zpomalený internet
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
zpomalený internet
Dobrý den poslední dobou mam extrémně zpomalený internet , když připojím jiný počítač internet je zase v normálu tudíž asi nejaký wir , tady dle navodu vkladam rsit log predem dekuji za pomoct
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomas at 2013-08-29 12:49:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 648 GB (68%) free of 954 GB
Total RAM: 8109 MB (58% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
winlogon.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\TinyWall\TinyWall.exe"
WLIDSvcM.exe 700
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\alg.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
RPMDaemon.exe
"C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe" -m
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\TinyWall\TinyWall.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe"
"C:\Users\Tomas\Downloads\gpcl64bit.exe"
"taskhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4604.12dadd00.1704666996 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4604 "\\.\pipe\gecko-crash-server-pipe.4604" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --proxy-stub-channel=Flash6060.6C66A550.2696 --host-broker-channel=Flash6060.6C66A550.6742 --host-pid=6060 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --channel=2716.002DF4FC.270615662 --proxy-stub-channel=Flash6060.6C66A550.2696 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --host-npapi-version=27 --type=renderer
"C:\Program Files\CCleaner\CCleaner64.exe" /uac
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5472.0.86418310\1843978664" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,9,19,22 --reduce-gpu-sandbox --gpu-vendor-id=0x10de --gpu-device-id=0x1201 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1422 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.1.385427589\1925605024" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.2.487367765\1575361949" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.3.846190601\1412336697" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.4.277554770\1119097802" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.5.1661804884\1116349784" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf\10.16.100.504_0\plugins/ChromeApproveTBPlugin.dll" --lang=cs --channel="5472.6.1873707251\866543425" /prefetch:-390060480
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf\10.16.100.504_0\plugins/ConduitChromeApiPlugin.dll" --lang=cs --channel="5472.7.438324998\1319638266" /prefetch:-390060480
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf\10.16.100.504_0\search/plugins/npConduitNewTabPlugin.dll" --lang=cs --channel="5472.8.1396814174\199631434" /prefetch:-390060480
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.16.531760769\1409639323" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.23.1258194344\295361125" /prefetch:673131151
"C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe" /c /a /s UserSession
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe" "C:\Users\Tomas\Downloads\Big Bang theory CZ\2. série\Teorie.velkeho.tresku.S02E01.Paradigma.zkazene.ryby.DVDRip.XviD.cz-iNG.avi"
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.30.1429676765\355718694" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.32.38524345\1331645281" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.33.22178109\1123339475" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.34.486806853\1484843926" /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\trend micro\Tomas.exe" /silentautolog
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 528 532 540 65536 536
"C:\Users\Tomas\Downloads\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\extensions\
battlefieldheroespatcher@ea.com
SpecialSavings@SpecialSavings.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
GBHO.BHO - C:\Windows\system32\mscoree.dll [2010-11-21 444752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\coIEPlg.dll [2012-08-21 497048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\IPS\IPSBHO.DLL [2012-08-10 387040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-01-03 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-01-03 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1d09c093-f71e-43c3-b948-19316cbd695e} - Smart Recovery 2 - C:\Windows\system32\mscoree.dll [2010-11-21 444752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\coIEPlg.dll [2012-08-21 497048]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-16 12445288]
"TinyWall Controller"=C:\Program Files (x86)\TinyWall\TinyWall.exe [2012-06-22 623272]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-03-19 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-03-19 398616]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-03-19 439064]
"Ma10PAN.exe"=C:\Windows\system32\Ma10PAN.exe [2009-10-23 896032]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RPMKickstart"=C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2011-03-30 2552320]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-10 218032]
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-10 218032]
"BitTorrent"=C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe [2013-04-24 1133392]
"Google Update"=C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-29 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe [2013-04-24 1133392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-29 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2013-06-28 2255184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr]
C:\Windows\Samsung\PanelMgr\ssmmgr.exe [2009-08-14 614400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart File Advisor]
C:\Program Files (x86)\Smart File Advisor\sfa.exe /checkassoc []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Server.lnk]
C:\PROGRA~2\ArcSoft\TOTALM~1\TOTALM~1\TMSERV~1.EXE []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2006-09-10 86960]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2013-06-28 2255184]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"EasyTuneVI"=C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [2007-07-26 20480]
C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Startup
RollerCoaster Tycoon 3 Registration.lnk - C:\Users\Tomas\AppData\Local\Temp\{FA51BA31-1C2F-4367-A6DB-713845DC214D}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-03-19 434688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 month======
2013-08-29 12:44:16 ----D---- C:\Program Files\trend micro
2013-08-29 12:44:15 ----D---- C:\rsit
2013-08-29 11:11:27 ----D---- C:\Program Files\Symantec
2013-08-29 11:11:27 ----D---- C:\Program Files\Common Files\Symantec Shared
2013-08-29 11:11:27 ----A---- C:\Windows\system32\drivers\SYMEVENT64x86.SYS
2013-08-29 11:10:49 ----D---- C:\Windows\system32\drivers\N360x64
2013-08-29 11:10:48 ----D---- C:\Program Files (x86)\Norton 360
2013-08-29 11:10:47 ----D---- C:\ProgramData\Norton
2013-08-29 11:10:19 ----D---- C:\ProgramData\NortonInstaller
2013-08-29 11:10:19 ----D---- C:\Program Files (x86)\NortonInstaller
2013-08-28 16:35:16 ----D---- C:\Users\Tomas\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2013-08-21 00:33:55 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2013-08-20 14:23:42 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-08-15 10:25:11 ----D---- C:\Program Files (x86)\Europa Universalis IV
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 18:55:57 ----A---- C:\Windows\system32\ieui.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\iesetup.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\iernonce.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-14 18:55:56 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-08-14 18:55:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-08-14 18:55:56 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-14 18:55:56 ----A---- C:\Windows\system32\iertutil.dll
2013-08-14 18:55:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-08-14 18:55:55 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-08-14 18:55:55 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-08-14 18:55:55 ----A---- C:\Windows\system32\jscript9.dll
2013-08-14 18:55:55 ----A---- C:\Windows\system32\jscript.dll
2013-08-14 18:55:54 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-08-14 18:55:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-08-14 18:55:54 ----A---- C:\Windows\system32\urlmon.dll
2013-08-14 18:55:54 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-14 18:55:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-08-14 18:55:53 ----A---- C:\Windows\system32\wininet.dll
2013-08-14 18:55:52 ----A---- C:\Windows\system32\ieframe.dll
2013-08-14 18:55:51 ----A---- C:\Windows\system32\mshtml.dll
2013-08-14 18:55:50 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\wintrust.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\crypt32.dll
2013-08-14 04:20:06 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-08-14 04:20:06 ----A---- C:\Windows\system32\tzres.dll
2013-08-14 04:20:00 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2013-08-14 04:20:00 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-14 04:19:59 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2013-08-14 04:19:59 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-14 04:19:58 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-08-14 04:19:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\user.exe
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-08-14 04:19:57 ----A---- C:\Windows\system32\wow64.dll
2013-08-14 04:19:57 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-14 04:19:57 ----A---- C:\Windows\system32\ntdll.dll
2013-08-14 04:19:55 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-14 04:19:55 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-08-13 15:16:12 ----D---- C:\Program Files (x86)\Total War
2013-08-13 15:16:05 ----A---- C:\Windows\IsUninst.exe
2013-08-13 13:03:17 ----D---- C:\Program Files (x86)\Crusader Kings II 1091
2013-08-12 11:18:37 ----D---- C:\Program Files\Steam
2013-08-12 09:26:15 ----D---- C:\Program Files (x86)\Paradox Interactive
2013-08-12 08:41:30 ----D---- C:\Program Files (x86)\MegaCasino
2013-08-07 19:46:17 ----D---- C:\Program Files (x86)\Capcom
2013-07-30 23:20:04 ----D---- C:\Users\Tomas\AppData\Roaming\The Creative Assembly
2013-07-30 16:17:05 ----D---- C:\Users\Tomas\AppData\Roaming\Might & Magic Heroes VI
2013-07-30 16:04:43 ----D---- C:\Program Files (x86)\Ubisoft
======List of files/folders modified in the last 1 month======
2013-08-29 12:49:17 ----D---- C:\Windows\Prefetch
2013-08-29 12:49:15 ----D---- C:\Windows\Temp
2013-08-29 12:46:22 ----D---- C:\Users\Tomas\AppData\Roaming\BitTorrent
2013-08-29 12:44:16 ----RD---- C:\Program Files
2013-08-29 12:27:06 ----D---- C:\Windows\SysWOW64
2013-08-29 12:27:01 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2013-08-29 11:25:01 ----D---- C:\Program Files (x86)\Common Files
2013-08-29 11:12:35 ----D---- C:\Windows\system32\Tasks
2013-08-29 11:11:31 ----SHD---- C:\System Volume Information
2013-08-29 11:11:27 ----D---- C:\Windows\system32\drivers
2013-08-29 11:11:27 ----D---- C:\Program Files\Common Files
2013-08-29 11:10:48 ----RD---- C:\Program Files (x86)
2013-08-29 11:10:47 ----HD---- C:\ProgramData
2013-08-29 10:59:14 ----SHD---- C:\Windows\Installer
2013-08-29 10:58:09 ----D---- C:\Windows\system32\DriverStore
2013-08-29 10:58:09 ----D---- C:\Windows\system32\catroot
2013-08-29 10:58:09 ----D---- C:\Windows\inf
2013-08-29 09:44:31 ----D---- C:\Windows\System32
2013-08-29 09:44:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-29 09:38:34 ----D---- C:\Windows\system32\NDF
2013-08-29 09:35:53 ----D---- C:\ProgramData\NVIDIA
2013-08-29 09:35:00 ----D---- C:\Windows\system32\config
2013-08-28 16:31:12 ----D---- C:\Program Files (x86)\Electronic Arts
2013-08-22 14:21:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-21 00:33:59 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-08-15 11:43:18 ----D---- C:\Windows\Microsoft.NET
2013-08-15 10:32:17 ----RSD---- C:\Windows\assembly
2013-08-15 10:32:00 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-08-15 10:32:00 ----D---- C:\Windows\system32\cs-CZ
2013-08-15 10:30:25 ----D---- C:\Windows\SYSWOW64\en-US
2013-08-15 10:30:25 ----D---- C:\Windows\system32\en-US
2013-08-15 10:29:15 ----AD---- C:\Windows
2013-08-15 10:29:04 ----D---- C:\Windows\winsxs
2013-08-15 10:29:03 ----D---- C:\Windows\system32\catroot2
2013-08-15 08:50:57 ----D---- C:\Program Files (x86)\Heroes of Newerth
2013-08-14 19:35:25 ----D---- C:\Windows\rescache
2013-08-14 19:00:51 ----D---- C:\Windows\Panther
2013-08-14 18:59:05 ----D---- C:\Program Files\Internet Explorer
2013-08-14 18:59:05 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-14 18:59:04 ----D---- C:\Windows\AppPatch
2013-08-14 18:53:28 ----D---- C:\Windows\system32\MRT
2013-08-14 18:52:37 ----D---- C:\Windows\debug
2013-08-14 18:52:32 ----A---- C:\Windows\system32\MRT.exe
2013-08-08 14:39:07 ----D---- C:\Users\Tomas\AppData\Roaming\Media Player Classic
2013-08-07 19:54:47 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-08-07 19:53:19 ----D---- C:\Windows\Logs
2013-08-07 19:46:16 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-08-07 19:45:19 ----D---- C:\Users\Tomas\AppData\Roaming\DAEMON Tools Lite
2013-07-30 13:20:28 ----D---- C:\Program Files (x86)\HTC
2013-07-30 13:10:16 ----D---- C:\ProgramData\Blizzard Entertainment
2013-07-30 13:10:16 ----D---- C:\Games
