weby ukazovali error 302
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
weby ukazovali error 302
Čavte. Dnes som vo Firefoxe prehliadal web a známe stránky nefungovali správne. Google pri vyhľadávaní vyhodil error 302 a bolo tam napísané niečo v zmysle ,, pre pokračovanie klikni sem,, . To isté mi spravil sportsdirect.com, keď som sa pokúsil o prihlásenie. Robili to aj iné stránky. Mal som podozrenie , že ma vírus niekde vždy presmeruje. Pozrel som súbor C:\Windows\System32\drivers\etc\hosts a boli tam dva záznamy pod For example:, ktoré som zmazal a bohužiaľ som si ich nezapísal. Po reštartovaní firefoxu sa mi už error 302 neukázal. Vložil som sem log z rsit, prosím o kontrolu.
# For example:
#
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
RSIT log:
Logfile of random's system information tool 1.09 (written by
random/random)
Run by Vojto at 2013-08-17 21:16:51
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 12 GB (28%) free of 41 GB
Total RAM: 3959 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:16:54, on 17. 8. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Vojto.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:
\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast
\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar
\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows
\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar
\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows
\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AutorunsDisabled
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel -
res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:
\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-
8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office
\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-
7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office
\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-
6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office
\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote -
{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files
(x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter: AutorunsDisabled - (no CLSID) - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe
Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM
\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service
(AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows
\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner
- C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files
\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown
owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown
owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) -
FileZilla Project - C:\Program Files (x86)\FileZilla Server\FileZilla
Server.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. -
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher
\FNPLicensingService64.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin
\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) -
Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service
\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows
\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) -
Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner -
C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA
Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update
Core\daemonu.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:
\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage)
- Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental)
(rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap
\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) -
Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown
owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) -
Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown
owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown
owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) -
Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) -
Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner
- C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown
owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) -
Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv)
- Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 6942 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows
SharedSection=1024,20480,768 Windows=On SubSystemType=Windows
ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4
ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows
SharedSection=1024,20480,768 Windows=On SubSystemType=Windows
ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4
ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 13703456
\??\C:\Windows\system32\conhost.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\OO Software\Defrag\oodag.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Common Files\Microsoft Shared
\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\notepad.exe"
"taskhost.exe"
"C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe"
"C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"D:\downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles
\dgu9mslu.default
prefs.js - "browser.search.useDBForOrder" - true
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=D:\programfiles\Foxit Reader\foxitreader\plugins
\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@java.com/DTPlugin,version=10.13.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@java.com/JavaPlugin,version=10.13.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5]
"Description"=A component of your photo software powered by RocketLife
"Path"=C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins
\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\Browser Helper Objects\AutorunsDisabled]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows
\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-02-24 2598280]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2010-06
-21 3838792]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management
\utility.exe [2009-12-17 4367808]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management
\Energy Management.exe [2009-12-17 6988736]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows
\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09
4858968]
C:\Users\Vojto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
\Startup
AutorunsDisabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network
\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies
\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
\explorer]
"NoPreviewPane"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies
\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess
\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess
\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 month======
2013-08-17 21:16:51 ----D---- C:\rsit
2013-08-17 21:12:26 ----D---- C:\Program Files\trend micro
2013-08-17 15:42:17 ----D---- C:\Program Files (x86)\ESET
2013-08-17 08:22:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-08-07 17:07:00 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2013-08-06 22:53:41 ----D---- C:\Program Files (x86)\Elaborate Bytes
2013-08-04 00:20:17 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2013-08-04 00:20:16 ----A---- C:\Windows\system32\drivers\aswSP.sys
2013-08-04 00:20:15 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2013-08-04 00:20:14 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2013-08-04 00:20:14 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2013-08-04 00:20:13 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2013-08-04 00:20:11 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2013-08-04 00:20:10 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2013-08-04 00:19:38 ----A---- C:\Windows\avastSS.scr
2013-08-02 03:59:01 ----A---- C:\Windows\system32\pwNative.exe
2013-08-02 03:59:00 ----N---- C:\Windows\system32\pwdspio.sys
2013-08-02 03:59:00 ----N---- C:\Windows\system32\pwdrvio.sys
2013-07-27 17:17:39 ----A---- C:\Windows\system32\drivers
\lgandnetadb.sys
2013-07-27 17:17:39 ----A---- C:\Windows\system32\drivers\lgandadb.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers
\lgandmodem64.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers\lgandgps64.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers
\lganddiag64.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers\lgandbus64.sys
======List of files/folders modified in the last 1 month======
2013-08-17 21:16:39 ----AD---- C:\Windows
2013-08-17 21:12:31 ----D---- C:\Windows\Prefetch
2013-08-17 21:12:26 ----RD---- C:\Program Files
2013-08-17 20:44:59 ----D---- C:\Windows\Temp
2013-08-17 15:42:17 ----RD---- C:\Program Files (x86)
2013-08-17 15:30:36 ----D---- C:\Program Files (x86)\Mozilla Maintenance
Service
2013-08-17 15:24:18 ----D---- C:\Windows\system32\drivers\etc
