
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o preventivku
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosím o preventivku
Dobrý den,
prosím o preventivní kontrolu notebooku. Děkuji!
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ervd at 2013-08-30 18:24:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 197 GB (43%) free of 455 GB
Total RAM: 4030 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:24:53, on 30.8.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16502)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\PDF Architect\PDF Architect.exe
C:\Program Files\trend micro\Ervd.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - Startup: Dropbox.lnk = Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Rich Media Downloader - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - (no file)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Brother Resource manager service (brmfrsmg) - Unknown owner - C:\windows\system32\BrmfRsmg.exe (file missing)
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13994 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\windows\system32\BrmfRsmg.exe -service
C:\windows\system32\BrmfRsmg.exe -process -overmain -load -open
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\PDF Architect\HelperService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe" /start
"C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
"C:\Program Files (x86)\PDF Architect\ConversionService.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3536
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
-Minimized
"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe" -h
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Program Files (x86)\PDF Architect\PDF Architect.exe" C:\Users\Ervd\Desktop\mast.pdf
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe33_ Global\UsGthrCtrlFltPipeMssGthrPipe33 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Ervd\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\HPCeeScheduleForERVD-HP$.job
C:\windows\tasks\HPCeeScheduleForErvd.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-05-09 242496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-06-29 553896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-06-29 211880]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-04-16 540328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}]
PDF Architect Helper - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2013-04-08 92208]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-24 463272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-24 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-05-09 242496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
{25A3A431-30BB-47C8-AD6A-E1063801134F} - PDF Architect Toolbar - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll [2013-04-08 654384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-09-01 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-09-01 392472]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-09-01 416024]
"IME14 JPN Uninstall"=C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
"IME14 KOR Uninstall"=C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
"IME14 CHS Uninstall"=C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-01-29 3011824]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2013-05-24 1664000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-02-15 21709904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
C:\Program Files (x86)\QIP 2012\qip.exe [2013-08-06 8502256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess]
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-09-17 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-08-03 1086376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-08-11 658424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-03 19603048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-05-29 449248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-06-07 1641896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-05-15 5622512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader]
C:\Program Files\VDownloader\VDownloader.exe /silent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly]
C:\Program Files (x86)\Voobly\voobly.exe [2013-08-26 155648]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [2012-06-20 333728]
"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2012-09-05 184736]
""= []
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"TkBellExe"=C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2013-08-11 295512]
C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-09-01 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-08-30 00:09:58 ----D---- C:\Program Files (x86)\Sony Media Go Install
2013-08-29 23:27:53 ----D---- C:\Program Files (x86)\GreenTree Applications
2013-08-29 23:23:06 ----D---- C:\Users\Ervd\AppData\Roaming\Youtube Downloader HD
2013-08-15 03:04:43 ----D---- C:\windows\system32\MRT