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-06-24 834544]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\1401000.018\SYMDS64.SYS [2012-07-27 493216]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\1401000.018\SYMEFA64.SYS [2012-08-07 1132192]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [2013-07-15 1393240]
R1 ccSet_N360;Norton 360 Settings Manager; C:\Windows\system32\drivers\N360x64\1401000.018\ccSetx64.sys [2012-08-06 168096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-06-10 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-08-29 484952]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130828.001\IDSvia64.sys [2013-08-28 520280]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 91568]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\1401000.018\SRTSPX64.SYS [2012-05-24 37496]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\1401000.018\Ironx64.SYS [2012-07-27 224416]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\N360x64\1401000.018\SYMNETS.SYS [2012-07-22 432800]
R2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2009-02-11 53816]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2008-11-11 11576]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-07-29 56960]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-07-29 79104]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-08-29 25640]
R3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-08-29 30528]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-03-19 14745600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-17 4734440]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130828.024\ENG64.SYS [2013-08-29 126040]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130828.024\EX64.SYS [2013-08-29 2099288]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-12-19 194488]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-01 535656]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\system32\drivers\N360x64\1401000.018\SRTSP64.SYS [2012-08-10 776352]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-08-29 177312]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
R4 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R4 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R4 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
S1 ArcSec;ArcSec; C:\Windows\system32\drivers\ArcSec.sys []
S1 Ma10.sys;Service for ESI 1010 EWDM; C:\Windows\system32\DRIVERS\Ma10.sys [2009-10-23 69664]
S3 EraserUtilDrv11311;EraserUtilDrv11311; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys [2013-08-29 140376]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2013-06-13 25640]
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-09-25 36928]
S3 Ma10WDM.sys;Service for ESI 1010 WDM; C:\Windows\system32\DRIVERS\Ma10WDM.sys [2009-10-23 43552]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\Windows\system32\drivers\WmHidLo.sys [2010-04-27 36936]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
S4 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2013-01-10 59440]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 DES2 Service;DES2 Service for Energy Saving.; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2011-08-22 57344]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2013-06-28 2470736]
R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe [2012-08-18 143928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-03-15 877856]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-10-08 166912]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2013-06-13 76888]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2013-08-29 214520]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-14 383264]
R2 TinyWall;TinyWall Service; C:\Program Files (x86)\TinyWall\TinyWall.exe [2012-06-22 623272]
R2 wlidsvc;Windows Live ID Sign-in Assistant; c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-28 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-15 1266464]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-21 257416]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-03-19 276248]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-11-17 1030600]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-28 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-08-20 117656]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-06-10 1255736]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Tomas at 2013-08-29 12:49:19
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 648 GB (68%) free of 954 GB
Total RAM: 8109 MB (58% free)
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
winlogon.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\TinyWall\TinyWall.exe"
WLIDSvcM.exe 700
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\alg.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
RPMDaemon.exe
"C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe" -m
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\TinyWall\TinyWall.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
"C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe"
"C:\Users\Tomas\Downloads\gpcl64bit.exe"
"taskhost.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4604.12dadd00.1704666996 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4604 "\\.\pipe\gecko-crash-server-pipe.4604" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --proxy-stub-channel=Flash6060.6C66A550.2696 --host-broker-channel=Flash6060.6C66A550.6742 --host-pid=6060 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe" --channel=2716.002DF4FC.270615662 --proxy-stub-channel=Flash6060.6C66A550.2696 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --host-npapi-version=27 --type=renderer
"C:\Program Files\CCleaner\CCleaner64.exe" /uac
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5472.0.86418310\1843978664" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,9,19,22 --reduce-gpu-sandbox --gpu-vendor-id=0x10de --gpu-device-id=0x1201 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.1422 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.1.385427589\1925605024" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.2.487367765\1575361949" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.3.846190601\1412336697" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.4.277554770\1119097802" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --extension-process --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.5.1661804884\1116349784" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf\10.16.100.504_0\plugins/ChromeApproveTBPlugin.dll" --lang=cs --channel="5472.6.1873707251\866543425" /prefetch:-390060480
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf\10.16.100.504_0\plugins/ConduitChromeApiPlugin.dll" --lang=cs --channel="5472.7.438324998\1319638266" /prefetch:-390060480
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf\10.16.100.504_0\search/plugins/npConduitNewTabPlugin.dll" --lang=cs --channel="5472.8.1396814174\199631434" /prefetch:-390060480
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.16.531760769\1409639323" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.23.1258194344\295361125" /prefetch:673131151
"C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe" /c /a /s UserSession
C:\Windows\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\K-Lite Codec Pack\Media Player Classic\mpc-hc.exe" "C:\Users\Tomas\Downloads\Big Bang theory CZ\2. série\Teorie.velkeho.tresku.S02E01.Paradigma.zkazene.ryby.DVDRip.XviD.cz-iNG.avi"
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.30.1429676765\355718694" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.32.38524345\1331645281" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.33.22178109\1123339475" /prefetch:673131151
"C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="D3D11Experiment/Enabled/ForceCompositingMode/thread/InfiniteCache/No/InstantExtended/Control0 pct:50a m29stable:r1/NewMenuStyle/Compact2/OmniboxStopTimer/UseStopTimer/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictor/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_86/UMA-Uniformity-Trial-10-Percent/group_02/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/group_01/" --renderer-print-preview --enable-threaded-compositing --disable-html-notifications --channel="5472.34.486806853\1484843926" /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\trend micro\Tomas.exe" /silentautolog
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe12_ Global\UsGthrCtrlFltPipeMssGthrPipe12 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 528 532 540 65536 536
"C:\Users\Tomas\Downloads\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.9.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\SysWOW64\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\extensions\
battlefieldheroespatcher@ea.com
SpecialSavings@SpecialSavings.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45d30484-7ded-43d9-957a-d2fd1f046511}]
GBHO.BHO - C:\Windows\system32\mscoree.dll [2010-11-21 444752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\coIEPlg.dll [2012-08-21 497048]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\IPS\IPSBHO.DLL [2012-08-10 387040]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-01-03 449512]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-01-03 155384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1d09c093-f71e-43c3-b948-19316cbd695e} - Smart Recovery 2 - C:\Windows\system32\mscoree.dll [2010-11-21 444752]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\coIEPlg.dll [2012-08-21 497048]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-16 12445288]
"TinyWall Controller"=C:\Program Files (x86)\TinyWall\TinyWall.exe [2012-06-22 623272]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-03-19 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-03-19 398616]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-03-19 439064]
"Ma10PAN.exe"=C:\Windows\system32\Ma10PAN.exe [2009-10-23 896032]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RPMKickstart"=C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2011-03-30 2552320]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-10 218032]
"ISUSPM"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-10 218032]
"BitTorrent"=C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe [2013-04-24 1133392]
"Google Update"=C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-29 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe [2013-04-24 1133392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-04-17 3671872]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-29 116648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2013-06-28 2255184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr]
C:\Windows\Samsung\PanelMgr\ssmmgr.exe [2009-08-14 614400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart File Advisor]
C:\Program Files (x86)\Smart File Advisor\sfa.exe /checkassoc []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Server.lnk]
C:\PROGRA~2\ArcSoft\TOTALM~1\TOTALM~1\TMSERV~1.EXE []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2006-09-10 86960]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2013-06-28 2255184]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"EasyTuneVI"=C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [2007-07-26 20480]
C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Startup
RollerCoaster Tycoon 3 Registration.lnk - C:\Users\Tomas\AppData\Local\Temp\{FA51BA31-1C2F-4367-A6DB-713845DC214D}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-03-19 434688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.ffds"=ff_vfw.dll
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -
======List of files/folders created in the last 1 month======
2013-08-29 12:44:16 ----D---- C:\Program Files\trend micro
2013-08-29 12:44:15 ----D---- C:\rsit
2013-08-29 11:11:27 ----D---- C:\Program Files\Symantec
2013-08-29 11:11:27 ----D---- C:\Program Files\Common Files\Symantec Shared
2013-08-29 11:11:27 ----A---- C:\Windows\system32\drivers\SYMEVENT64x86.SYS
2013-08-29 11:10:49 ----D---- C:\Windows\system32\drivers\N360x64
2013-08-29 11:10:48 ----D---- C:\Program Files (x86)\Norton 360
2013-08-29 11:10:47 ----D---- C:\ProgramData\Norton
2013-08-29 11:10:19 ----D---- C:\ProgramData\NortonInstaller
2013-08-29 11:10:19 ----D---- C:\Program Files (x86)\NortonInstaller
2013-08-28 16:35:16 ----D---- C:\Users\Tomas\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2013-08-21 00:33:55 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2013-08-20 14:23:42 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-08-15 10:25:11 ----D---- C:\Program Files (x86)\Europa Universalis IV
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-08-14 18:55:57 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 18:55:57 ----A---- C:\Windows\system32\ieui.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\iesetup.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\iernonce.dll
2013-08-14 18:55:57 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-14 18:55:56 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-08-14 18:55:56 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-08-14 18:55:56 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-14 18:55:56 ----A---- C:\Windows\system32\iertutil.dll
2013-08-14 18:55:55 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-08-14 18:55:55 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-08-14 18:55:55 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-08-14 18:55:55 ----A---- C:\Windows\system32\jscript9.dll