2013-08-15 22:49:07 ----D---- C:\Windows\system32\NDF
2013-08-15 22:41:10 ----D---- C:\Windows\System32
2013-08-15 22:41:10 ----D---- C:\Windows\inf
2013-08-15 22:41:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-15 21:27:06 ----D---- C:\Windows\system32\drivers
2013-08-11 13:37:28 ----D---- C:\Users\Vojto\AppData\Roaming\uTorrent
2013-08-07 16:22:23 ----D---- C:\Windows\SysWOW64
2013-08-06 22:54:05 ----HD---- C:\ProgramData
2013-08-06 22:54:00 ----D---- C:\Windows\system32\Tasks
2013-08-06 13:07:24 ----D---- C:\Users\Vojto\AppData\Roaming\Media
Player Classic
2013-08-04 00:20:09 ----SHD---- C:\Windows\Installer
2013-08-04 00:20:05 ----D---- C:\Windows\winsxs
2013-08-04 00:19:51 ----D---- C:\Windows\system32\config
2013-08-04 00:19:26 ----D---- C:\ProgramData\AVAST Software
2013-08-04 00:19:26 ----D---- C:\Program Files\AVAST Software
2013-08-03 23:17:42 ----D---- C:\Windows\system32\catroot2
2013-07-27 17:18:34 ----D---- C:\Windows\system32\DriverStore
2013-07-27 17:18:31 ----D---- C:\Program Files (x86)\LG Electronics
2013-07-27 17:18:30 ----HD---- C:\Program Files (x86)\InstallShield
Installation Information
2013-07-27 17:18:18 ----D---- C:\Program Files (x86)\Common Files
2013-07-20 14:15:07 ----D---- C:\Users\Vojto\AppData\Roaming\ApexDC++
2013-07-20 00:07:53 ----D---- C:\Program Files\mpchc
2013-07-20 00:00:53 ----D---- C:\Users\Vojto\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,
3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-05-09
65336]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-08-04
189936]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys
[2009-12-17 538136]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-
11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-06-15 828912]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-05-09
72016]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-08-04
1030952]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-08-04
378944]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers
\aswTdi.sys [2013-05-09 64288]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows
\system32\drivers\csc.sys [2010-11-21 514560]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys
[2012-12-19 237992]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows
\system32\DRIVERS\VBoxUSBMon.sys [2012-12-19 120232]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS
\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05
-09 33400]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys
[2013-05-09 80816]
R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers
\npf.sys [2010-06-25 35344]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows
\system32\DRIVERS\AcpiVpc.sys [2009-10-19 28176]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows
\system32\DRIVERS\bcmwl664.sys [2009-11-05 2838008]
R3 Cam5607;Lenovo EasyCamera ; C:\Windows\System32\Drivers\BisonC07.sys
[2009-12-01 1270896]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition
Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2009-12-01
709632]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys
[2010-02-19 167816]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS
\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows
\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26
158976]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows
\system32\drivers\nvhda64v.sys [2012-04-18 188736]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows
\system32\DRIVERS\VBoxNetAdp.sys [2012-12-19 132008]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows
\system32\DRIVERS\VBoxNetFlt.sys [2012-12-19 146856]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows
\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 Andbus;LGE Android Platform Composite USB Device; C:\Windows
\system32\DRIVERS\lgandbus64.sys [2012-03-02 19456]
S3 AndDiag;LGE Android Platform USB Serial Port; C:\Windows
\system32\DRIVERS\lganddiag64.sys [2012-03-02 27648]
S3 AndGps;LGE Android Platform USB GPS NMEA Port; C:\Windows
\system32\DRIVERS\lgandgps64.sys [2012-03-02 27136]
S3 ANDModem;LGE Android Platform USB Modem; C:\Windows\system32\DRIVERS
\lgandmodem64.sys [2012-03-02 34304]
S3 andnetadb;ADB Interface DriverNet; C:\Windows\System32\Drivers
\lgandnetadb.sys [2012-03-07 31744]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers
\lgandadb.sys [2010-08-02 31744]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS
\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows
\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers
\BTHport.sys [2010-11-21 552448]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers
\BTHUSB.sys [2010-11-21 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers
\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers
\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS
\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14
12352]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows
\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows
\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows
\System32\Drivers\RtsUStor.sys [2009-12-11 232992]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS
\Rt64win7.sys [2011-06-10 539240]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21
6656]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite
2010\WNt500x64\Sandra.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21
34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11
-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows
\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\programfiles
\tuneuputilities\TuneUpUtilitiesDriver64.sys [2010-02-24 11856]
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS
\usb8023x.sys [2009-07-14 19968]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21
199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11
-21 21760]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys
[2010-11-21 41984]
S4 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver; C:
\Windows\system32\DRIVERS\niede.sys [2010-06-15 38064]
S4 niraptrkw;niraptrkw; C:\Windows\system32\DRIVERS\niraptrkw.sys [2012
-06-15 12464]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,
3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software
\Avast\AvastSvc.exe [2013-05-09 46808]
R2 OODefragAgent;O&O Defrag; C:\Program Files\OO Software\Defrag
\oodag.exe [2010-06-21 2532680]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-
07-14 27136]
R3 FileZilla Server;FileZilla Server FTP server; C:\Program Files
(x86)\FileZilla Server\FileZilla Server.exe [2012-02-26 632320]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common
Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
[2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN
v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework
\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN
v4.0.30319_X64; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files
(x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:
\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-
13 257416]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 CscService;Offline Files; C:\Windows\System32\svchost.exe [2009-07-14
27136]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program
Files\Common Files\Macrovision Shared\FLEXnet Publisher
\FNPLicensingService64.exe [2012-06-15 1030600]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe
[2013-05-31 641352]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint
Workspace Audit Service; C:\Program Files (x86)\Microsoft Office
\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files
(x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-08-17
117656]
S3 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe
[2012-05-15 889664]
S3 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files
(x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15
1262400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files
\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows
\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program
Files (x86)\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows
\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows
\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 TuneUp.Defrag;TuneUp Drive Defrag Service; D:\programfiles
\tuneuputilities\TuneUpDefragService.exe [2012-06-15 607040]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\programfiles
\tuneuputilities\TuneUpUtilitiesService64.exe [2010-08-27 1403200]
S4 UxTuneUp;TuneUp Theme Extension; C:\Windows\System32\svchost.exe
[2009-07-14 27136]
-----------------EOF-----------------
# For example:
#
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
RSIT log:
Logfile of random's system information tool 1.09 (written by
random/random)
Run by Vojto at 2013-08-17 21:16:51
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 12 GB (28%) free of 41 GB