2013-08-15 03:01:38 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-08-15 03:01:38 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-08-15 03:01:38 ----A---- C:\windows\system32\mshtmled.dll
2013-08-15 03:01:36 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-08-15 03:01:36 ----A---- C:\windows\system32\ieUnatt.exe
2013-08-15 03:01:36 ----A---- C:\windows\system32\ieui.dll
2013-08-15 03:01:35 ----A---- C:\windows\SYSWOW64\url.dll
2013-08-15 03:01:35 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-08-15 03:01:35 ----A---- C:\windows\system32\url.dll
2013-08-15 03:01:34 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-08-15 03:01:34 ----A---- C:\windows\system32\wininet.dll
2013-08-15 03:01:33 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-08-15 03:01:33 ----A---- C:\windows\system32\urlmon.dll
2013-08-15 03:01:32 ----A---- C:\windows\system32\jscript9.dll
2013-08-15 03:01:31 ----A---- C:\windows\system32\msfeeds.dll
2013-08-15 03:01:30 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-08-15 03:01:28 ----A---- C:\windows\system32\jsproxy.dll
2013-08-15 03:01:27 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-08-15 03:01:27 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-08-15 03:01:27 ----A---- C:\windows\system32\vbscript.dll
2013-08-15 03:01:26 ----A---- C:\windows\system32\jscript.dll
2013-08-15 03:01:25 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-08-15 03:01:25 ----A---- C:\windows\system32\iertutil.dll
2013-08-15 03:01:24 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-08-15 03:01:21 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-08-15 03:01:19 ----A---- C:\windows\system32\mshtml.dll
2013-08-15 03:01:16 ----A---- C:\windows\system32\ieframe.dll
2013-08-15 03:01:15 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-08-14 20:29:22 ----A---- C:\windows\SYSWOW64\wintrust.dll
2013-08-14 20:29:22 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2013-08-14 20:29:22 ----A---- C:\windows\SYSWOW64\crypt32.dll
2013-08-14 20:29:22 ----A---- C:\windows\system32\wintrust.dll
2013-08-14 20:29:22 ----A---- C:\windows\system32\cryptsvc.dll
2013-08-14 20:29:22 ----A---- C:\windows\system32\crypt32.dll
2013-08-14 20:29:21 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2013-08-14 20:29:21 ----A---- C:\windows\system32\cryptnet.dll
2013-08-14 20:29:09 ----A---- C:\windows\SYSWOW64\tzres.dll
2013-08-14 20:29:09 ----A---- C:\windows\system32\tzres.dll
2013-08-14 20:29:06 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2013-08-14 20:29:06 ----A---- C:\windows\system32\WMVDECOD.DLL
2013-08-14 20:29:05 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2013-08-14 20:29:05 ----A---- C:\windows\system32\rpcrt4.dll
2013-08-14 20:29:03 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-08-14 20:29:02 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-08-14 20:29:01 ----A---- C:\windows\system32\ntoskrnl.exe
2013-08-14 20:29:01 ----A---- C:\windows\system32\ntdll.dll
2013-08-14 20:29:00 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-08-14 20:29:00 ----A---- C:\windows\SYSWOW64\ntdll.dll
2013-08-14 20:29:00 ----A---- C:\windows\system32\wow64.dll
2013-08-14 20:28:59 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-08-14 20:28:58 ----A---- C:\windows\SYSWOW64\user.exe
2013-08-14 20:28:58 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-08-14 20:28:58 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-08-14 20:28:55 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2013-08-14 20:28:54 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-08-12 14:49:11 ----D---- C:\ICQ
2013-08-12 14:48:41 ----D---- C:\Users\Ervd\AppData\Roaming\QIP
2013-08-12 14:48:26 ----D---- C:\Program Files (x86)\QIP 2012
2013-08-11 12:57:05 ----D---- C:\Users\Ervd\AppData\Roaming\RealNetworks
2013-08-11 12:56:41 ----D---- C:\Program Files (x86)\RealNetworks
2013-08-11 12:56:39 ----D---- C:\ProgramData\RealNetworks
2013-08-11 12:56:24 ----A---- C:\windows\SYSWOW64\rmoc3260.dll
2013-08-11 12:56:19 ----A---- C:\windows\SYSWOW64\pndx5032.dll
2013-08-11 12:56:19 ----A---- C:\windows\SYSWOW64\pndx5016.dll
2013-08-11 12:56:18 ----A---- C:\windows\SYSWOW64\pncrt.dll
2013-08-11 12:56:14 ----D---- C:\Program Files (x86)\Real
2013-08-11 12:55:55 ----D---- C:\Users\Ervd\AppData\Roaming\Real
2013-08-11 12:54:42 ----D---- C:\ProgramData\Real
2013-08-11 12:53:07 ----D---- C:\ProgramData\Apple Computer
2013-08-11 12:53:07 ----D---- C:\Program Files (x86)\QuickTime
2013-08-11 12:52:21 ----D---- C:\ProgramData\Apple
2013-08-11 12:52:21 ----D---- C:\Program Files (x86)\Apple Software Update
2013-08-11 12:49:25 ----D---- C:\PFiles
2013-08-08 18:56:33 ----D---- C:\Users\Ervd\AppData\Roaming\OpenOffice
2013-08-08 18:55:22 ----D---- C:\Program Files (x86)\OpenOffice 4
2013-07-31 21:55:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-07-31 21:50:39 ----D---- C:\Users\Ervd\AppData\Roaming\GHISLER
2013-07-31 21:50:39 ----A---- C:\windows\UC.PIF
2013-07-31 21:50:39 ----A---- C:\windows\RAR.PIF
2013-07-31 21:50:39 ----A---- C:\windows\PKZIP.PIF
2013-07-31 21:50:39 ----A---- C:\windows\PKUNZIP.PIF