2013-08-14 18:55:55 ----A---- C:\Windows\system32\jscript.dll
2013-08-14 18:55:54 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-08-14 18:55:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-08-14 18:55:54 ----A---- C:\Windows\system32\urlmon.dll
2013-08-14 18:55:54 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-14 18:55:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-08-14 18:55:53 ----A---- C:\Windows\system32\wininet.dll
2013-08-14 18:55:52 ----A---- C:\Windows\system32\ieframe.dll
2013-08-14 18:55:51 ----A---- C:\Windows\system32\mshtml.dll
2013-08-14 18:55:50 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-08-14 04:20:11 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\wintrust.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-14 04:20:11 ----A---- C:\Windows\system32\crypt32.dll
2013-08-14 04:20:06 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-08-14 04:20:06 ----A---- C:\Windows\system32\tzres.dll
2013-08-14 04:20:00 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2013-08-14 04:20:00 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-14 04:19:59 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2013-08-14 04:19:59 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-14 04:19:58 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-08-14 04:19:58 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\user.exe
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-08-14 04:19:57 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-08-14 04:19:57 ----A---- C:\Windows\system32\wow64.dll
2013-08-14 04:19:57 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-14 04:19:57 ----A---- C:\Windows\system32\ntdll.dll
2013-08-14 04:19:55 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-14 04:19:55 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-08-13 15:16:12 ----D---- C:\Program Files (x86)\Total War
2013-08-13 15:16:05 ----A---- C:\Windows\IsUninst.exe
2013-08-13 13:03:17 ----D---- C:\Program Files (x86)\Crusader Kings II 1091
2013-08-12 11:18:37 ----D---- C:\Program Files\Steam
2013-08-12 09:26:15 ----D---- C:\Program Files (x86)\Paradox Interactive
2013-08-12 08:41:30 ----D---- C:\Program Files (x86)\MegaCasino
2013-08-07 19:46:17 ----D---- C:\Program Files (x86)\Capcom
2013-07-30 23:20:04 ----D---- C:\Users\Tomas\AppData\Roaming\The Creative Assembly
2013-07-30 16:17:05 ----D---- C:\Users\Tomas\AppData\Roaming\Might & Magic Heroes VI
2013-07-30 16:04:43 ----D---- C:\Program Files (x86)\Ubisoft
======List of files/folders modified in the last 1 month======
2013-08-29 12:49:17 ----D---- C:\Windows\Prefetch
2013-08-29 12:49:15 ----D---- C:\Windows\Temp
2013-08-29 12:46:22 ----D---- C:\Users\Tomas\AppData\Roaming\BitTorrent
2013-08-29 12:44:16 ----RD---- C:\Program Files
2013-08-29 12:27:06 ----D---- C:\Windows\SysWOW64
2013-08-29 12:27:01 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2013-08-29 11:25:01 ----D---- C:\Program Files (x86)\Common Files
2013-08-29 11:12:35 ----D---- C:\Windows\system32\Tasks
2013-08-29 11:11:31 ----SHD---- C:\System Volume Information
2013-08-29 11:11:27 ----D---- C:\Windows\system32\drivers
2013-08-29 11:11:27 ----D---- C:\Program Files\Common Files
2013-08-29 11:10:48 ----RD---- C:\Program Files (x86)
2013-08-29 11:10:47 ----HD---- C:\ProgramData
2013-08-29 10:59:14 ----SHD---- C:\Windows\Installer
2013-08-29 10:58:09 ----D---- C:\Windows\system32\DriverStore
2013-08-29 10:58:09 ----D---- C:\Windows\system32\catroot
2013-08-29 10:58:09 ----D---- C:\Windows\inf
2013-08-29 09:44:31 ----D---- C:\Windows\System32
2013-08-29 09:44:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-29 09:38:34 ----D---- C:\Windows\system32\NDF
2013-08-29 09:35:53 ----D---- C:\ProgramData\NVIDIA
2013-08-29 09:35:00 ----D---- C:\Windows\system32\config
2013-08-28 16:31:12 ----D---- C:\Program Files (x86)\Electronic Arts
2013-08-22 14:21:04 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-21 00:33:59 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-08-15 11:43:18 ----D---- C:\Windows\Microsoft.NET
2013-08-15 10:32:17 ----RSD---- C:\Windows\assembly
2013-08-15 10:32:00 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-08-15 10:32:00 ----D---- C:\Windows\system32\cs-CZ
2013-08-15 10:30:25 ----D---- C:\Windows\SYSWOW64\en-US
2013-08-15 10:30:25 ----D---- C:\Windows\system32\en-US
2013-08-15 10:29:15 ----AD---- C:\Windows
2013-08-15 10:29:04 ----D---- C:\Windows\winsxs
2013-08-15 10:29:03 ----D---- C:\Windows\system32\catroot2
2013-08-15 08:50:57 ----D---- C:\Program Files (x86)\Heroes of Newerth
2013-08-14 19:35:25 ----D---- C:\Windows\rescache
2013-08-14 19:00:51 ----D---- C:\Windows\Panther
2013-08-14 18:59:05 ----D---- C:\Program Files\Internet Explorer
2013-08-14 18:59:05 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-14 18:59:04 ----D---- C:\Windows\AppPatch
2013-08-14 18:53:28 ----D---- C:\Windows\system32\MRT
2013-08-14 18:52:37 ----D---- C:\Windows\debug
2013-08-14 18:52:32 ----A---- C:\Windows\system32\MRT.exe
2013-08-08 14:39:07 ----D---- C:\Users\Tomas\AppData\Roaming\Media Player Classic
2013-08-07 19:54:47 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-08-07 19:53:19 ----D---- C:\Windows\Logs
2013-08-07 19:46:16 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-08-07 19:45:19 ----D---- C:\Users\Tomas\AppData\Roaming\DAEMON Tools Lite
2013-07-30 13:20:28 ----D---- C:\Program Files (x86)\HTC
2013-07-30 13:10:16 ----D---- C:\ProgramData\Blizzard Entertainment
2013-07-30 13:10:16 ----D---- C:\Games
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-06-24 834544]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\1401000.018\SYMDS64.SYS [2012-07-27 493216]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\1401000.018\SYMEFA64.SYS [2012-08-07 1132192]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2011-01-10 21104]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [2013-07-15 1393240]
R1 ccSet_N360;Norton 360 Settings Manager; C:\Windows\system32\drivers\N360x64\1401000.018\ccSetx64.sys [2012-08-06 168096]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-06-10 283200]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-08-29 484952]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130828.001\IDSvia64.sys [2013-08-28 520280]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2010-04-12 91568]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\1401000.018\SRTSPX64.SYS [2012-05-24 37496]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\1401000.018\Ironx64.SYS [2012-07-27 224416]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\N360x64\1401000.018\SYMNETS.SYS [2012-07-22 432800]
R2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2009-02-11 53816]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2008-11-11 11576]
R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver; C:\Windows\System32\Drivers\EtronHub3.sys [2011-07-29 56960]
R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver; C:\Windows\System32\Drivers\EtronXHCI.sys [2011-07-29 79104]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2013-08-29 25640]
R3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2013-08-29 30528]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-03-19 14745600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-17 4734440]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-12-06 331264]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130828.024\ENG64.SYS [2013-08-29 126040]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130828.024\EX64.SYS [2013-08-29 2099288]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2012-12-19 194488]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-01 535656]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\system32\drivers\N360x64\1401000.018\SRTSP64.SYS [2012-08-10 776352]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-08-29 177312]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2010-04-27 26440]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2010-04-27 77512]
R4 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R4 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R4 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
S1 ArcSec;ArcSec; C:\Windows\system32\drivers\ArcSec.sys []
S1 Ma10.sys;Service for ESI 1010 EWDM; C:\Windows\system32\DRIVERS\Ma10.sys [2009-10-23 69664]
S3 EraserUtilDrv11311;EraserUtilDrv11311; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11311.sys [2013-08-29 140376]
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2013-06-13 25640]
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-09-25 36928]
S3 Ma10WDM.sys;Service for ESI 1010 WDM; C:\Windows\system32\DRIVERS\Ma10WDM.sys [2009-10-23 43552]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2010-04-27 43976]
S3 WmHidLo;Logitech Gaming USB Filter Driver; C:\Windows\system32\drivers\WmHidLo.sys [2010-04-27 36936]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2010-04-27 16200]
S4 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2013-01-10 59440]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 DES2 Service;DES2 Service for Energy Saving.; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [2011-08-22 57344]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2013-06-28 2470736]
R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\20.1.0.24\ccSvcHst.exe [2012-08-18 143928]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-03-15 877856]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-10-08 166912]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2013-06-13 76888]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2013-08-29 214520]
R2 Smart TimeLock;Smart TimeLock Service; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [2009-10-13 114688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-03-14 383264]
R2 TinyWall;TinyWall Service; C:\Program Files (x86)\TinyWall\TinyWall.exe [2012-06-22 623272]
R2 wlidsvc;Windows Live ID Sign-in Assistant; c:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-28 116648]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-03-15 1266464]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-21 257416]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-03-19 276248]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-11-17 1030600]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-06-28 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-08-20 117656]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-06-10 1255736]
-----------------EOF-----------------
Re: zpomalený internet
jestli me tu teda muze nekdo prosim pomoct kdyz vidim ze u ostatnich prispevku se to deje
Re: zpomalený internet
Zdravim
A jestli si teda jako pockate, tak vam tu mozna nekdo pomuze. Mate tu zadost ani ne hodinu a uz jste netrpelivy. My jsme tu ZDARMA a ve svem VOLNEM case a kolem poledne je jaksi vetsina z nas v praci...
Takze si bud pockejte nebo si zaplatte servis a toho se muzete ptat klidne co pet minut jestli vam teda pomuze a jestli uz to ma...
Zde si bud pockate nebo mate holt smulu. my tu pomoci muzeme, nikolik musime. A pokud se vam to nelibi, nikdo vas tu nenuti byt, tlacitko Odhlasit mate vlevo nahore....
Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
A jestli si teda jako pockate, tak vam tu mozna nekdo pomuze. Mate tu zadost ani ne hodinu a uz jste netrpelivy. My jsme tu ZDARMA a ve svem VOLNEM case a kolem poledne je jaksi vetsina z nas v praci...
Takze si bud pockejte nebo si zaplatte servis a toho se muzete ptat klidne co pet minut jestli vam teda pomuze a jestli uz to ma...
Zde si bud pockate nebo mate holt smulu. my tu pomoci muzeme, nikolik musime. A pokud se vam to nelibi, nikdo vas tu nenuti byt, tlacitko Odhlasit mate vlevo nahore....
- Provedte aktualizaci
- Provedte uplny sken - nic nemazte

- MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
Re: zpomalený internet
nebylo to mysleno spatne jen kdyz sem videl ze si to kazdy zobrazil tak sem nevedel jestli sem neporusil treba nejaka pravidla fora ze me nikdo neodepsal , vzdy kdyz sem tu neco resil tak sem nemel sebemensi problem treba jen nekdo napsal ze se na to pozdeji podiva nebo tak a nechal sem to byt protoze sem aspon vedel ze se o tom problemu vi, tot vse 
Re: zpomalený internet
A proto jste si zalozil jeste dalsi dva thready aby se o vas poraaaadne vedelo ze
Kdybyste porusil nejake pravidla fora, tak vezte, ze aktivni moderatori, kteri jsou temer neustale online, by ihned reagovali...
Pockam si tedy na vysledek z MBAMu...
Kdybyste porusil nejake pravidla fora, tak vezte, ze aktivni moderatori, kteri jsou temer neustale online, by ihned reagovali...
Pockam si tedy na vysledek z MBAMu...
Re: zpomalený internet
Ikdyz to nebylo asi spravne reseni tak ano, omlouvam se nebude se to opakovat. ted provadim scan a velice si vazim vasi pomoci
Re: zpomalený internet
No to opravdu nebylo a jak jste si mohl vsimnout, temata ihned zmizela, jelikoz to bylo poruseni pravidel fora a kolegove MODi zareagovali
Pravidla fora napsal:4. Na svůj problém si založte jen jedno téma - založením témat do více sekcí řešení neuspíší, ba naopak problém znepřehledníte a jen přidáte práci rádcům a moderátorům. Taktéž nevkládejte žádost o pomoc do cizího tématu, jen tím uděláte rádci v tématu guláš.
Re: zpomalený internet
dobrá beru navedomí
) jen jedna otázečka jeste jak dlouho ten scan tak trvá? jestli se dá vubec urcit nejaká priblizná doba 
Re: zpomalený internet
Doba skenu nelze urcit, zalezi na vykonu procesoru, velikosti disku a mnozstvi souboru, kterymi se MBAM musi prodrat...