Total RAM: 3959 MB (58% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:16:54, on 17. 8. 2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal
Running processes:
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Vojto.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:
\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast
\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar
\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows
\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar
\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows
\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: AutorunsDisabled
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel -
res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:
\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-
8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office
\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-
7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office
\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-
6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office
\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote -
{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files
(x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter: AutorunsDisabled - (no CLSID) - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe
Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM
\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service
(AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows
\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner
- C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files
\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown
owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown
owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) -
FileZilla Project - C:\Program Files (x86)\FileZilla Server\FileZilla
Server.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. -
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher
\FNPLicensingService64.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin
\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) -
Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service
\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows
\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) -
Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner -
C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA
Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update
Core\daemonu.exe
O23 - Service: O&O Defrag (OODefragAgent) - O&O Software GmbH - C:
\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage)
- Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental)
(rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap
\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) -
Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown
owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) -
Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown
owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown
owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) -
Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) -
Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner
- C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown
owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) -
Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv)
- Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
--
End of file - 6942 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows
SharedSection=1024,20480,768 Windows=On SubSystemType=Windows
ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4
ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows
SharedSection=1024,20480,768 Windows=On SubSystemType=Windows
ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3
ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4
ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 13703456
\??\C:\Windows\system32\conhost.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\OO Software\Defrag\oodag.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Common Files\Microsoft Shared
\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\notepad.exe"
"taskhost.exe"
"C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe"
"C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"D:\downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles
\dgu9mslu.default
prefs.js - "browser.search.useDBForOrder" - true
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=D:\programfiles\Foxit Reader\foxitreader\plugins
\npFoxitReaderPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@java.com/DTPlugin,version=10.13.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@java.com/JavaPlugin,version=10.13.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins
\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5]
"Description"=A component of your photo software powered by RocketLife
"Path"=C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins
\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\Browser Helper Objects\AutorunsDisabled]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows
\CurrentVersion\Explorer\Browser Helper Objects\AutorunsDisabled]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-02-24 2598280]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe [2010-06
-21 3838792]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management
\utility.exe [2009-12-17 4367808]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management
\Energy Management.exe [2009-12-17 6988736]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows
\CurrentVersion\Run]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09
4858968]
C:\Users\Vojto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
\Startup
AutorunsDisabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network
\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies
\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
\explorer]
"NoPreviewPane"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies
\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess
\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess
\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 month======
2013-08-17 21:16:51 ----D---- C:\rsit
2013-08-17 21:12:26 ----D---- C:\Program Files\trend micro
2013-08-17 15:42:17 ----D---- C:\Program Files (x86)\ESET
2013-08-17 08:22:31 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-08-07 17:07:00 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2013-08-06 22:53:41 ----D---- C:\Program Files (x86)\Elaborate Bytes
2013-08-04 00:20:17 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2013-08-04 00:20:16 ----A---- C:\Windows\system32\drivers\aswSP.sys
2013-08-04 00:20:15 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2013-08-04 00:20:14 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2013-08-04 00:20:14 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2013-08-04 00:20:13 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2013-08-04 00:20:11 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2013-08-04 00:20:10 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2013-08-04 00:19:38 ----A---- C:\Windows\avastSS.scr
2013-08-02 03:59:01 ----A---- C:\Windows\system32\pwNative.exe
2013-08-02 03:59:00 ----N---- C:\Windows\system32\pwdspio.sys
2013-08-02 03:59:00 ----N---- C:\Windows\system32\pwdrvio.sys
2013-07-27 17:17:39 ----A---- C:\Windows\system32\drivers
\lgandnetadb.sys
2013-07-27 17:17:39 ----A---- C:\Windows\system32\drivers\lgandadb.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers
\lgandmodem64.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers\lgandgps64.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers
\lganddiag64.sys
2013-07-27 17:17:38 ----A---- C:\Windows\system32\drivers\lgandbus64.sys
======List of files/folders modified in the last 1 month======
2013-08-17 21:16:39 ----AD---- C:\Windows
2013-08-17 21:12:31 ----D---- C:\Windows\Prefetch
2013-08-17 21:12:26 ----RD---- C:\Program Files
2013-08-17 20:44:59 ----D---- C:\Windows\Temp
2013-08-17 15:42:17 ----RD---- C:\Program Files (x86)
2013-08-17 15:30:36 ----D---- C:\Program Files (x86)\Mozilla Maintenance
Service
2013-08-17 15:24:18 ----D---- C:\Windows\system32\drivers\etc
2013-08-15 22:49:07 ----D---- C:\Windows\system32\NDF
2013-08-15 22:41:10 ----D---- C:\Windows\System32
2013-08-15 22:41:10 ----D---- C:\Windows\inf
2013-08-15 22:41:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-15 21:27:06 ----D---- C:\Windows\system32\drivers
2013-08-11 13:37:28 ----D---- C:\Users\Vojto\AppData\Roaming\uTorrent
2013-08-07 16:22:23 ----D---- C:\Windows\SysWOW64
2013-08-06 22:54:05 ----HD---- C:\ProgramData
2013-08-06 22:54:00 ----D---- C:\Windows\system32\Tasks
2013-08-06 13:07:24 ----D---- C:\Users\Vojto\AppData\Roaming\Media
Player Classic
2013-08-04 00:20:09 ----SHD---- C:\Windows\Installer