2013-07-31 21:50:39 ----A---- C:\windows\LHA.PIF
2013-07-31 21:50:39 ----A---- C:\windows\ARJ.PIF
2013-07-31 21:47:48 ----D---- C:\Users\Ervd\AppData\Roaming\TeamViewer
======List of files/folders modified in the last 1 month======
2013-08-30 18:24:53 ----D---- C:\windows\Prefetch
2013-08-30 18:24:51 ----D---- C:\Program Files\trend micro
2013-08-30 17:23:13 ----D---- C:\windows\temp
2013-08-30 15:09:27 ----D---- C:\windows\Tasks
2013-08-30 15:09:27 ----D---- C:\windows\system32\Tasks
2013-08-30 15:08:47 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-08-30 09:35:14 ----D---- C:\windows\system32\config
2013-08-30 09:21:49 ----A---- C:\windows\SYSWOW64\log.txt
2013-08-30 09:19:59 ----D---- C:\ProgramData\PDFC
2013-08-30 09:19:45 ----D---- C:\Users\Ervd\AppData\Roaming\Dropbox
2013-08-30 09:17:38 ----D---- C:\Program Files (x86)\Pando Networks
2013-08-30 00:16:29 ----SHD---- C:\windows\Installer
2013-08-30 00:09:58 ----RD---- C:\Program Files (x86)
2013-08-29 23:43:10 ----D---- C:\Users\Ervd\AppData\Roaming\Audacity
2013-08-29 23:40:29 ----D---- C:\Program Files (x86)\SpeedFan
2013-08-29 23:29:05 ----D---- C:\ProgramData
2013-08-29 23:11:16 ----D---- C:\windows\System32
2013-08-29 23:11:16 ----D---- C:\windows\inf
2013-08-29 23:11:16 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-08-29 14:41:44 ----SHD---- C:\System Volume Information
2013-08-27 12:38:31 ----D---- C:\Program Files (x86)\Voobly
2013-08-21 00:26:20 ----D---- C:\Users\Ervd\AppData\Roaming\vlc
2013-08-18 12:09:51 ----D---- C:\windows\system32\catroot2
2013-08-16 12:54:29 ----D---- C:\Windows
2013-08-15 14:28:33 ----D---- C:\windows\debug
2013-08-15 11:48:24 ----D---- C:\windows\Microsoft.NET
2013-08-15 11:48:22 ----RSD---- C:\windows\assembly
2013-08-15 03:36:58 ----D---- C:\windows\winsxs
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\sl-SI
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\sk-SK
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\hr-HR
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\en-US
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-08-15 03:34:18 ----D---- C:\windows\SysWOW64
2013-08-15 03:34:18 ----D---- C:\windows\system32\sl-SI
2013-08-15 03:34:18 ----D---- C:\windows\system32\sk-SK
2013-08-15 03:34:18 ----D---- C:\windows\system32\hr-HR
2013-08-15 03:34:18 ----D---- C:\windows\system32\en-US
2013-08-15 03:34:18 ----D---- C:\windows\system32\cs-CZ
2013-08-15 03:34:17 ----D---- C:\windows\system32\drivers
2013-08-15 03:34:17 ----D---- C:\windows\AppPatch
2013-08-15 03:34:17 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-15 03:34:16 ----D---- C:\windows\SYSWOW64\migration
2013-08-15 03:34:16 ----D---- C:\windows\system32\migration
2013-08-15 03:34:16 ----D---- C:\Program Files\Internet Explorer
2013-08-15 03:04:36 ----A---- C:\windows\system32\MRT.exe
2013-08-15 03:03:46 ----A---- C:\windows\win.ini
2013-08-15 03:01:59 ----D---- C:\windows\system32\catroot
2013-08-15 02:41:07 ----D---- C:\Program Files (x86)\The KMPlayer
2013-08-13 00:41:26 ----D---- C:\Program Files (x86)\Diablo III
2013-08-12 06:39:30 ----D---- C:\Users\Ervd\AppData\Roaming\Apple Computer
2013-08-11 12:56:30 ----D---- C:\Program Files (x86)\Common Files
2013-08-11 12:56:15 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2013-08-11 12:56:15 ----A---- C:\windows\SYSWOW64\msvcp71.dll
2013-08-11 12:47:02 ----D---- C:\windows\SYSWOW64\Adobe
2013-08-08 18:55:30 ----RSD---- C:\windows\Fonts
2013-08-08 18:55:08 ----D---- C:\Program Files (x86)\OpenOffice.org 3
2013-08-06 18:05:01 ----D---- C:\Program Files (x86)\Opera
2013-07-31 22:02:28 ----RD---- C:\Program Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2013-05-09 65336]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2013-06-28 189936]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2012-09-24 31040]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2013-05-09 72016]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2013-06-28 1030952]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2013-06-28 378944]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2013-05-09 64288]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-04-02 283200]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2013-05-09 33400]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 80816]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2012-09-24 43840]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-10-14 10496000]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-10-14 326656]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys [2010-12-03 25912]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-05-24 708200]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2013-05-24 543744]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-01-29 468720]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BrUsbScn;Ovladač skeneru Brother MFC USB; C:\windows\System32\Drivers\BrUsbScn.sys [2009-06-10 14336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-01-02 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-06-30 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2011-02-08 486144]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2013-01-16 27760]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-09-01 12306848]