Re: zpomalený internet
zde vkladam vysledek testu
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.08.29.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Tomas :: TOM [administrátor]
Ochrana: Povolena
29.8.2013 19:38:58
MBAM-log-2013-08-29 (20-53-06).txt
Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 490817
Uplynulý čas: 1 hodin, 12 minut, 50 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D6BDDFEF-534E-FFCF-5F11-03F05D8D600C} (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\BabylonToolbar (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 8
C:\ProgramData\IBUpdaterService (PUP.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\12E0DCEE4A234FD7A3A40EE6337DA6F8 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\38E9B4B8D46F4D4683AB17D792B1F8D3 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\OpenCandy_12E0DCEE4A234FD7A3A40EE6337DA6F8 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\OpenCandy_38E9B4B8D46F4D4683AB17D792B1F8D3 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 8
C:\ProgramData\InstallMate\{E11AE922-9232-4EF7-AC1C-DA103AF9CBD4}\Setup.exe (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\{E11AE922-9232-4EF7-AC1C-DA103AF9CBD4}\TsuDll.dll (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout\filescout.exe (Trojan.PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\IBUpdaterService\repository.xml (PUP.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\38E9B4B8D46F4D4683AB17D792B1F8D3\TuneUpUtilities2013-2200329_cs-CZ.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout\filescout.exe (PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout\uninst.exe (PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.08.29.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Tomas :: TOM [administrátor]
Ochrana: Povolena
29.8.2013 19:38:58
MBAM-log-2013-08-29 (20-53-06).txt
Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 490817
Uplynulý čas: 1 hodin, 12 minut, 50 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D6BDDFEF-534E-FFCF-5F11-03F05D8D600C} (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\BabylonToolbar (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 8
C:\ProgramData\IBUpdaterService (PUP.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\Babylon (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\12E0DCEE4A234FD7A3A40EE6337DA6F8 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\38E9B4B8D46F4D4683AB17D792B1F8D3 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\OpenCandy_12E0DCEE4A234FD7A3A40EE6337DA6F8 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\OpenCandy_38E9B4B8D46F4D4683AB17D792B1F8D3 (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 8
C:\ProgramData\InstallMate\{E11AE922-9232-4EF7-AC1C-DA103AF9CBD4}\Setup.exe (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\{E11AE922-9232-4EF7-AC1C-DA103AF9CBD4}\TsuDll.dll (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout\filescout.exe (Trojan.PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\IBUpdaterService\repository.xml (PUP.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\Babylon\log_file.txt (PUP.Optional.Babylon.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\OpenCandy\38E9B4B8D46F4D4683AB17D792B1F8D3\TuneUpUtilities2013-2200329_cs-CZ.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout\filescout.exe (PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
C:\Users\Tomas\AppData\Roaming\File Scout\uninst.exe (PUP.Optional.FileScout.A) -> Nebyla provedena žádná instrukce.
Re: zpomalený internet
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: zpomalený internet
ADWcleaner
# AdwCleaner v3.001 - Report created 29/08/2013 at 21:56:06
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Tomas - TOM
# Running from : C:\Users\Tomas\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\StarApp
Folder Deleted : C:\Users\Tomas\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Users\Tomas\AppData\Roaming\StatusWinks
Folder Deleted : C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\Extensions\SpecialSavings@SpecialSavings.com
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Deleted : C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\ICQ\ICQToolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v23.0.1 (cs)
[ File : C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : homepage
*************************
AdwCleaner[R0].txt - [2050 octets] - [29/08/2013 21:55:41]
AdwCleaner[S0].txt - [1899 octets] - [29/08/2013 21:56:06]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1959 octets] ##########
JUNKWARE
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 7 Home Premium x64
Ran by Tomas on źt 29.08.2013 at 21:42:42,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1444486529-4172279158-2348300707-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babylontoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mybabylontb_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\uniblue
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\splashtop"
Successfully deleted: [Folder] "C:\Users\Tomas\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\Tomas\AppData\Roaming\specialsavings"
Successfully deleted: [Folder] "C:\Users\Tomas\AppData\Roaming\splashtop"
Successfully deleted: [Folder] "C:\Users\Tomas\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Tomas\appdata\local\tempdir"
Successfully deleted: [Folder] "C:\Users\Tomas\appdata\locallow\conduit"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\statuswinks@statuswinks
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\statuswinks@statuswinks
Emptied folder: C:\Users\Tomas\AppData\Roaming\mozilla\firefox\profiles\b71zi4jy.default\minidumps [2 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Tomas\appdata\local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 29.08.2013 at 21:53:02,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.001 - Report created 29/08/2013 at 21:56:06
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Tomas - TOM
# Running from : C:\Users\Tomas\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\ICQ\ICQToolbar
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\StarApp
Folder Deleted : C:\Users\Tomas\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Users\Tomas\AppData\Roaming\StatusWinks
Folder Deleted : C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\Extensions\SpecialSavings@SpecialSavings.com
File Deleted : C:\Windows\System32\roboot64.exe
File Deleted : C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Deleted : C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C3110516-8EFC-49D6-8B72-69354F332062}
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\ICQ\ICQToolbar
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v23.0.1 (cs)
[ File : C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\prefs.js ]
-\\ Google Chrome v
[ File : C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : homepage
*************************
AdwCleaner[R0].txt - [2050 octets] - [29/08/2013 21:55:41]
AdwCleaner[S0].txt - [1899 octets] - [29/08/2013 21:56:06]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1959 octets] ##########
JUNKWARE
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.5 (08.28.2013:1)
OS: Windows 7 Home Premium x64
Ran by Tomas on źt 29.08.2013 at 21:42:42,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1444486529-4172279158-2348300707-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babylontoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mybabylontb_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\uniblue
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\splashtop"
Successfully deleted: [Folder] "C:\Users\Tomas\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\Tomas\AppData\Roaming\specialsavings"
Successfully deleted: [Folder] "C:\Users\Tomas\AppData\Roaming\splashtop"
Successfully deleted: [Folder] "C:\Users\Tomas\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Tomas\appdata\local\tempdir"
Successfully deleted: [Folder] "C:\Users\Tomas\appdata\locallow\conduit"
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\statuswinks@statuswinks
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\statuswinks@statuswinks
Emptied folder: C:\Users\Tomas\AppData\Roaming\mozilla\firefox\profiles\b71zi4jy.default\minidumps [2 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Tomas\appdata\local\Google\Chrome\User Data\Default\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\dknkjnkhedbanphkkpbpcgoblmkbfhlf
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 29.08.2013 at 21:53:02,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: zpomalený internet
Poprosim o spusteni nasledujiciho
Aplikace ke stažení:
Po stažení FRSTLauncher spustte, objevi se mozna varovani od antiviru, ignorujte a nechte FRSTL spustit
Následně dojde ke stažení FRST a inicializaci
- Po spuštění FRST odsouhlasíme licenční podmínky kliknutím na Ano.
- Dooznačíme položku Addition.txt - viz obrázek.

- Klikneme na tlačítko Scan čímž spustíme skenování.
- Počkáme na dokončení skenování FRST a vytvoření doplňkových informací naší nástavbou.
- Otevře se nám textový soubor FRST.txt, což je požadovaný log a jehož obsah vložíme do svého tématu na fóru.
- Po uzavření logu se FRSTLauncher.exe ukončí a na ploše nám zbyde utilta FRST a dva logy FRST.txt a Addition.txt - nic z toho zatím nemažeme.
Re: zpomalený internet
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Tomas (administrator) on 29-08-2013 22:18:00
Running from C:\Users\Tomas\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Károly Pados) C:\Program Files (x86)\TinyWall\TinyWall.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
() C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Károly Pados) C:\Program Files (x86)\TinyWall\TinyWall.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-16] (Realtek Semiconductor)
HKLM\...\Run: [TinyWall Controller] - C:\Program Files (x86)\TinyWall\TinyWall.exe [623272 2012-06-22] (Károly Pados)
HKLM\...\Run: [Ma10PAN.exe] - C:\Windows\system32\Ma10PAN.exe [896032 2009-10-23] ()
HKLM\...\RunOnce: [RPMKickstart] - C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.)
HKLM-x32\...\RunOnce: [EasyTuneVI] - C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [20480 2007-07-26] ()
HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [218032 2006-09-10] (Macrovision Corporation)
HKCU\...\Run: [ISUSPM] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-10] (Macrovision Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-29] (Google Inc.)
MountPoints2: F - F:\Setup.exe
MountPoints2: I - I:\HTC_Sync_Manager_PC.exe
MountPoints2: {8ffd6ec6-b272-11e1-93af-806e6f6e6963} - E:\autorun.exe
MountPoints2: {ce73b416-baa6-11e1-b103-50e549e91cbd} - G:\Autorun.exe
HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [86960 2006-09-10] (Macrovision Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3830224 2013-05-16] (Safer-Networking Ltd.)
HKU\UpdatusUser\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [218032 2006-09-10] (Macrovision Corporation)
HKU\UpdatusUser\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [250504 2013-03-15] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [205184 2013-03-15] (NVIDIA Corporation)
Startup: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Startup\RollerCoaster Tycoon 3 Registration.lnk
ShortcutTarget: RollerCoaster Tycoon 3 Registration.lnk -> C:\Users\Tomas\AppData\Local\Temp\{FA51BA31-1C2F-4367-A6DB-713845DC214D}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: localhost:21320
SearchScopes: HKCU - {32C23A45-0E2A-4fb0-A515-CB231205D3BA} URL = http://www.bing.com/search?q={searchTer ... R1&pc=SPLH
SearchScopes: HKCU - {75FD6C1B-B415-4f5f-9861-DBCAD37EB673} URL = http://uk.search.yahoo.com/search?p={se ... ype=IEBDSV
BHO: GBHO.BHO - {45d30484-7ded-43d9-957a-d2fd1f046511} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/f ... wflash.cab
Handler: ftp - No CLSID Value -
Handler: http - No CLSID Value -
Handler: https - No CLSID Value -
Handler-x32: ftp - No CLSID Value -
Handler-x32: http - No CLSID Value -
Handler-x32: https - No CLSID Value -
FireFox:
========
FF ProfilePath: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-cz.xml
FF Extension: Smiley Bar for Facebook - C:\Users\Tomas\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
FF Extension: Battlefield Heroes Updater - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\Extensions\battlefieldheroespatcher@ea.com
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\29.0.1547.57\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Extension: (YouTube) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Flash Player V15.0) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gompblemgafijijmlgbaepcijfgfgljf\13.5_0
CHR Extension: (Norton Identity Protection) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0
CHR Extension: (CnC TA Script Collection) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmhpmdclklpgfcpoiomjofgfagenmgeo\1.2.8.46_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [bfcpnihmbfoaeoakalclfalkdepgiaje] - C:\Users\Tomas\AppData\Roaming\SpecialSavings\SpecialSavings.crx
CHR HKLM-x32\...\Chrome\Extension: [hgojaaaiddhmiiakpejiklijbalpckih] - C:\Users\Tomas\AppData\Roaming\StatusWinks\statuswinks.crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\Exts\Chrome.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [57344 2011-08-22] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-06-13] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.)
R2 TinyWall; C:\Program Files (x86)\TinyWall\TinyWall.exe [623272 2012-06-22] (Károly Pados)
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] ()
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-07-15] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-07-15] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-02-11] (Samsung Electronics Co., Ltd.)