2013-08-04 00:20:05 ----D---- C:\Windows\winsxs
2013-08-04 00:19:51 ----D---- C:\Windows\system32\config
2013-08-04 00:19:26 ----D---- C:\ProgramData\AVAST Software
2013-08-04 00:19:26 ----D---- C:\Program Files\AVAST Software
2013-08-03 23:17:42 ----D---- C:\Windows\system32\catroot2
2013-07-27 17:18:34 ----D---- C:\Windows\system32\DriverStore
2013-07-27 17:18:31 ----D---- C:\Program Files (x86)\LG Electronics
2013-07-27 17:18:30 ----HD---- C:\Program Files (x86)\InstallShield
Installation Information
2013-07-27 17:18:18 ----D---- C:\Program Files (x86)\Common Files
2013-07-20 14:15:07 ----D---- C:\Users\Vojto\AppData\Roaming\ApexDC++
2013-07-20 00:07:53 ----D---- C:\Program Files\mpchc
2013-07-20 00:00:53 ----D---- C:\Users\Vojto\AppData\Roaming\vlc
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,
3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2013-05-09
65336]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2013-08-04
189936]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys
[2009-12-17 538136]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-
11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-06-15 828912]
R1 aswRdr;aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [2013-05-09
72016]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2013-08-04
1030952]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2013-08-04
378944]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers
\aswTdi.sys [2013-05-09 64288]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows
\system32\drivers\csc.sys [2010-11-21 514560]
R1 VBoxDrv;VirtualBox Service; C:\Windows\system32\DRIVERS\VBoxDrv.sys
[2012-12-19 237992]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\Windows
\system32\DRIVERS\VBoxUSBMon.sys [2012-12-19 120232]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS
\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2013-05
-09 33400]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys
[2013-05-09 80816]
R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers
\npf.sys [2010-06-25 35344]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows
\system32\DRIVERS\AcpiVpc.sys [2009-10-19 28176]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows
\system32\DRIVERS\bcmwl664.sys [2009-11-05 2838008]
R3 Cam5607;Lenovo EasyCamera ; C:\Windows\System32\Drivers\BisonC07.sys
[2009-12-01 1270896]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition
Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2009-12-01
709632]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys
[2010-02-19 167816]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS
\GEARAspiWDM.sys [2012-08-21 33240]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows
\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26
158976]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows
\system32\drivers\nvhda64v.sys [2012-04-18 188736]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\Windows
\system32\DRIVERS\VBoxNetAdp.sys [2012-12-19 132008]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service; C:\Windows
\system32\DRIVERS\VBoxNetFlt.sys [2012-12-19 146856]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows
\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 Andbus;LGE Android Platform Composite USB Device; C:\Windows
\system32\DRIVERS\lgandbus64.sys [2012-03-02 19456]
S3 AndDiag;LGE Android Platform USB Serial Port; C:\Windows
\system32\DRIVERS\lganddiag64.sys [2012-03-02 27648]
S3 AndGps;LGE Android Platform USB GPS NMEA Port; C:\Windows
\system32\DRIVERS\lgandgps64.sys [2012-03-02 27136]
S3 ANDModem;LGE Android Platform USB Modem; C:\Windows\system32\DRIVERS
\lgandmodem64.sys [2012-03-02 34304]
S3 andnetadb;ADB Interface DriverNet; C:\Windows\System32\Drivers
\lgandnetadb.sys [2012-03-07 31744]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers
\lgandadb.sys [2010-08-02 31744]
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS
\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows
\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers
\BTHport.sys [2010-11-21 552448]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers
\BTHUSB.sys [2010-11-21 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers
\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers
\btwaudio.sys []
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys []
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS
\btwl2cap.sys []
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14
12352]
S3 pwdrvio;pwdrvio; \??\C:\Windows\syswow64\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\Windows\syswow64\pwdspio.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows
\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows
\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows
\System32\Drivers\RtsUStor.sys [2009-12-11 232992]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS
\Rt64win7.sys [2011-06-10 539240]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21
6656]
S3 SANDRA;SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite
2010\WNt500x64\Sandra.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21
34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11
-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows
\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\D:\programfiles
\tuneuputilities\TuneUpUtilitiesDriver64.sys [2010-02-24 11856]
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS
\usb8023x.sys [2009-07-14 19968]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21
199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11
-21 21760]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys
[2010-11-21 41984]
S4 NIEthernetDeviceEnumerator;NI Ethernet Device Enumerator Driver; C:
\Windows\system32\DRIVERS\niede.sys [2010-06-15 38064]
S4 niraptrkw;niraptrkw; C:\Windows\system32\DRIVERS\niraptrkw.sys [2012
-06-15 12464]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,
3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software
\Avast\AvastSvc.exe [2013-05-09 46808]
R2 OODefragAgent;O&O Defrag; C:\Program Files\OO Software\Defrag
\oodag.exe [2010-06-21 2532680]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-
07-14 27136]
R3 FileZilla Server;FileZilla Server FTP server; C:\Program Files
(x86)\FileZilla Server\FileZilla Server.exe [2012-02-26 632320]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common
Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
[2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN
v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework
\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN
v4.0.30319_X64; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files
(x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:
\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-
13 257416]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 CscService;Offline Files; C:\Windows\System32\svchost.exe [2009-07-14
27136]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program
Files\Common Files\Macrovision Shared\FLEXnet Publisher
\FNPLicensingService64.exe [2012-06-15 1030600]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe
[2013-05-31 641352]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint
Workspace Audit Service; C:\Program Files (x86)\Microsoft Office
\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files
(x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-08-17
117656]
S3 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe
[2012-05-15 889664]
S3 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files
(x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15
1262400]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files
\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows
\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program
Files (x86)\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows
\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows
\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\
\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET
\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 TuneUp.Defrag;TuneUp Drive Defrag Service; D:\programfiles
\tuneuputilities\TuneUpDefragService.exe [2012-06-15 607040]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service; D:\programfiles
\tuneuputilities\TuneUpUtilitiesService64.exe [2010-08-27 1403200]
S4 UxTuneUp;TuneUp Theme Extension; C:\Windows\System32\svchost.exe
[2009-07-14 27136]
-----------------EOF-----------------
Re: weby ukazovali error 302
Zdravim
Poprosim o spusteni nasledujiciho
Aplikace ke stažení:
Po stažení FRSTLauncher spustte, objevi se mozna varovani od antiviru, ignorujte a nechte FRSTL spustit
Následně dojde ke stažení FRST a inicializaci
Poprosim o spusteni nasledujiciho
- Po spuštění FRST odsouhlasíme licenční podmínky kliknutím na Ano.
- Dooznačíme položku Addition.txt - viz obrázek.

- Klikneme na tlačítko Scan čímž spustíme skenování.