S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2013-05-24 175928]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 trufos;trufos; C:\windows\system32\drivers\trufos.sys [2013-03-07 350160]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\drivers\usb8023x.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-05-08 143088]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2013-05-24 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-10-14 204288]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
R2 brmfrsmg;Brother Resource manager service; C:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-09-06 197536]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2012-06-20 523680]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2012-09-24 31040]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 PDF Architect Helper Service;PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [2013-04-08 1320496]
R2 PDF Architect Service;PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [2013-04-08 799280]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-08-11 1128952]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-04-16 39056]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2013-05-24 323072]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2012-09-05 1420192]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-09-06 1001376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-19 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-06-03 162408]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-13 257416]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-09 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-08-01 724888]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
prosím o preventivní kontrolu notebooku. Děkuji!
Logfile of random's system information tool 1.09 (written by random/random)
Run by Ervd at 2013-08-30 18:24:47
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 197 GB (43%) free of 455 GB
Total RAM: 4030 MB (45% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:24:53, on 30.8.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16502)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
C:\Program Files (x86)\Opera\opera.exe
C:\Program Files (x86)\PDF Architect\PDF Architect.exe
C:\Program Files\trend micro\Ervd.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [HP HD Webcam [Fixed]_Monitor] C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
O4 - HKLM\..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - Startup: Dropbox.lnk = Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Rich Media Downloader - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - (no file)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Brother Resource manager service (brmfrsmg) - Unknown owner - C:\windows\system32\BrmfRsmg.exe (file missing)
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Connection Manager 4 Service (hpCMSrv) - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\windows\system32\Hpservice.exe (file missing)
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: PDF Architect Helper Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GmbH - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: ArcCapture (uArcCapture) - ArcSoft, Inc. - C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 13994 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\Hpservice.exe
atieclxx
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\windows\system32\BrmfRsmg.exe -service
C:\windows\system32\BrmfRsmg.exe -process -overmain -load -open
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\PDF Architect\HelperService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe" /start
"C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
"C:\Program Files (x86)\PDF Architect\ConversionService.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe"
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3536
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
-Minimized
"C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe"
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe" -h
"C:\Program Files (x86)\Opera\opera.exe"
"C:\Program Files (x86)\PDF Architect\PDF Architect.exe" C:\Users\Ervd\Desktop\mast.pdf
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe33_ Global\UsGthrCtrlFltPipeMssGthrPipe33 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Ervd\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\HPCeeScheduleForERVD-HP$.job
C:\windows\tasks\HPCeeScheduleForErvd.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-05-09 242496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-06-29 553896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-06-29 211880]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealNetworks Download and Record Plugin for Internet Explorer - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-04-16 540328]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A2D5EBA-F86D-4BD3-A177-019765996711}]