R2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-02-11] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-06-10] (DT Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-29] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-29] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-29] (Symantec Corporation)
S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-13] (Windows (R) Server 2003 DDK provider)
S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-13] (Windows (R) Server 2003 DDK provider)
R3 gdrv; C:\Windows\gdrv.sys [25640 2013-08-29] (Windows (R) Server 2003 DDK provider)
R3 gdrv; C:\Windows\gdrv.sys [25640 2013-08-29] (Windows (R) Server 2003 DDK provider)
R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-08-29] ()
R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-08-29] ()
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-28] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-28] (Symantec Corporation)
S1 Ma10.sys; C:\Windows\System32\DRIVERS\Ma10.sys [69664 2009-10-23] ()
S3 Ma10WDM.sys; C:\Windows\System32\DRIVERS\Ma10WDM.sys [43552 2009-10-23] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-06-24] ()
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-08-29] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
S1 ArcSec; system32\drivers\ArcSec.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 22:16 - 2013-08-29 22:16 - 00000000 ____D C:\Users\Tomas\AppData\Local\qb1200AB.2A
2013-08-29 22:16 - 2013-08-27 21:11 - 01579080 _____ (Farbar) C:\Users\Tomas\Desktop\FRST64.exe
2013-08-29 22:05 - 2013-08-29 22:05 - 240353280 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi (1).crdownload
2013-08-29 21:55 - 2013-08-29 21:56 - 00000000 ____D C:\AdwCleaner
2013-08-29 21:43 - 2013-08-29 21:44 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360
2013-08-29 21:42 - 2013-08-29 21:42 - 01023533 _____ (Thisisu) C:\Users\Tomas\Downloads\JRT.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00994642 _____ C:\Users\Tomas\Downloads\adwcleaner.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 21:34 - 2013-08-29 21:36 - 41189376 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi.crdownload
2013-08-29 20:57 - 2013-08-29 21:19 - 399572992 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e04.avi
2013-08-29 19:36 - 2013-08-29 19:36 - 00001119 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 19:36 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-29 19:35 - 2013-08-29 19:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 16:13 - 2013-08-29 16:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-29 16:13 - 2013-08-29 16:13 - 00001389 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-08-29 16:13 - 2013-08-29 16:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-29 16:13 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-08-29 16:12 - 2013-08-29 16:13 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-29 16:09 - 2013-08-29 16:11 - 36271144 _____ (Safer-Networking Ltd. ) C:\Users\Tomas\Downloads\spybot-2.1.exe
2013-08-29 15:20 - 2013-08-29 15:51 - 398563328 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e03.avi
2013-08-29 15:06 - 2013-08-29 15:17 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\ICQ-Profile
2013-08-29 15:02 - 2013-08-29 15:04 - 38466186 _____ C:\Users\Tomas\Downloads\install_icq8.exe
2013-08-29 14:07 - 2013-08-29 14:29 - 399538176 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e02.avi
2013-08-29 13:11 - 2013-08-29 21:57 - 00000224 _____ C:\Windows\setupact.log
2013-08-29 13:11 - 2013-08-29 13:11 - 00000000 _____ C:\Windows\setuperr.log
2013-08-29 13:10 - 2013-08-29 21:38 - 00006986 _____ C:\Windows\PFRO.log
2013-08-29 12:44 - 2013-08-29 12:49 - 00000000 ____D C:\rsit
2013-08-29 12:44 - 2013-08-29 12:49 - 00000000 ____D C:\Program Files\trend micro
2013-08-29 12:43 - 2013-08-29 12:43 - 00935175 _____ C:\Users\Tomas\Downloads\RSITx64.exe
2013-08-29 11:11 - 2013-08-29 21:38 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-08-29 11:11 - 2013-08-29 20:09 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-08-29 11:11 - 2013-08-29 20:09 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Symantec
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-08-29 11:10 - 2013-08-29 21:38 - 00000000 ____D C:\Windows\system32\Drivers\N360x64
2013-08-29 11:10 - 2013-08-29 11:11 - 00000000 ____D C:\ProgramData\Norton
2013-08-29 11:10 - 2013-08-29 11:10 - 00000000 ____D C:\Program Files (x86)\Norton 360
2013-08-28 16:35 - 2013-08-28 16:42 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2013-08-21 00:33 - 2013-08-21 00:33 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-08-20 14:23 - 2013-08-20 14:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 19:11 - 2013-08-16 19:11 - 00017659 _____ C:\Users\Tomas\Desktop\kkkk.srt
2013-08-15 10:25 - 2013-08-15 10:26 - 00000000 ____D C:\Program Files (x86)\Europa Universalis IV
2013-08-15 10:22 - 2013-01-01 01:00 - 670990336 _____ C:\Users\Tomas\Desktop\flt-euiv.iso
2013-08-14 18:55 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 18:55 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 18:55 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 18:55 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 18:55 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 18:55 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 18:55 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 18:55 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 18:55 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 18:55 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 18:55 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 18:55 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 04:20 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 04:20 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 04:20 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 04:20 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 04:20 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 04:20 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 04:20 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 04:20 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 04:20 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 04:20 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 04:20 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 04:20 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 04:19 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 04:19 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 04:19 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 04:19 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 04:19 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 04:19 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 04:19 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 04:19 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 04:19 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 04:19 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 04:19 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 04:19 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 04:19 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 04:19 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 04:19 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-13 20:37 - 2013-08-13 20:48 - 00000000 ____D C:\Users\Tomas\Downloads\Europa_Universalis_IV-FLT
2013-08-13 15:16 - 2013-08-13 15:16 - 00000000 ____D C:\Program Files (x86)\Total War
2013-08-13 15:16 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2013-08-12 11:19 - 2013-08-15 10:35 - 00000000 ____D C:\Users\Tomas\Documents\Paradox Interactive
2013-08-12 11:18 - 2013-08-12 11:18 - 00000000 ____D C:\Program Files\Steam
2013-08-12 09:26 - 2013-08-12 11:59 - 00000000 ____D C:\Program Files (x86)\Paradox Interactive
2013-08-12 08:41 - 2013-08-12 08:59 - 00000000 ____D C:\Program Files (x86)\MegaCasino
2013-07-30 16:17 - 2013-07-30 16:28 - 00000000 ____D C:\Users\Tomas\AppData\Local\Ubisoft Game Launcher
2013-07-30 16:04 - 2013-07-30 16:10 - 00000000 ____D C:\Program Files (x86)\Ubisoft
==================== One Month Modified Files and Folders =======
2013-08-29 22:17 - 2013-08-29 22:17 - 00000000 ____D C:\FRST
2013-08-29 22:16 - 2013-08-29 22:16 - 00000000 ____D C:\Users\Tomas\AppData\Local\qb1200AB.2A
2013-08-29 22:06 - 2011-04-12 10:34 - 00640116 _____ C:\Windows\system32\perfh005.dat
2013-08-29 22:06 - 2011-04-12 10:34 - 00127028 _____ C:\Windows\system32\perfc005.dat
2013-08-29 22:06 - 2009-07-14 07:13 - 01498176 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-29 22:05 - 2013-08-29 22:05 - 240353280 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi (1).crdownload
2013-08-29 22:05 - 2009-07-14 06:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-29 22:05 - 2009-07-14 06:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-29 22:04 - 2013-04-11 20:24 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\BitTorrent
2013-08-29 22:00 - 2012-07-01 10:30 - 01748759 _____ C:\Windows\WindowsUpdate.log
2013-08-29 21:58 - 2013-06-14 08:48 - 00000004 _____ C:\Windows\SysWOW64\GVTunner.ref
2013-08-29 21:58 - 2012-06-22 22:58 - 00000000 ____D C:\Users\Tomas\AppData\Local\LogMeIn Hamachi
2013-08-29 21:58 - 2012-06-09 23:02 - 00030528 _____ C:\Windows\GVTDrv64.sys
2013-08-29 21:57 - 2013-08-29 13:11 - 00000224 _____ C:\Windows\setupact.log
2013-08-29 21:57 - 2013-04-19 22:00 - 00000430 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-08-29 21:57 - 2012-06-28 13:16 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-29 21:57 - 2012-06-09 23:20 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-29 21:57 - 2012-06-09 23:00 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-08-29 21:57 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-29 21:56 - 2013-08-29 21:55 - 00000000 ____D C:\AdwCleaner
2013-08-29 21:56 - 2012-08-18 05:57 - 00000000 ____D C:\ProgramData\ICQ
2013-08-29 21:52 - 2012-06-28 13:16 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-29 21:44 - 2013-08-29 21:43 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360
2013-08-29 21:42 - 2013-08-29 21:42 - 01023533 _____ (Thisisu) C:\Users\Tomas\Downloads\JRT.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00994642 _____ C:\Users\Tomas\Downloads\adwcleaner.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 21:38 - 2013-08-29 13:10 - 00006986 _____ C:\Windows\PFRO.log
2013-08-29 21:38 - 2013-08-29 11:11 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-08-29 21:38 - 2013-08-29 11:10 - 00000000 ____D C:\Windows\system32\Drivers\N360x64
2013-08-29 21:36 - 2013-08-29 21:34 - 41189376 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi.crdownload
2013-08-29 21:33 - 2012-06-09 23:10 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 21:19 - 2013-08-29 20:57 - 399572992 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e04.avi
2013-08-29 20:38 - 2012-07-29 20:57 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job
2013-08-29 20:09 - 2013-08-29 11:11 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-08-29 20:09 - 2013-08-29 11:11 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-08-29 19:36 - 2013-08-29 19:36 - 00001119 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 19:35 - 2013-08-29 19:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 18:09 - 2013-06-12 22:17 - 00214520 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-08-29 18:09 - 2013-01-06 13:57 - 00214520 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-08-29 18:09 - 2012-08-07 18:03 - 00214520 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-08-29 16:46 - 2012-06-10 12:33 - 00000000 ____D C:\Users\Tomas\Desktop\Games
2013-08-29 16:14 - 2013-08-29 16:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-29 16:13 - 2013-08-29 16:13 - 00001389 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-08-29 16:13 - 2013-08-29 16:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-29 16:13 - 2013-08-29 16:12 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-29 16:11 - 2013-08-29 16:09 - 36271144 _____ (Safer-Networking Ltd. ) C:\Users\Tomas\Downloads\spybot-2.1.exe
2013-08-29 15:51 - 2013-08-29 15:20 - 398563328 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e03.avi
2013-08-29 15:17 - 2013-08-29 15:06 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\ICQ-Profile