- Počkáme na dokončení skenování FRST a vytvoření doplňkových informací naší nástavbou.
- Otevře se nám textový soubor FRST.txt, což je požadovaný log a jehož obsah vložíme do svého tématu na fóru.
- Po uzavření logu se FRSTLauncher.exe ukončí a na ploše nám zbyde utilta FRST a dva logy FRST.txt a Addition.txt - nic z toho zatím nemažeme.
Re: weby ukazovali error 302
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-08-2013
Ran by Vojto (administrator) on 19-08-2013 14:05:31
Running from D:\downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-02-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [OODefragTray] - C:\Program Files\OO Software\Defrag\oodtray.exe [3838792 2010-06-21] (O&O Software GmbH)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4367808 2009-12-17] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [6988736 2009-12-17] (Lenovo (Beijing) Limited)
HKCU\...\Command Processor: <======= ATTENTION
MountPoints2: {c68cc687-37ca-11e2-b9e9-806e6f6e6963} - F:\LaunchU3.exe -a
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\UpdatusUser\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
Startup: C:\Users\Vojto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
BootExecute: autocheck autochk * OODBS
==================== Internet (Whitelisted) ====================
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
DPF: HKLM {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/ ... 0237966447
Filter: AutorunsDisabled - No CLSID Value - No File
Filter-x32: AutorunsDisabled - No CLSID Value - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - D:\programfiles\Foxit Reader\foxitreader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
FF Extension: firefox - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default\Extensions\firefox@ghostery.com.xpi
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S4 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [632320 2012-02-26] (FileZilla Project)
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2532680 2010-06-21] (O&O Software GmbH)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S4 TuneUp.Defrag; D:\programfiles\tuneuputilities\TuneUpDefragService.exe [607040 2012-06-15] (TuneUp Software)
S4 TuneUp.UtilitiesSvc; D:\programfiles\tuneuputilities\TuneUpUtilitiesService64.exe [1403200 2010-08-27] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2012-03-02] (LG Electronics Inc.)
S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2012-03-02] (LG Electronics Inc.)
S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2012-03-02] (LG Electronics Inc.)
S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [34304 2012-03-02] (LG Electronics Inc.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc)
S3 androidusb; C:\Windows\System32\Drivers\lgandadb.sys [31744 2010-08-02] (Google Inc)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-04] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-04] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-04] ()
S4 NIEthernetDeviceEnumerator; C:\Windows\System32\DRIVERS\niede.sys [38064 2010-06-15] (National Instruments Corporation)
S4 niraptrkw; C:\Windows\System32\DRIVERS\niraptrkw.sys [12464 2012-06-15] (National Instruments Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-06-18] ()
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-06-18] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-06-18] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-06-18] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [828912 2012-06-15] ()
S3 TuneUpUtilitiesDrv; D:\programfiles\tuneuputilities\TuneUpUtilitiesDriver64.sys [11856 2010-02-24] (TuneUp Software)
U3 a281adfa; C:\Windows\System32\Drivers\a281adfa.sys [0 ] (Advanced Micro Devices)
S3 btwaudio; system32\drivers\btwaudio.sys [x]
S3 btwavdt; system32\drivers\btwavdt.sys [x]
S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [x]
S3 btwrchid; system32\DRIVERS\btwrchid.sys [x]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x64\Sandra.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-19 14:02 - 2013-08-19 14:02 - 00000000 ____D C:\FRST
2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\Users\Vojto\AppData\Local\qb2A76F989.A0
2013-08-17 21:16 - 2013-08-17 21:16 - 00000000 ____D C:\Users\Vojto\Desktop\autokms
2013-08-17 21:12 - 2013-08-17 21:16 - 00000000 ____D C:\Program Files\trend micro
2013-08-17 15:42 - 2013-08-17 15:42 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-17 08:22 - 2013-08-17 15:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-15 21:40 - 2013-08-15 22:42 - 00000437 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-08-15 21:27 - 2013-08-15 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2013-08-07 17:07 - 2013-08-07 17:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-07 16:22 - 2013-08-07 16:22 - 00000048 _____ C:\Windows\978C96E52C3F4B7A.log
2013-08-06 22:54 - 2013-08-06 22:54 - 00000085 ___SH C:\ProgramData\.zreglib
2013-08-06 22:53 - 2013-08-07 16:22 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-08-06 22:53 - 2013-08-06 22:53 - 00002970 _____ C:\Windows\System32\Tasks\elbyExecuteWithUAC
2013-08-04 00:20 - 2013-08-17 14:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-08-04 00:20 - 2013-08-04 00:20 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-08-04 00:20 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-08-04 00:19 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-08-04 00:10 - 2013-08-04 00:10 - 00000002 _____ C:\AvastSetup.log
2013-08-02 03:59 - 2012-06-18 13:34 - 02966720 _____ C:\Windows\system32\pwNative.exe
2013-08-02 03:59 - 2012-06-18 13:34 - 00019032 ____N C:\Windows\system32\pwdrvio.sys
2013-08-02 03:59 - 2012-06-18 13:34 - 00012384 ____N C:\Windows\system32\pwdspio.sys
2013-07-27 17:17 - 2012-03-07 03:00 - 00031744 _____ (Google Inc) C:\Windows\system32\Drivers\lgandnetadb.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00034304 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lgandmodem64.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00027648 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lganddiag64.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00027136 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lgandgps64.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00019456 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lgandbus64.sys
2013-07-27 17:17 - 2010-08-02 16:19 - 00031744 _____ (Google Inc) C:\Windows\system32\Drivers\lgandadb.sys