PDF Architect Helper - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll [2013-04-08 92208]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-06-24 463272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-22 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-06-24 171944]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09 351136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-05-09 242496]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-05-09 198688]
{25A3A431-30BB-47C8-AD6A-E1063801134F} - PDF Architect Toolbar - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll [2013-04-08 654384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-09-01 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-09-01 392472]
"Persistence"=C:\windows\system32\igfxpers.exe [2011-09-01 416024]
"IME14 JPN Uninstall"=C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
"IME14 KOR Uninstall"=C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
"IME14 CHS Uninstall"=C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-01-29 3011824]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2013-05-24 1664000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent]
C:\Program Files\Motorola\Bluetooth\btmshell.dll [2011-02-15 21709904]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant]
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe [2011-01-27 13880]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup]
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE [2012-03-14 110896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
C:\Program Files (x86)\QIP 2012\qip.exe [2013-08-06 8502256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess]
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [2009-09-17 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2012-08-03 1086376]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
C:\Program Files (x86)\PDF Complete\pdfsty.exe [2011-08-11 658424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-06-03 19603048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion]
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2013-05-29 449248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files (x86)\Steam\Steam.exe [2013-06-07 1641896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12 253816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2013-05-15 5622512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader]
C:\Program Files\VDownloader\VDownloader.exe /silent []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly]
C:\Program Files (x86)\Voobly\voobly.exe [2013-08-26 155648]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-10-14 343168]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-01-26 283160]
"HP HD Webcam [Fixed]_Monitor"=C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [2010-11-26 267128]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2013-05-09 4858968]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [2012-06-20 333728]
"HPConnectionManager"=C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [2012-09-05 184736]
""= []
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"TkBellExe"=C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [2013-08-11 295512]
C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-09-01 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=153
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codecp.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.FFDS"=ff_vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2013-08-30 00:09:58 ----D---- C:\Program Files (x86)\Sony Media Go Install
2013-08-29 23:27:53 ----D---- C:\Program Files (x86)\GreenTree Applications
2013-08-29 23:23:06 ----D---- C:\Users\Ervd\AppData\Roaming\Youtube Downloader HD
2013-08-15 03:04:43 ----D---- C:\windows\system32\MRT
2013-08-15 03:01:38 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-08-15 03:01:38 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-08-15 03:01:38 ----A---- C:\windows\system32\mshtmled.dll
2013-08-15 03:01:36 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-08-15 03:01:36 ----A---- C:\windows\system32\ieUnatt.exe
2013-08-15 03:01:36 ----A---- C:\windows\system32\ieui.dll
2013-08-15 03:01:35 ----A---- C:\windows\SYSWOW64\url.dll
2013-08-15 03:01:35 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-08-15 03:01:35 ----A---- C:\windows\system32\url.dll
2013-08-15 03:01:34 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-08-15 03:01:34 ----A---- C:\windows\system32\wininet.dll
2013-08-15 03:01:33 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-08-15 03:01:33 ----A---- C:\windows\system32\urlmon.dll
2013-08-15 03:01:32 ----A---- C:\windows\system32\jscript9.dll
2013-08-15 03:01:31 ----A---- C:\windows\system32\msfeeds.dll
2013-08-15 03:01:30 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-08-15 03:01:28 ----A---- C:\windows\system32\jsproxy.dll