2013-08-29 15:04 - 2013-08-29 15:02 - 38466186 _____ C:\Users\Tomas\Downloads\install_icq8.exe
2013-08-29 14:29 - 2013-08-29 14:07 - 399538176 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e02.avi
2013-08-29 14:02 - 2012-06-10 21:45 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Media Player Classic
2013-08-29 13:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-29 13:11 - 2013-08-29 13:11 - 00000000 _____ C:\Windows\setuperr.log
2013-08-29 13:07 - 2012-06-10 11:12 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\DAEMON Tools Lite
2013-08-29 13:06 - 2012-06-09 23:34 - 00000000 ____D C:\Windows\Panther
2013-08-29 13:02 - 2012-06-09 22:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-29 12:49 - 2013-08-29 12:44 - 00000000 ____D C:\rsit
2013-08-29 12:49 - 2013-08-29 12:44 - 00000000 ____D C:\Program Files\trend micro
2013-08-29 12:43 - 2013-08-29 12:43 - 00935175 _____ C:\Users\Tomas\Downloads\RSITx64.exe
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Symantec
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-08-29 11:11 - 2013-08-29 11:10 - 00000000 ____D C:\ProgramData\Norton
2013-08-29 11:10 - 2013-08-29 11:10 - 00000000 ____D C:\Program Files (x86)\Norton 360
2013-08-29 04:38 - 2012-07-29 20:57 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job
2013-08-28 16:42 - 2013-08-28 16:35 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2013-08-28 16:31 - 2013-07-21 19:53 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-08-27 21:11 - 2013-08-29 22:16 - 01579080 _____ (Farbar) C:\Users\Tomas\Desktop\FRST64.exe
2013-08-22 14:21 - 2012-09-10 02:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-21 14:49 - 2012-07-29 20:59 - 00002371 _____ C:\Users\Tomas\Desktop\Google Chrome.lnk
2013-08-21 00:34 - 2012-06-09 23:10 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-21 00:33 - 2013-08-21 00:33 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-08-21 00:33 - 2012-06-09 23:10 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-21 00:33 - 2012-06-09 23:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-20 14:23 - 2013-08-20 14:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 19:11 - 2013-08-16 19:11 - 00017659 _____ C:\Users\Tomas\Desktop\kkkk.srt
2013-08-15 10:35 - 2013-08-12 11:19 - 00000000 ____D C:\Users\Tomas\Documents\Paradox Interactive
2013-08-15 10:26 - 2013-08-15 10:25 - 00000000 ____D C:\Program Files (x86)\Europa Universalis IV
2013-08-15 10:24 - 2012-11-21 01:12 - 00000000 ____D C:\Users\Tomas\Desktop\wow
2013-08-15 08:50 - 2013-07-29 19:09 - 00000000 ____D C:\Program Files (x86)\Heroes of Newerth
2013-08-14 19:35 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-14 18:53 - 2013-07-27 03:03 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 18:52 - 2012-06-10 04:41 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-13 20:48 - 2013-08-13 20:37 - 00000000 ____D C:\Users\Tomas\Downloads\Europa_Universalis_IV-FLT
2013-08-13 15:29 - 2012-06-12 11:52 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-08-13 15:16 - 2013-08-13 15:16 - 00000000 ____D C:\Program Files (x86)\Total War
2013-08-12 17:54 - 2012-06-11 10:36 - 00000072 _____ C:\Users\Public\LMDebug.log
2013-08-12 11:59 - 2013-08-12 09:26 - 00000000 ____D C:\Program Files (x86)\Paradox Interactive
2013-08-12 11:18 - 2013-08-12 11:18 - 00000000 ____D C:\Program Files\Steam
2013-08-12 08:59 - 2013-08-12 08:41 - 00000000 ____D C:\Program Files (x86)\MegaCasino
2013-08-07 19:54 - 2012-09-28 22:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-07-31 07:20 - 2012-06-09 22:45 - 00000000 ____D C:\Users\Tomas
2013-07-30 16:28 - 2013-07-30 16:17 - 00000000 ____D C:\Users\Tomas\AppData\Local\Ubisoft Game Launcher
2013-07-30 16:10 - 2013-07-30 16:04 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-07-30 13:50 - 2012-06-27 23:01 - 00000000 ____D C:\Users\Tomas\Documents\My Games
2013-07-30 13:20 - 2012-11-04 21:43 - 00000000 ____D C:\Program Files (x86)\HTC
2013-07-30 13:10 - 2012-08-02 18:02 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-07-30 13:10 - 2012-06-10 11:22 - 00000000 ____D C:\Games
2013-07-30 10:55 - 2013-07-21 23:41 - 00000000 ____D C:\Users\Tomas\Documents\Red Alert 3
2013-07-30 09:17 - 2013-07-23 23:55 - 00000000 ____D C:\Users\Tomas\Downloads\Big Bang theory CZ
Files to move or delete:
====================
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\Setup.exe
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\VisualCRT\vc2008redist_x86.exe
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DSETUP.dll
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\dsetup32.dll
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DXSETUP.exe
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\data\Star Wars - The Old Republic Uninstaller.exe
C:\Users\Tomas\AppData\Local\Temp\icqsetup.exe
C:\Users\Tomas\AppData\Local\Temp\Quarantine.exe
C:\Users\Tomas\AppData\Local\Temp\nsi146E.tmp\install_icq.exe
C:\Users\Tomas\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Scheduled Tasks (whitelisted) ===========
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job => C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job => C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Supplementary Scan (All) ================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent
"C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr
C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart File Advisor
"C:\Program Files (x86)\Smart File Advisor\sfa.exe" /checkassoc [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler
C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Server.lnk
C:\PROGRA~2\ArcSoft\TOTALM~1\TOTALM~1\TMSERV~1.EXE [x]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000005
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=dword:00000001
"NoActiveDesktopChanges"=dword:00000001
"ForceActiveDesktopOn"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x1
DefaultInboundAction REG_DWORD 0x1
DefaultOutboundAction REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"vidc.uyvy"="msyuv.dll"
"vidc.yuy2"="msyuv.dll"
"vidc.yvyu"="msyuv.dll"
"vidc.iyuv"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"vidc.yvu9"="tsbyuv.dll"
"msacm.l3acm"="C:\\Windows\\System32\\l3codeca.acm"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"aux"="wdmaud.drv"
"vidc.ffds"="ff_vfw.dll"
"wave6"="wdmaud.drv"
"mixer6"="wdmaud.drv"
"wave4"="wdmaud.drv"
"midi4"="wdmaud.drv"
"mixer4"="wdmaud.drv"
"wave5"="wdmaud.drv"
"midi5"="wdmaud.drv"
"mixer5"="wdmaud.drv"
"wave2"="wdmaud.drv"
"midi2"="wdmaud.drv"
"mixer2"="wdmaud.drv"
"wave3"="wdmaud.drv"
"midi3"="wdmaud.drv"
"mixer3"="wdmaud.drv"
==================== Drive and Memory info ===================
Drive c: (Hlavni) (Fixed) (Total:931.51 GB) (Free:675.64 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Dokumenty, Files) (Fixed) (Total:465.76 GB) (Free:49.61 GB) NTFS
Drive e: (Mój dysk) (CDROM) (Total:0.31 GB) (Free:0 GB) CDFS
Available physical RAM: 5766.65 MB
Total physical RAM: 8109.12 MB
Percentage of memory in use: 28%
LastRegBack: 2013-08-22 01:48
==================== End Of Log ==============================
Ran by Tomas (administrator) on 29-08-2013 22:18:00
Running from C:\Users\Tomas\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Károly Pados) C:\Program Files (x86)\TinyWall\TinyWall.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SMART6\Recovery\RPMDaemon.exe
() C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Károly Pados) C:\Program Files (x86)\TinyWall\TinyWall.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Macrovision Corporation) C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\AlarmClock.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-16] (Realtek Semiconductor)
HKLM\...\Run: [TinyWall Controller] - C:\Program Files (x86)\TinyWall\TinyWall.exe [623272 2012-06-22] (Károly Pados)
HKLM\...\Run: [Ma10PAN.exe] - C:\Windows\system32\Ma10PAN.exe [896032 2009-10-23] ()
HKLM\...\RunOnce: [RPMKickstart] - C:\Program Files\GIGABYTE\SMART6\Recovery\RPMKickstart.exe [2552320 2011-03-30] (Gigabyte Technology CO., LTD.)
HKLM-x32\...\RunOnce: [EasyTuneVI] - C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [20480 2007-07-26] ()
HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [218032 2006-09-10] (Macrovision Corporation)
HKCU\...\Run: [ISUSPM] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-10] (Macrovision Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-29] (Google Inc.)
MountPoints2: F - F:\Setup.exe
MountPoints2: I - I:\HTC_Sync_Manager_PC.exe
MountPoints2: {8ffd6ec6-b272-11e1-93af-806e6f6e6963} - E:\autorun.exe
MountPoints2: {ce73b416-baa6-11e1-b103-50e549e91cbd} - G:\Autorun.exe
HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [86960 2006-09-10] (Macrovision Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3830224 2013-05-16] (Safer-Networking Ltd.)
HKU\UpdatusUser\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [218032 2006-09-10] (Macrovision Corporation)
HKU\UpdatusUser\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [250504 2013-03-15] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [205184 2013-03-15] (NVIDIA Corporation)
Startup: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Startup\RollerCoaster Tycoon 3 Registration.lnk
ShortcutTarget: RollerCoaster Tycoon 3 Registration.lnk -> C:\Users\Tomas\AppData\Local\Temp\{FA51BA31-1C2F-4367-A6DB-713845DC214D}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: localhost:21320
SearchScopes: HKCU - {32C23A45-0E2A-4fb0-A515-CB231205D3BA} URL = http://www.bing.com/search?q={searchTer ... R1&pc=SPLH
SearchScopes: HKCU - {75FD6C1B-B415-4f5f-9861-DBCAD37EB673} URL = http://uk.search.yahoo.com/search?p={se ... ype=IEBDSV
BHO: GBHO.BHO - {45d30484-7ded-43d9-957a-d2fd1f046511} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/f ... wflash.cab
Handler: ftp - No CLSID Value -
Handler: http - No CLSID Value -
Handler: https - No CLSID Value -
Handler-x32: ftp - No CLSID Value -
Handler-x32: http - No CLSID Value -
Handler-x32: https - No CLSID Value -
FireFox:
========
FF ProfilePath: C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Tomas\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wikipedia-cz.xml
FF Extension: Smiley Bar for Facebook - C:\Users\Tomas\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
FF Extension: Battlefield Heroes Updater - C:\Users\Tomas\AppData\Roaming\Mozilla\Firefox\Profiles\b71zi4jy.default\Extensions\battlefieldheroespatcher@ea.com
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFFPlgn\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\29.0.1547.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\29.0.1547.57\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\29.0.1547.57\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Extension: (YouTube) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Flash Player V15.0) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gompblemgafijijmlgbaepcijfgfgljf\13.5_0
CHR Extension: (Norton Identity Protection) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0
CHR Extension: (CnC TA Script Collection) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmhpmdclklpgfcpoiomjofgfagenmgeo\1.2.8.46_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\Tomas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [bfcpnihmbfoaeoakalclfalkdepgiaje] - C:\Users\Tomas\AppData\Roaming\SpecialSavings\SpecialSavings.crx
CHR HKLM-x32\...\Chrome\Extension: [hgojaaaiddhmiiakpejiklijbalpckih] - C:\Users\Tomas\AppData\Roaming\StatusWinks\statuswinks.crx
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\Exts\Chrome.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Tomas\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 DES2 Service; C:\Program Files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [57344 2011-08-22] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-06-13] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.)
R2 TinyWall; C:\Program Files (x86)\TinyWall\TinyWall.exe [623272 2012-06-22] (Károly Pados)
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21104 2011-01-10] ()
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-07-15] (Symantec Corporation)
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20130715.001\BHDrvx64.sys [1393240 2013-07-15] (Symantec Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-02-11] (Samsung Electronics Co., Ltd.)