2013-07-24 20:08 - 2013-07-24 20:08 - 00001078 _____ C:\Users\Vojto\Desktop\frd.lnk
2013-07-21 22:05 - 2013-07-21 22:11 - 00000000 ____D C:\Users\Vojto\.idlerc
==================== One Month Modified Files and Folders =======
2013-08-19 14:02 - 2013-08-19 14:02 - 00000000 ____D C:\FRST
2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\Users\Vojto\AppData\Local\qb2A76F989.A0
2013-08-19 13:55 - 2013-02-22 16:31 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-19 10:44 - 2013-06-28 21:13 - 00130718 _____ C:\Windows\WindowsUpdate.log
2013-08-19 02:16 - 2012-06-15 01:31 - 00000000 ____D C:\Users\Vojto\Documents\Lexicon
2013-08-18 08:42 - 2009-07-14 06:45 - 00021808 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-18 08:42 - 2009-07-14 06:45 - 00021808 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-17 21:16 - 2013-08-17 21:12 - 00000000 ____D C:\Program Files\trend micro
2013-08-17 15:42 - 2013-08-17 15:42 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-17 15:30 - 2013-08-17 08:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-17 15:30 - 2012-06-14 23:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-17 14:35 - 2013-08-04 00:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-08-15 22:49 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-15 22:46 - 2012-06-18 19:11 - 00000000 ____D C:\Users\Vojto\.VirtualBox
2013-08-15 22:42 - 2013-08-15 21:40 - 00000437 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-08-15 22:41 - 2009-07-14 07:13 - 00778150 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-15 21:27 - 2013-08-15 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2013-08-15 21:27 - 2013-06-20 15:31 - 00015883 _____ C:\Windows\setupact.log
2013-08-15 19:57 - 2012-06-15 20:06 - 00000306 _____ C:\Users\Vojto\.packettracer
2013-08-11 13:37 - 2012-06-15 02:38 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\uTorrent
2013-08-11 08:06 - 2013-07-12 13:19 - 00004682 _____ C:\Windows\PFRO.log
2013-08-11 08:06 - 2012-06-15 00:22 - 00600007 _____ C:\Windows\system32\oodbs.lor
2013-08-11 08:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-07 17:08 - 2013-08-07 17:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-07 16:22 - 2013-08-07 16:22 - 00000048 _____ C:\Windows\978C96E52C3F4B7A.log
2013-08-07 16:22 - 2013-08-06 22:53 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-08-06 23:01 - 2012-06-15 01:12 - 00000124 _____ C:\Users\Vojto\Documents\ax_files.xml
2013-08-06 22:54 - 2013-08-06 22:54 - 00000085 ___SH C:\ProgramData\.zreglib
2013-08-06 22:53 - 2013-08-06 22:53 - 00002970 _____ C:\Windows\System32\Tasks\elbyExecuteWithUAC
2013-08-06 13:07 - 2013-06-01 11:21 - 00000000 ____D C:\Users\Vojto\AppData\Local\CrashDumps
2013-08-06 13:07 - 2012-06-15 22:52 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\Media Player Classic
2013-08-04 00:26 - 2012-06-14 23:31 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-08-04 00:20 - 2013-08-04 00:20 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-08-04 00:19 - 2012-06-14 23:31 - 00000000 ____D C:\ProgramData\AVAST Software
2013-08-04 00:19 - 2012-06-14 23:31 - 00000000 ____D C:\Program Files\AVAST Software
2013-08-04 00:10 - 2013-08-04 00:10 - 00000002 _____ C:\AvastSetup.log
2013-07-29 16:48 - 2012-06-15 19:59 - 00007601 _____ C:\Users\Vojto\AppData\Local\Resmon.ResmonCfg
2013-07-27 17:18 - 2012-06-17 17:12 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2013-07-27 17:18 - 2012-06-14 22:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-24 20:08 - 2013-07-24 20:08 - 00001078 _____ C:\Users\Vojto\Desktop\frd.lnk
2013-07-21 22:11 - 2013-07-21 22:05 - 00000000 ____D C:\Users\Vojto\.idlerc
2013-07-21 22:05 - 2012-06-14 22:03 - 00000000 ____D C:\Users\Vojto
2013-07-20 14:15 - 2012-09-14 12:11 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\ApexDC++
2013-07-20 14:15 - 2012-09-14 12:11 - 00000000 ____D C:\Users\Vojto\AppData\Local\ApexDC++
2013-07-20 00:07 - 2012-06-14 23:37 - 00000000 ____D C:\Program Files\mpchc
2013-07-20 00:00 - 2012-09-14 13:27 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\vlc
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-12 08:30
==================== End Of Log ============================
Ran by Vojto (administrator) on 19-08-2013 14:05:31
Running from D:\downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(O&O Software GmbH) C:\Program Files\OO Software\Defrag\oodag.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-02-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [OODefragTray] - C:\Program Files\OO Software\Defrag\oodtray.exe [3838792 2010-06-21] (O&O Software GmbH)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4367808 2009-12-17] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [6988736 2009-12-17] (Lenovo (Beijing) Limited)
HKCU\...\Command Processor: <======= ATTENTION
MountPoints2: {c68cc687-37ca-11e2-b9e9-806e6f6e6963} - F:\LaunchU3.exe -a
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
HKU\UpdatusUser\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x]
Startup: C:\Users\Vojto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
BootExecute: autocheck autochk * OODBS
==================== Internet (Whitelisted) ====================
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
DPF: HKLM {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/ ... 0237966447
Filter: AutorunsDisabled - No CLSID Value - No File
Filter-x32: AutorunsDisabled - No CLSID Value - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - D:\programfiles\Foxit Reader\foxitreader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Extensions\songbird@songbirdnest.com
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
FF Extension: firefox - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default\Extensions\firefox@ghostery.com.xpi
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: No Name - C:\Users\Vojto\AppData\Roaming\Mozilla\Firefox\Profiles\dgu9mslu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S4 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [632320 2012-02-26] (FileZilla Project)
R2 OODefragAgent; C:\Program Files\OO Software\Defrag\oodag.exe [2532680 2010-06-21] (O&O Software GmbH)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S4 TuneUp.Defrag; D:\programfiles\tuneuputilities\TuneUpDefragService.exe [607040 2012-06-15] (TuneUp Software)
S4 TuneUp.UtilitiesSvc; D:\programfiles\tuneuputilities\TuneUpUtilitiesService64.exe [1403200 2010-08-27] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus64.sys [19456 2012-03-02] (LG Electronics Inc.)
