 06:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-15 05:47 . 2013-03-15 05:47 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-01 23:33 121968 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2010-10-25 21:41 1410400 ----a-w- c:\windows\System32\IcnOvrly.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Facebook Update"="c:\users\Matúš\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-08-04 138096]
"cz.seznam.software.autoupdate"="c:\users\Matúš\AppData\Roaming\Seznam.cz\szninstall.exe" [2013-05-16 1062472]
"cz.seznam.software.szndesktop"="c:\users\Matúš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" [2013-04-12 92664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-20 8555040]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2010-04-20 694816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-12-10 1594664]
"331BigDog"="c:\program files\USB Camera\VM331_STI.EXE" [2010-01-15 536576]
"EnergyUtility"="c:\program files\Lenovo\Energy Management\utility.exe" [2010-04-12 4204448]
"Energy Management"="c:\program files\Lenovo\Energy Management\Energy Management.exe" [2010-03-18 6285216]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-09-23 273528]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2013-05-01 4858456]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"seznam-listicka-distribuce"="c:\program files\Seznam.cz\distribution\szninstall.exe" [2013-05-16 1062472]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2010-4-20 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer7"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Matúš^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Matúš^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Matúš\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2010-12-21 09:53 1483264 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2010-04-12 08:40 180224 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-08-08 20:17 1242448 ----a-w- c:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2009-05-19 22:16 222504 ------w- c:\program files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
2010-10-25 21:41 3122528 ----a-w- c:\program files\Lenovo\VeriFace\PManage.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YouCam Mirror Tray icon]
2010-03-02 22:37 171104 ------w- c:\program files\Lenovo\YouCam\YouCamTray.exe
.
R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 116648]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-07-13 160944]
R3 Bridge0;Bridge0;c:\windows\system32\drivers\WDBridge.sys [2009-07-28 63240]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-04-08 45736]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 CFcatchme;CFcatchme;c:\users\MAT~1\AppData\Local\Temp\CFcatchme.sys [x]
R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2008-08-07 3276800]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 116648]
R3 IGRS;IGRS;c:\program files\Lenovo\ReadyComm\common\IGRS.exe [2009-07-15 38152]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
R3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc;c:\program files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
R3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc;c:\program files\Lenovo\ReadyComm\ConnSvc.exe [2009-11-17 575304]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 PS_MDP;ReadyComm Presentation Space Helper Service;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-11-11 181792]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Služba Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-13 1343400]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX86.sys [2010-01-15 32352]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-04-28 218688]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-01-14 172032]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-01 66336]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [2009-09-14 153600]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [2009-09-14 121856]
S2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [2009-08-27 1253376]
S2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8;c:\program files\Nitro\Pro 8\NitroPDFDriverService8.exe [2013-04-30 196616]
S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NLSSRV32.EXE [2013-04-30 70152]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter;c:\windows\System32\IgrsSvcs.exe [2009-07-14 20992]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2009-09-03 21256]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-02-22 66600]
S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys [2010-01-27 185344]
S3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc
IgrsSvcs REG_MULTI_SZ ReadyComm.DirectRouter PS_MDP
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-08-10 15:16 1173456 ----a-w- c:\program files\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 15:13]
.
2013-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-08-10 15:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.seznam.cz/?clid=13415
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Matúš\AppData\Roaming\Mozilla\Firefox\Profiles\mjvhso8w.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-funmoods - c:\program files\Funmoods\1.8.11.0\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-08-10 18:00:26
ComboFix-quarantined-files.txt 2013-08-10 16:00
ComboFix2.txt 2012-03-12 07:17
ComboFix3.txt 2012-03-11 21:48
.
Pre-Run: 65 779 441 664 bytes free
Post-Run: 66 110 029 824 bytes free
.