R2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-02-11] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-06-10] (DT Soft Ltd)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-29] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-29] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-29] (Symantec Corporation)
S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-13] (Windows (R) Server 2003 DDK provider)
S3 etdrv; C:\Windows\etdrv.sys [25640 2013-06-13] (Windows (R) Server 2003 DDK provider)
R3 gdrv; C:\Windows\gdrv.sys [25640 2013-08-29] (Windows (R) Server 2003 DDK provider)
R3 gdrv; C:\Windows\gdrv.sys [25640 2013-08-29] (Windows (R) Server 2003 DDK provider)
R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-08-29] ()
R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2013-08-29] ()
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-28] (Symantec Corporation)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20130828.001\IDSvia64.sys [520280 2013-08-28] (Symantec Corporation)
S1 Ma10.sys; C:\Windows\System32\DRIVERS\Ma10.sys [69664 2009-10-23] ()
S3 Ma10WDM.sys; C:\Windows\System32\DRIVERS\Ma10WDM.sys [43552 2009-10-23] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20130829.002\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-06-24] ()
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-08-29] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
S1 ArcSec; system32\drivers\ArcSec.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-29 22:16 - 2013-08-29 22:16 - 00000000 ____D C:\Users\Tomas\AppData\Local\qb1200AB.2A
2013-08-29 22:16 - 2013-08-27 21:11 - 01579080 _____ (Farbar) C:\Users\Tomas\Desktop\FRST64.exe
2013-08-29 22:05 - 2013-08-29 22:05 - 240353280 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi (1).crdownload
2013-08-29 21:55 - 2013-08-29 21:56 - 00000000 ____D C:\AdwCleaner
2013-08-29 21:43 - 2013-08-29 21:44 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360
2013-08-29 21:42 - 2013-08-29 21:42 - 01023533 _____ (Thisisu) C:\Users\Tomas\Downloads\JRT.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00994642 _____ C:\Users\Tomas\Downloads\adwcleaner.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 21:34 - 2013-08-29 21:36 - 41189376 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi.crdownload
2013-08-29 20:57 - 2013-08-29 21:19 - 399572992 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e04.avi
2013-08-29 19:36 - 2013-08-29 19:36 - 00001119 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 19:36 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-29 19:35 - 2013-08-29 19:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 16:13 - 2013-08-29 16:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-29 16:13 - 2013-08-29 16:13 - 00001389 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-08-29 16:13 - 2013-08-29 16:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-29 16:13 - 2009-01-25 13:14 - 00017272 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2013-08-29 16:12 - 2013-08-29 16:13 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-29 16:09 - 2013-08-29 16:11 - 36271144 _____ (Safer-Networking Ltd. ) C:\Users\Tomas\Downloads\spybot-2.1.exe
2013-08-29 15:20 - 2013-08-29 15:51 - 398563328 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e03.avi
2013-08-29 15:06 - 2013-08-29 15:17 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\ICQ-Profile
2013-08-29 15:02 - 2013-08-29 15:04 - 38466186 _____ C:\Users\Tomas\Downloads\install_icq8.exe
2013-08-29 14:07 - 2013-08-29 14:29 - 399538176 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e02.avi
2013-08-29 13:11 - 2013-08-29 21:57 - 00000224 _____ C:\Windows\setupact.log
2013-08-29 13:11 - 2013-08-29 13:11 - 00000000 _____ C:\Windows\setuperr.log
2013-08-29 13:10 - 2013-08-29 21:38 - 00006986 _____ C:\Windows\PFRO.log
2013-08-29 12:44 - 2013-08-29 12:49 - 00000000 ____D C:\rsit
2013-08-29 12:44 - 2013-08-29 12:49 - 00000000 ____D C:\Program Files\trend micro
2013-08-29 12:43 - 2013-08-29 12:43 - 00935175 _____ C:\Users\Tomas\Downloads\RSITx64.exe
2013-08-29 11:11 - 2013-08-29 21:38 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-08-29 11:11 - 2013-08-29 20:09 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-08-29 11:11 - 2013-08-29 20:09 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Symantec
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-08-29 11:10 - 2013-08-29 21:38 - 00000000 ____D C:\Windows\system32\Drivers\N360x64
2013-08-29 11:10 - 2013-08-29 11:11 - 00000000 ____D C:\ProgramData\Norton
2013-08-29 11:10 - 2013-08-29 11:10 - 00000000 ____D C:\Program Files (x86)\Norton 360
2013-08-28 16:35 - 2013-08-28 16:42 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2013-08-21 00:33 - 2013-08-21 00:33 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-08-20 14:23 - 2013-08-20 14:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 19:11 - 2013-08-16 19:11 - 00017659 _____ C:\Users\Tomas\Desktop\kkkk.srt
2013-08-15 10:25 - 2013-08-15 10:26 - 00000000 ____D C:\Program Files (x86)\Europa Universalis IV
2013-08-15 10:22 - 2013-01-01 01:00 - 670990336 _____ C:\Users\Tomas\Desktop\flt-euiv.iso
2013-08-14 18:55 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-14 18:55 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-14 18:55 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-08-14 18:55 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-14 18:55 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-08-14 18:55 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-14 18:55 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-08-14 18:55 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-08-14 18:55 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-08-14 18:55 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-08-14 18:55 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-08-14 18:55 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-08-14 18:55 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-14 18:55 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-08-14 04:20 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-14 04:20 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-08-14 04:20 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-14 04:20 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-08-14 04:20 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-14 04:20 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-14 04:20 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-14 04:20 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-14 04:20 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2013-08-14 04:20 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-08-14 04:20 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-08-14 04:20 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-08-14 04:19 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-14 04:19 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-14 04:19 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-08-14 04:19 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-14 04:19 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-08-14 04:19 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-08-14 04:19 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-08-14 04:19 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2013-08-14 04:19 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-08-14 04:19 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-08-14 04:19 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-08-14 04:19 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-08-14 04:19 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-08-14 04:19 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-14 04:19 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-13 20:37 - 2013-08-13 20:48 - 00000000 ____D C:\Users\Tomas\Downloads\Europa_Universalis_IV-FLT
2013-08-13 15:16 - 2013-08-13 15:16 - 00000000 ____D C:\Program Files (x86)\Total War
2013-08-13 15:16 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2013-08-12 11:19 - 2013-08-15 10:35 - 00000000 ____D C:\Users\Tomas\Documents\Paradox Interactive
2013-08-12 11:18 - 2013-08-12 11:18 - 00000000 ____D C:\Program Files\Steam
2013-08-12 09:26 - 2013-08-12 11:59 - 00000000 ____D C:\Program Files (x86)\Paradox Interactive
2013-08-12 08:41 - 2013-08-12 08:59 - 00000000 ____D C:\Program Files (x86)\MegaCasino
2013-07-30 16:17 - 2013-07-30 16:28 - 00000000 ____D C:\Users\Tomas\AppData\Local\Ubisoft Game Launcher
2013-07-30 16:04 - 2013-07-30 16:10 - 00000000 ____D C:\Program Files (x86)\Ubisoft
==================== One Month Modified Files and Folders =======
2013-08-29 22:17 - 2013-08-29 22:17 - 00000000 ____D C:\FRST
2013-08-29 22:16 - 2013-08-29 22:16 - 00000000 ____D C:\Users\Tomas\AppData\Local\qb1200AB.2A
2013-08-29 22:06 - 2011-04-12 10:34 - 00640116 _____ C:\Windows\system32\perfh005.dat
2013-08-29 22:06 - 2011-04-12 10:34 - 00127028 _____ C:\Windows\system32\perfc005.dat
2013-08-29 22:06 - 2009-07-14 07:13 - 01498176 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-29 22:05 - 2013-08-29 22:05 - 240353280 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi (1).crdownload
2013-08-29 22:05 - 2009-07-14 06:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-29 22:05 - 2009-07-14 06:45 - 00021888 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-29 22:04 - 2013-04-11 20:24 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\BitTorrent
2013-08-29 22:00 - 2012-07-01 10:30 - 01748759 _____ C:\Windows\WindowsUpdate.log
2013-08-29 21:58 - 2013-06-14 08:48 - 00000004 _____ C:\Windows\SysWOW64\GVTunner.ref
2013-08-29 21:58 - 2012-06-22 22:58 - 00000000 ____D C:\Users\Tomas\AppData\Local\LogMeIn Hamachi
2013-08-29 21:58 - 2012-06-09 23:02 - 00030528 _____ C:\Windows\GVTDrv64.sys
2013-08-29 21:57 - 2013-08-29 13:11 - 00000224 _____ C:\Windows\setupact.log
2013-08-29 21:57 - 2013-04-19 22:00 - 00000430 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-08-29 21:57 - 2012-06-28 13:16 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-29 21:57 - 2012-06-09 23:20 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-29 21:57 - 2012-06-09 23:00 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2013-08-29 21:57 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-29 21:56 - 2013-08-29 21:55 - 00000000 ____D C:\AdwCleaner
2013-08-29 21:56 - 2012-08-18 05:57 - 00000000 ____D C:\ProgramData\ICQ
2013-08-29 21:52 - 2012-06-28 13:16 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-29 21:44 - 2013-08-29 21:43 - 00000000 ____D C:\Windows\System32\Tasks\Norton 360
2013-08-29 21:42 - 2013-08-29 21:42 - 01023533 _____ (Thisisu) C:\Users\Tomas\Downloads\JRT.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00994642 _____ C:\Users\Tomas\Downloads\adwcleaner.exe
2013-08-29 21:42 - 2013-08-29 21:42 - 00000000 ____D C:\Windows\ERUNT
2013-08-29 21:38 - 2013-08-29 13:10 - 00006986 _____ C:\Windows\PFRO.log
2013-08-29 21:38 - 2013-08-29 11:11 - 00003206 _____ C:\Windows\System32\Tasks\Norton WSC Integration
2013-08-29 21:38 - 2013-08-29 11:10 - 00000000 ____D C:\Windows\system32\Drivers\N360x64
2013-08-29 21:36 - 2013-08-29 21:34 - 41189376 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e05.avi.crdownload
2013-08-29 21:33 - 2012-06-09 23:10 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-29 21:19 - 2013-08-29 20:57 - 399572992 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e04.avi
2013-08-29 20:38 - 2012-07-29 20:57 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job
2013-08-29 20:09 - 2013-08-29 11:11 - 00177312 _____ (Symantec Corporation) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
2013-08-29 20:09 - 2013-08-29 11:11 - 00007631 _____ C:\Windows\system32\Drivers\SYMEVENT64x86.CAT