S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag64.sys [27648 2012-03-02] (LG Electronics Inc.)
S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps64.sys [27136 2012-03-02] (LG Electronics Inc.)
S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem64.sys [34304 2012-03-02] (LG Electronics Inc.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2012-03-07] (Google Inc)
S3 androidusb; C:\Windows\System32\Drivers\lgandadb.sys [31744 2010-08-02] (Google Inc)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-04] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-04] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-04] ()
S4 NIEthernetDeviceEnumerator; C:\Windows\System32\DRIVERS\niede.sys [38064 2010-06-15] (National Instruments Corporation)
S4 niraptrkw; C:\Windows\System32\DRIVERS\niraptrkw.sys [12464 2012-06-15] (National Instruments Corporation)
R2 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-06-18] ()
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2012-06-18] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-06-18] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12384 2012-06-18] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [828912 2012-06-15] ()
S3 TuneUpUtilitiesDrv; D:\programfiles\tuneuputilities\TuneUpUtilitiesDriver64.sys [11856 2010-02-24] (TuneUp Software)
U3 a281adfa; C:\Windows\System32\Drivers\a281adfa.sys [0 ] (Advanced Micro Devices)
S3 btwaudio; system32\drivers\btwaudio.sys [x]
S3 btwavdt; system32\drivers\btwavdt.sys [x]
S3 btwl2cap; system32\DRIVERS\btwl2cap.sys [x]
S3 btwrchid; system32\DRIVERS\btwrchid.sys [x]
S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010\WNt500x64\Sandra.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-19 14:02 - 2013-08-19 14:02 - 00000000 ____D C:\FRST
2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\Users\Vojto\AppData\Local\qb2A76F989.A0
2013-08-17 21:16 - 2013-08-17 21:16 - 00000000 ____D C:\Users\Vojto\Desktop\autokms
2013-08-17 21:12 - 2013-08-17 21:16 - 00000000 ____D C:\Program Files\trend micro
2013-08-17 15:42 - 2013-08-17 15:42 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-17 08:22 - 2013-08-17 15:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-15 21:40 - 2013-08-15 22:42 - 00000437 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-08-15 21:27 - 2013-08-15 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2013-08-07 17:07 - 2013-08-07 17:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-07 16:22 - 2013-08-07 16:22 - 00000048 _____ C:\Windows\978C96E52C3F4B7A.log
2013-08-06 22:54 - 2013-08-06 22:54 - 00000085 ___SH C:\ProgramData\.zreglib
2013-08-06 22:53 - 2013-08-07 16:22 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-08-06 22:53 - 2013-08-06 22:53 - 00002970 _____ C:\Windows\System32\Tasks\elbyExecuteWithUAC
2013-08-04 00:20 - 2013-08-17 14:35 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-08-04 00:20 - 2013-08-04 00:20 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-08-04 00:20 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-08-04 00:20 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-08-04 00:19 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-08-04 00:10 - 2013-08-04 00:10 - 00000002 _____ C:\AvastSetup.log
2013-08-02 03:59 - 2012-06-18 13:34 - 02966720 _____ C:\Windows\system32\pwNative.exe
2013-08-02 03:59 - 2012-06-18 13:34 - 00019032 ____N C:\Windows\system32\pwdrvio.sys
2013-08-02 03:59 - 2012-06-18 13:34 - 00012384 ____N C:\Windows\system32\pwdspio.sys
2013-07-27 17:17 - 2012-03-07 03:00 - 00031744 _____ (Google Inc) C:\Windows\system32\Drivers\lgandnetadb.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00034304 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lgandmodem64.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00027648 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lganddiag64.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00027136 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lgandgps64.sys
2013-07-27 17:17 - 2012-03-02 16:02 - 00019456 _____ (LG Electronics Inc.) C:\Windows\system32\Drivers\lgandbus64.sys
2013-07-27 17:17 - 2010-08-02 16:19 - 00031744 _____ (Google Inc) C:\Windows\system32\Drivers\lgandadb.sys
2013-07-24 20:08 - 2013-07-24 20:08 - 00001078 _____ C:\Users\Vojto\Desktop\frd.lnk
2013-07-21 22:05 - 2013-07-21 22:11 - 00000000 ____D C:\Users\Vojto\.idlerc
==================== One Month Modified Files and Folders =======
2013-08-19 14:02 - 2013-08-19 14:02 - 00000000 ____D C:\FRST
2013-08-19 14:00 - 2013-08-19 14:00 - 00000000 ____D C:\Users\Vojto\AppData\Local\qb2A76F989.A0
2013-08-19 13:55 - 2013-02-22 16:31 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-19 10:44 - 2013-06-28 21:13 - 00130718 _____ C:\Windows\WindowsUpdate.log
2013-08-19 02:16 - 2012-06-15 01:31 - 00000000 ____D C:\Users\Vojto\Documents\Lexicon
2013-08-18 08:42 - 2009-07-14 06:45 - 00021808 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-18 08:42 - 2009-07-14 06:45 - 00021808 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-17 21:16 - 2013-08-17 21:12 - 00000000 ____D C:\Program Files\trend micro
2013-08-17 15:42 - 2013-08-17 15:42 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-17 15:30 - 2013-08-17 08:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-17 15:30 - 2012-06-14 23:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-17 14:35 - 2013-08-04 00:20 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-08-15 22:49 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-15 22:46 - 2012-06-18 19:11 - 00000000 ____D C:\Users\Vojto\.VirtualBox
2013-08-15 22:42 - 2013-08-15 21:40 - 00000437 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-08-15 22:41 - 2009-07-14 07:13 - 00778150 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-15 21:27 - 2013-08-15 21:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_lgandnetadb_01005.Wdf