- - End Of File - - 5B436ACEC4D5842440BE0DC8F68AD057
5C616939100B85E558DA92B899A0FC36
Re: prosím o preventivku , chybová hláška pri spustení RSIT

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1230704 2011-03-21] () HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [273528 2011-09-23] (RealNetworks, Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [seznam-listicka-distribuce] - "C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x] HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd) HKCU\...\Run: [Facebook Update] - C:\Users\Matúš\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-08-04] (Facebook Inc.) HKCU\...\Run: [cz.seznam.software.autoupdate] - "C:\Users\Matúš\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x] HKCU\...\Run: [cz.seznam.software.szndesktop] - "C:\Users\Matúš\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x] HKU\MAMA - požičané\...\Run: [Google Update] - C:\Users\MAMA - požičané\AppData\Local\Google\Update\GoogleUpdate.exe [ 2012-06-21] (Google Inc.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox SearchScopes: HKCU - {44A9A374-9227-49BF-98D1-3671E8C72E6B} URL = http://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_13415 SearchScopes: HKCU - {52D1C9AE-31FE-49B5-A503-D192195376D0} URL = http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415 SearchScopes: HKCU - {6AF92AD8-9193-492D-9D8A-50E68A39DC7E} URL = http://www.novinky.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415 SearchScopes: HKCU - {87D65BB2-F69E-47E8-8143-8811E47F8F0A} URL = http://www.firmy.cz/?q={searchTerms}&sourceid=QuickSearch_13415 SearchScopes: HKCU - {88C444FB-48C4-4668-8CD0-A831D6CFBB7F} URL = http://www.mapy.cz/?query={searchTerms}&sourceid=QuickSearch_13415 SearchScopes: HKCU - {A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} URL = http://search.yahoo.com/search?fr=chr-g ... =937811&p={searchTerms} SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms} SearchScopes: HKCU - {B93C4ACC-35A5-489D-B1BA-6E13E467FA17} URL = http://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_13415 SearchScopes: HKCU - {D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} URL = http://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_13415 SearchScopes: HKCU - {F611790B-9BD4-4781-B488-4DD4494DF28D} URL = http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=QuickSearch_13415 SearchScopes: HKCU - {F614C607-E06F-47CE-A20C-AE1F5F7D38A2} URL = http://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_13415 Toolbar: HKCU -No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU -No Name - {32099AAC-C132-4136-9E9A-4E364A424E17} - No File CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\MAT~1\AppData\Local\funmoods_2.0.1.crx U3 BcmSqlStartupSvc; S3 catchme; \??\C:\Users\MAT~1\AppData\Local\Temp\catchme.sys [x] S3 CFcatchme; \??\C:\Users\MAT~1\AppData\Local\Temp\CFcatchme.sys [x] U2 IAStorDataMgrSvc; U2 IviRegMgr; U2 RichVideo; U3 SQLWriter; REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray" /f REG: reg delete "KEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE" /f REG: reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list /v "C:\\Users\\Matúš\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe" /f C:\Users\Matúš\AppData\\Roaming\cacaoweb Unlock: "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}" Hosts: CMD: shutdown /r /f /t 2 End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

-
- Návštěvník
- Příspěvky: 88
- Registrován: 03 pro 2008 15:28
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Počítač je po reštarte, tu je log :
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-08-2013 01
Ran by Matúš at 2013-08-13 21:59:31 Run:1
Running from C:\Users\Matúš\Desktop
Boot Mode: Normal
==============================================
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value deleted successfully.
HKU\MAMA - požičané\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{44A9A374-9227-49BF-98D1-3671E8C72E6B} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{44A9A374-9227-49BF-98D1-3671E8C72E6B} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52D1C9AE-31FE-49B5-A503-D192195376D0} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{52D1C9AE-31FE-49B5-A503-D192195376D0} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6AF92AD8-9193-492D-9D8A-50E68A39DC7E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6AF92AD8-9193-492D-9D8A-50E68A39DC7E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{87D65BB2-F69E-47E8-8143-8811E47F8F0A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{87D65BB2-F69E-47E8-8143-8811E47F8F0A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{88C444FB-48C4-4668-8CD0-A831D6CFBB7F} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{88C444FB-48C4-4668-8CD0-A831D6CFBB7F} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B93C4ACC-35A5-489D-B1BA-6E13E467FA17} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{B93C4ACC-35A5-489D-B1BA-6E13E467FA17} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F611790B-9BD4-4781-B488-4DD4494DF28D} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{F611790B-9BD4-4781-B488-4DD4494DF28D} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F614C607-E06F-47CE-A20C-AE1F5F7D38A2} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{F614C607-E06F-47CE-A20C-AE1F5F7D38A2} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully.
HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh => Key deleted successfully.
C:\Users\MAT~1\AppData\Local\funmoods_2.0.1.crx => Moved successfully.
U3 BcmSqlStartupSvc; => Service not found.
catchme => Service deleted successfully.
CFcatchme => Service deleted successfully.
U2 IAStorDataMgrSvc; => Service not found.
U2 IviRegMgr; => Service not found.
U2 RichVideo; => Service not found.
SQLWriter => Service deleted successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "KEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f =========
ERROR: Invalid key name.
Type "REG DELETE /?" for usage.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list /v "C:\\Users\\Matúš\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe" /f =========
========= End of Reg: =========
C:\Users\Matúš\AppData\\Roaming\cacaoweb => Moved successfully.
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}" => Key unlocked successfilly.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-08-2013 01
Ran by Matúš at 2013-08-13 21:59:31 Run:1
Running from C:\Users\Matúš\Desktop
Boot Mode: Normal
==============================================
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value deleted successfully.
HKU\MAMA - požičané\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{44A9A374-9227-49BF-98D1-3671E8C72E6B} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{44A9A374-9227-49BF-98D1-3671E8C72E6B} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{52D1C9AE-31FE-49B5-A503-D192195376D0} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{52D1C9AE-31FE-49B5-A503-D192195376D0} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6AF92AD8-9193-492D-9D8A-50E68A39DC7E} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{6AF92AD8-9193-492D-9D8A-50E68A39DC7E} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{87D65BB2-F69E-47E8-8143-8811E47F8F0A} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{87D65BB2-F69E-47E8-8143-8811E47F8F0A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{88C444FB-48C4-4668-8CD0-A831D6CFBB7F} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{88C444FB-48C4-4668-8CD0-A831D6CFBB7F} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A3CDFA19-33D8-4EBA-9B54-48BBBF4639BF} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B93C4ACC-35A5-489D-B1BA-6E13E467FA17} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{B93C4ACC-35A5-489D-B1BA-6E13E467FA17} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D8D01F9E-BF64-41F8-9A19-B74D33A9DF0D} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F611790B-9BD4-4781-B488-4DD4494DF28D} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{F611790B-9BD4-4781-B488-4DD4494DF28D} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F614C607-E06F-47CE-A20C-AE1F5F7D38A2} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{F614C607-E06F-47CE-A20C-AE1F5F7D38A2} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Value deleted successfully.
HKCR\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} => Value deleted successfully.
HKCR\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} => Key not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh => Key deleted successfully.
C:\Users\MAT~1\AppData\Local\funmoods_2.0.1.crx => Moved successfully.
U3 BcmSqlStartupSvc; => Service not found.
catchme => Service deleted successfully.
CFcatchme => Service deleted successfully.
U2 IAStorDataMgrSvc; => Service not found.
U2 IviRegMgr; => Service not found.
U2 RichVideo; => Service not found.
SQLWriter => Service deleted successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "KEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f =========
ERROR: Invalid key name.
Type "REG DELETE /?" for usage.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE" /f =========
Oper cia sa Łspeçne dokonźila.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list /v "C:\\Users\\Matúš\\AppData\\Roaming\\cacaoweb\\cacaoweb.exe" /f =========
========= End of Reg: =========
C:\Users\Matúš\AppData\\Roaming\cacaoweb => Moved successfully.
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}" => Key unlocked successfilly.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Tak jeste uklidime
Odinstalujte Combofix
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 


- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy


-
- Návštěvník
- Příspěvky: 88
- Registrován: 03 pro 2008 15:28
Re: prosím o preventivku , chybová hláška pri spustení RSIT
Ďakujem, odteraz dôverujem výhradne iba tomuto fóru.
Vďaka!
Vďaka!