2013-08-29 19:36 - 2013-08-29 19:36 - 00001119 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-29 19:36 - 2013-08-29 19:36 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-29 19:35 - 2013-08-29 19:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Tomas\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-29 18:09 - 2013-06-12 22:17 - 00214520 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-08-29 18:09 - 2013-01-06 13:57 - 00214520 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-08-29 18:09 - 2012-08-07 18:03 - 00214520 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-08-29 16:46 - 2012-06-10 12:33 - 00000000 ____D C:\Users\Tomas\Desktop\Games
2013-08-29 16:14 - 2013-08-29 16:13 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-08-29 16:13 - 2013-08-29 16:13 - 00001389 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-08-29 16:13 - 2013-08-29 16:13 - 00000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2013-08-29 16:13 - 2013-08-29 16:12 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2013-08-29 16:11 - 2013-08-29 16:09 - 36271144 _____ (Safer-Networking Ltd. ) C:\Users\Tomas\Downloads\spybot-2.1.exe
2013-08-29 15:51 - 2013-08-29 15:20 - 398563328 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e03.avi
2013-08-29 15:17 - 2013-08-29 15:06 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\ICQ-Profile
2013-08-29 15:04 - 2013-08-29 15:02 - 38466186 _____ C:\Users\Tomas\Downloads\install_icq8.exe
2013-08-29 14:29 - 2013-08-29 14:07 - 399538176 _____ C:\Users\Tomas\Downloads\Babylon-5---s03e02.avi
2013-08-29 14:02 - 2012-06-10 21:45 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Media Player Classic
2013-08-29 13:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-29 13:11 - 2013-08-29 13:11 - 00000000 _____ C:\Windows\setuperr.log
2013-08-29 13:07 - 2012-06-10 11:12 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\DAEMON Tools Lite
2013-08-29 13:06 - 2012-06-09 23:34 - 00000000 ____D C:\Windows\Panther
2013-08-29 13:02 - 2012-06-09 22:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-08-29 12:49 - 2013-08-29 12:44 - 00000000 ____D C:\rsit
2013-08-29 12:49 - 2013-08-29 12:44 - 00000000 ____D C:\Program Files\trend micro
2013-08-29 12:43 - 2013-08-29 12:43 - 00935175 _____ C:\Users\Tomas\Downloads\RSITx64.exe
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Symantec
2013-08-29 11:11 - 2013-08-29 11:11 - 00000000 ____D C:\Program Files\Common Files\Symantec Shared
2013-08-29 11:11 - 2013-08-29 11:10 - 00000000 ____D C:\ProgramData\Norton
2013-08-29 11:10 - 2013-08-29 11:10 - 00000000 ____D C:\Program Files (x86)\Norton 360
2013-08-29 04:38 - 2012-07-29 20:57 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job
2013-08-28 16:42 - 2013-08-28 16:35 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\My Battle for Middle-earth(tm) II Files
2013-08-28 16:31 - 2013-07-21 19:53 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-08-27 21:11 - 2013-08-29 22:16 - 01579080 _____ (Farbar) C:\Users\Tomas\Desktop\FRST64.exe
2013-08-22 14:21 - 2012-09-10 02:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-21 14:49 - 2012-07-29 20:59 - 00002371 _____ C:\Users\Tomas\Desktop\Google Chrome.lnk
2013-08-21 00:34 - 2012-06-09 23:10 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-08-21 00:33 - 2013-08-21 00:33 - 17737608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-08-21 00:33 - 2012-06-09 23:10 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-08-21 00:33 - 2012-06-09 23:10 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-08-20 14:23 - 2013-08-20 14:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-16 19:11 - 2013-08-16 19:11 - 00017659 _____ C:\Users\Tomas\Desktop\kkkk.srt
2013-08-15 10:35 - 2013-08-12 11:19 - 00000000 ____D C:\Users\Tomas\Documents\Paradox Interactive
2013-08-15 10:26 - 2013-08-15 10:25 - 00000000 ____D C:\Program Files (x86)\Europa Universalis IV
2013-08-15 10:24 - 2012-11-21 01:12 - 00000000 ____D C:\Users\Tomas\Desktop\wow
2013-08-15 08:50 - 2013-07-29 19:09 - 00000000 ____D C:\Program Files (x86)\Heroes of Newerth
2013-08-14 19:35 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-08-14 18:53 - 2013-07-27 03:03 - 00000000 ____D C:\Windows\system32\MRT
2013-08-14 18:52 - 2012-06-10 04:41 - 78161360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-08-13 20:48 - 2013-08-13 20:37 - 00000000 ____D C:\Users\Tomas\Downloads\Europa_Universalis_IV-FLT
2013-08-13 15:29 - 2012-06-12 11:52 - 00000000 ____D C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-08-13 15:16 - 2013-08-13 15:16 - 00000000 ____D C:\Program Files (x86)\Total War
2013-08-12 17:54 - 2012-06-11 10:36 - 00000072 _____ C:\Users\Public\LMDebug.log
2013-08-12 11:59 - 2013-08-12 09:26 - 00000000 ____D C:\Program Files (x86)\Paradox Interactive
2013-08-12 11:18 - 2013-08-12 11:18 - 00000000 ____D C:\Program Files\Steam
2013-08-12 08:59 - 2013-08-12 08:41 - 00000000 ____D C:\Program Files (x86)\MegaCasino
2013-08-07 19:54 - 2012-09-28 22:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2013-07-31 07:20 - 2012-06-09 22:45 - 00000000 ____D C:\Users\Tomas
2013-07-30 16:28 - 2013-07-30 16:17 - 00000000 ____D C:\Users\Tomas\AppData\Local\Ubisoft Game Launcher
2013-07-30 16:10 - 2013-07-30 16:04 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-07-30 13:50 - 2012-06-27 23:01 - 00000000 ____D C:\Users\Tomas\Documents\My Games
2013-07-30 13:20 - 2012-11-04 21:43 - 00000000 ____D C:\Program Files (x86)\HTC
2013-07-30 13:10 - 2012-08-02 18:02 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2013-07-30 13:10 - 2012-06-10 11:22 - 00000000 ____D C:\Games
2013-07-30 10:55 - 2013-07-21 23:41 - 00000000 ____D C:\Users\Tomas\Documents\Red Alert 3
2013-07-30 09:17 - 2013-07-23 23:55 - 00000000 ____D C:\Users\Tomas\Downloads\Big Bang theory CZ
Files to move or delete:
====================
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\Setup.exe
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\VisualCRT\vc2008redist_x86.exe
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DSETUP.dll
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\dsetup32.dll
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DXSETUP.exe
C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\data\Star Wars - The Old Republic Uninstaller.exe
C:\Users\Tomas\AppData\Local\Temp\icqsetup.exe
C:\Users\Tomas\AppData\Local\Temp\Quarantine.exe
C:\Users\Tomas\AppData\Local\Temp\nsi146E.tmp\install_icq.exe
C:\Users\Tomas\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Scheduled Tasks (whitelisted) ===========
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job => C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job => C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Supplementary Scan (All) ================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent
"C:\Users\Tomas\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
"C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe" /c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr
C:\Windows\Samsung\PanelMgr\ssmmgr.exe /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart File Advisor
"C:\Program Files (x86)\Smart File Advisor\sfa.exe" /checkassoc [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler
C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Server.lnk
C:\PROGRA~2\ArcSoft\TOTALM~1\TOTALM~1\TMSERV~1.EXE [x]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000005
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000001
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=dword:00000001
"NoActiveDesktopChanges"=dword:00000001
"ForceActiveDesktopOn"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x1
DefaultInboundAction REG_DWORD 0x1
DefaultOutboundAction REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"vidc.uyvy"="msyuv.dll"
"vidc.yuy2"="msyuv.dll"
"vidc.yvyu"="msyuv.dll"
"vidc.iyuv"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"vidc.yvu9"="tsbyuv.dll"
"msacm.l3acm"="C:\\Windows\\System32\\l3codeca.acm"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"aux"="wdmaud.drv"
"vidc.ffds"="ff_vfw.dll"
"wave6"="wdmaud.drv"
"mixer6"="wdmaud.drv"
"wave4"="wdmaud.drv"
"midi4"="wdmaud.drv"
"mixer4"="wdmaud.drv"
"wave5"="wdmaud.drv"
"midi5"="wdmaud.drv"
"mixer5"="wdmaud.drv"
"wave2"="wdmaud.drv"
"midi2"="wdmaud.drv"
"mixer2"="wdmaud.drv"
"wave3"="wdmaud.drv"
"midi3"="wdmaud.drv"
"mixer3"="wdmaud.drv"
==================== Drive and Memory info ===================
Drive c: (Hlavni) (Fixed) (Total:931.51 GB) (Free:675.64 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Dokumenty, Files) (Fixed) (Total:465.76 GB) (Free:49.61 GB) NTFS
Drive e: (Mój dysk) (CDROM) (Total:0.31 GB) (Free:0 GB) CDFS
Available physical RAM: 5766.65 MB
Total physical RAM: 8109.12 MB
Percentage of memory in use: 28%
LastRegBack: 2013-08-22 01:48
==================== End Of Log ==============================
Re: zpomalený internet
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKCU\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [218032 2006-09-10] (Macrovision Corporation) HKCU\...\Run: [ISUSPM] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-10] (Macrovision Corporation) HKCU\...\Run: [Google Update] - C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-29] (Google Inc.) MountPoints2: F - F:\Setup.exe MountPoints2: I - I:\HTC_Sync_Manager_PC.exe MountPoints2: {8ffd6ec6-b272-11e1-93af-806e6f6e6963} - E:\autorun.exe MountPoints2: {ce73b416-baa6-11e1-b103-50e549e91cbd} - G:\Autorun.exe HKLM-x32\...\Run: [ISUSScheduler] - C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [86960 2006-09-10] (Macrovision Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3830224 2013-05-16] (Safer-Networking Ltd.) HKU\UpdatusUser\...\Run: [ISUSPM Startup] - C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [218032 2006-09-10] (Macrovision Corporation) HKU\UpdatusUser\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd) Startup: C:\Users\Tomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Startup\RollerCoaster Tycoon 3 Registration.lnk ShortcutTarget: RollerCoaster Tycoon 3 Registration.lnk -> C:\Users\Tomas\AppData\Local\Temp\{FA51BA31-1C2F-4367-A6DB-713845DC214D}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe (No File) ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: localhost:21320 SearchScopes: HKCU - {32C23A45-0E2A-4fb0-A515-CB231205D3BA} URL = http://www.bing.com/search?q={searchTerms}&form=SPLBR1&pc=SPLH SearchScopes: HKCU - {75FD6C1B-B415-4f5f-9861-DBCAD37EB673} URL = http://uk.search.yahoo.com/search?p={searchTerms}&fr=chr-devicevm&type=IEBDSV Handler: ftp - No CLSID Value - Handler: http - No CLSID Value - Handler: https - No CLSID Value - Handler-x32: ftp - No CLSID Value - Handler-x32: http - No CLSID Value - Handler-x32: https - No CLSID Value - Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000Core.job => C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1444486529-4172279158-2348300707-1000UA.job => C:\Users\Tomas\AppData\Local\Google\Update\GoogleUpdate.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\Setup.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\VisualCRT\vc2008redist_x86.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DSETUP.dll C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\dsetup32.dll C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\software\DirectX\DXSETUP.exe C:\Users\hedev\AppData\Local\Temp\InstallSWTOR\data\Star Wars - The Old Republic Uninstaller.exe C:\Users\Tomas\AppData\Local\Temp\icqsetup.exe C:\Users\Tomas\AppData\Local\Temp\Quarantine.exe C:\Users\Tomas\AppData\Local\Temp\nsi146E.tmp\install_icq.exe C:\Users\Tomas\AppData\Local\Temp\jrt\erunt\ERUNT.EXE REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart File Advisor" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f REG: reg delete"HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TotalMedia Server.lnk" /f Hosts: CMD: shutdown /r /f /t 2 End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt



Přispějete na provoz fóra?