2013-08-15 21:27 - 2013-06-20 15:31 - 00015883 _____ C:\Windows\setupact.log
2013-08-15 19:57 - 2012-06-15 20:06 - 00000306 _____ C:\Users\Vojto\.packettracer
2013-08-11 13:37 - 2012-06-15 02:38 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\uTorrent
2013-08-11 08:06 - 2013-07-12 13:19 - 00004682 _____ C:\Windows\PFRO.log
2013-08-11 08:06 - 2012-06-15 00:22 - 00600007 _____ C:\Windows\system32\oodbs.lor
2013-08-11 08:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-07 17:08 - 2013-08-07 17:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-08-07 16:22 - 2013-08-07 16:22 - 00000048 _____ C:\Windows\978C96E52C3F4B7A.log
2013-08-07 16:22 - 2013-08-06 22:53 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes
2013-08-06 23:01 - 2012-06-15 01:12 - 00000124 _____ C:\Users\Vojto\Documents\ax_files.xml
2013-08-06 22:54 - 2013-08-06 22:54 - 00000085 ___SH C:\ProgramData\.zreglib
2013-08-06 22:53 - 2013-08-06 22:53 - 00002970 _____ C:\Windows\System32\Tasks\elbyExecuteWithUAC
2013-08-06 13:07 - 2013-06-01 11:21 - 00000000 ____D C:\Users\Vojto\AppData\Local\CrashDumps
2013-08-06 13:07 - 2012-06-15 22:52 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\Media Player Classic
2013-08-04 00:26 - 2012-06-14 23:31 - 00000000 _____ C:\Windows\SysWOW64\config.nt
2013-08-04 00:20 - 2013-08-04 00:20 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-08-04 00:20 - 2013-08-04 00:20 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-08-04 00:19 - 2012-06-14 23:31 - 00000000 ____D C:\ProgramData\AVAST Software
2013-08-04 00:19 - 2012-06-14 23:31 - 00000000 ____D C:\Program Files\AVAST Software
2013-08-04 00:10 - 2013-08-04 00:10 - 00000002 _____ C:\AvastSetup.log
2013-07-29 16:48 - 2012-06-15 19:59 - 00007601 _____ C:\Users\Vojto\AppData\Local\Resmon.ResmonCfg
2013-07-27 17:18 - 2012-06-17 17:12 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2013-07-27 17:18 - 2012-06-14 22:50 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-24 20:08 - 2013-07-24 20:08 - 00001078 _____ C:\Users\Vojto\Desktop\frd.lnk
2013-07-21 22:11 - 2013-07-21 22:05 - 00000000 ____D C:\Users\Vojto\.idlerc
2013-07-21 22:05 - 2012-06-14 22:03 - 00000000 ____D C:\Users\Vojto
2013-07-20 14:15 - 2012-09-14 12:11 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\ApexDC++
2013-07-20 14:15 - 2012-09-14 12:11 - 00000000 ____D C:\Users\Vojto\AppData\Local\ApexDC++
2013-07-20 00:07 - 2012-06-14 23:37 - 00000000 ____D C:\Program Files\mpchc
2013-07-20 00:00 - 2012-09-14 13:27 - 00000000 ____D C:\Users\Vojto\AppData\Roaming\vlc
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-12 08:30
==================== End Of Log ============================
Re: weby ukazovali error 302
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKCU\...\Command Processor: <======= ATTENTION Filter: AutorunsDisabled - No CLSID Value - No File Filter-x32: AutorunsDisabled - No CLSID Value - No File C:\Windows\tasks\Adobe Flash Player Updater.job Hosts: CMD: shutdown /r /f /t 2 End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: weby ukazovali error 302
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-08-2013
Ran by Vojto at 2013-08-19 17:25:08 Run:1
Running from D:\downloads\sken virusov
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKCU\...\Command Processor: <======= ATTENTION
Filter: AutorunsDisabled - No CLSID Value - No File
Filter-x32: AutorunsDisabled - No CLSID Value - No File
C:\Windows\tasks\Adobe Flash Player Updater.job
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKCU\Software\Microsoft\Command Processor\\AutoRun => Value deleted successfully.
HKCR\PROTOCOLS\Filter\AutorunsDisabled => Key deleted successfully.
HKCR\Wow6432Node\PROTOCOLS\Filter\AutorunsDisabled => Key not found.
C:\Windows\tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Ran by Vojto at 2013-08-19 17:25:08 Run:1
Running from D:\downloads\sken virusov
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKCU\...\Command Processor: <======= ATTENTION
Filter: AutorunsDisabled - No CLSID Value - No File
Filter-x32: AutorunsDisabled - No CLSID Value - No File
C:\Windows\tasks\Adobe Flash Player Updater.job
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKCU\Software\Microsoft\Command Processor\\AutoRun => Value deleted successfully.
HKCR\PROTOCOLS\Filter\AutorunsDisabled => Key deleted successfully.
HKCR\Wow6432Node\PROTOCOLS\Filter\AutorunsDisabled => Key not found.
C:\Windows\tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Re: weby ukazovali error 302
- Ulozte nejlepe na Plochu a rozbalte
- Spustte kliknutim na mbanr
- Nyni postupne kliknete na Next a Update
- Po dokonceni update (aktualizace) databaze kliknete opet na Next
- Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
- Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
- Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
- Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
- PC bude restartovan
- Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte
- Provedte aktualizaci
- Provedte uplny sken - nic nemazte

- MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
Re: weby ukazovali error 302
Obidva programy nič nenašli.
Re: weby ukazovali error 302
OK, chybky stale vyskakuji?
Re: weby ukazovali error 302
Nie, vôbec. Bolo to len nachvíľu v jeden deň. Ďalej som už na chybu nenarazil. Mohlo to byť tuším aj toto http://www.wired.co.uk/news/archive/201 ... /googledip . Niektoré weby obsahujú kód z google analytics, ale čas výpadku neodpovedá.
Chyba bola presne 302 The document has moved here .
Chyba bola presne 302 The document has moved here .
Re: weby ukazovali error 302
Tak jeste uklidime
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: weby ukazovali error 302
TFC mi spôsobil zamrznutie počítača pri logging off. Musel som natvrdo vypnúť. Díky za rady, ale nástroje od geekstogo už nikdy nepoužijem.



Přispějete na provoz fóra?