2013-08-15 03:01:27 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-08-15 03:01:27 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-08-15 03:01:27 ----A---- C:\windows\system32\vbscript.dll
2013-08-15 03:01:26 ----A---- C:\windows\system32\jscript.dll
2013-08-15 03:01:25 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-08-15 03:01:25 ----A---- C:\windows\system32\iertutil.dll
2013-08-15 03:01:24 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-08-15 03:01:21 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-08-15 03:01:19 ----A---- C:\windows\system32\mshtml.dll
2013-08-15 03:01:16 ----A---- C:\windows\system32\ieframe.dll
2013-08-15 03:01:15 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-08-14 20:29:22 ----A---- C:\windows\SYSWOW64\wintrust.dll
2013-08-14 20:29:22 ----A---- C:\windows\SYSWOW64\cryptsvc.dll
2013-08-14 20:29:22 ----A---- C:\windows\SYSWOW64\crypt32.dll
2013-08-14 20:29:22 ----A---- C:\windows\system32\wintrust.dll
2013-08-14 20:29:22 ----A---- C:\windows\system32\cryptsvc.dll
2013-08-14 20:29:22 ----A---- C:\windows\system32\crypt32.dll
2013-08-14 20:29:21 ----A---- C:\windows\SYSWOW64\cryptnet.dll
2013-08-14 20:29:21 ----A---- C:\windows\system32\cryptnet.dll
2013-08-14 20:29:09 ----A---- C:\windows\SYSWOW64\tzres.dll
2013-08-14 20:29:09 ----A---- C:\windows\system32\tzres.dll
2013-08-14 20:29:06 ----A---- C:\windows\SYSWOW64\WMVDECOD.DLL
2013-08-14 20:29:06 ----A---- C:\windows\system32\WMVDECOD.DLL
2013-08-14 20:29:05 ----A---- C:\windows\SYSWOW64\rpcrt4.dll
2013-08-14 20:29:05 ----A---- C:\windows\system32\rpcrt4.dll
2013-08-14 20:29:03 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-08-14 20:29:02 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-08-14 20:29:01 ----A---- C:\windows\system32\ntoskrnl.exe
2013-08-14 20:29:01 ----A---- C:\windows\system32\ntdll.dll
2013-08-14 20:29:00 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-08-14 20:29:00 ----A---- C:\windows\SYSWOW64\ntdll.dll
2013-08-14 20:29:00 ----A---- C:\windows\system32\wow64.dll
2013-08-14 20:28:59 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-08-14 20:28:58 ----A---- C:\windows\SYSWOW64\user.exe
2013-08-14 20:28:58 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-08-14 20:28:58 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-08-14 20:28:55 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2013-08-14 20:28:54 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-08-12 14:49:11 ----D---- C:\ICQ
2013-08-12 14:48:41 ----D---- C:\Users\Ervd\AppData\Roaming\QIP
2013-08-12 14:48:26 ----D---- C:\Program Files (x86)\QIP 2012
2013-08-11 12:57:05 ----D---- C:\Users\Ervd\AppData\Roaming\RealNetworks
2013-08-11 12:56:41 ----D---- C:\Program Files (x86)\RealNetworks
2013-08-11 12:56:39 ----D---- C:\ProgramData\RealNetworks
2013-08-11 12:56:24 ----A---- C:\windows\SYSWOW64\rmoc3260.dll
2013-08-11 12:56:19 ----A---- C:\windows\SYSWOW64\pndx5032.dll
2013-08-11 12:56:19 ----A---- C:\windows\SYSWOW64\pndx5016.dll
2013-08-11 12:56:18 ----A---- C:\windows\SYSWOW64\pncrt.dll
2013-08-11 12:56:14 ----D---- C:\Program Files (x86)\Real
2013-08-11 12:55:55 ----D---- C:\Users\Ervd\AppData\Roaming\Real
2013-08-11 12:54:42 ----D---- C:\ProgramData\Real
2013-08-11 12:53:07 ----D---- C:\ProgramData\Apple Computer
2013-08-11 12:53:07 ----D---- C:\Program Files (x86)\QuickTime
2013-08-11 12:52:21 ----D---- C:\ProgramData\Apple
2013-08-11 12:52:21 ----D---- C:\Program Files (x86)\Apple Software Update
2013-08-11 12:49:25 ----D---- C:\PFiles
2013-08-08 18:56:33 ----D---- C:\Users\Ervd\AppData\Roaming\OpenOffice
2013-08-08 18:55:22 ----D---- C:\Program Files (x86)\OpenOffice 4
2013-07-31 21:55:11 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-07-31 21:50:39 ----D---- C:\Users\Ervd\AppData\Roaming\GHISLER
2013-07-31 21:50:39 ----A---- C:\windows\UC.PIF
2013-07-31 21:50:39 ----A---- C:\windows\RAR.PIF
2013-07-31 21:50:39 ----A---- C:\windows\PKZIP.PIF
2013-07-31 21:50:39 ----A---- C:\windows\PKUNZIP.PIF
2013-07-31 21:50:39 ----A---- C:\windows\LHA.PIF
2013-07-31 21:50:39 ----A---- C:\windows\ARJ.PIF
2013-07-31 21:47:48 ----D---- C:\Users\Ervd\AppData\Roaming\TeamViewer
======List of files/folders modified in the last 1 month======
2013-08-30 18:24:53 ----D---- C:\windows\Prefetch
2013-08-30 18:24:51 ----D---- C:\Program Files\trend micro
2013-08-30 17:23:13 ----D---- C:\windows\temp
2013-08-30 15:09:27 ----D---- C:\windows\Tasks
2013-08-30 15:09:27 ----D---- C:\windows\system32\Tasks
2013-08-30 15:08:47 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-08-30 09:35:14 ----D---- C:\windows\system32\config
2013-08-30 09:21:49 ----A---- C:\windows\SYSWOW64\log.txt
2013-08-30 09:19:59 ----D---- C:\ProgramData\PDFC
2013-08-30 09:19:45 ----D---- C:\Users\Ervd\AppData\Roaming\Dropbox
2013-08-30 09:17:38 ----D---- C:\Program Files (x86)\Pando Networks
2013-08-30 00:16:29 ----SHD---- C:\windows\Installer
2013-08-30 00:09:58 ----RD---- C:\Program Files (x86)
2013-08-29 23:43:10 ----D---- C:\Users\Ervd\AppData\Roaming\Audacity
2013-08-29 23:40:29 ----D---- C:\Program Files (x86)\SpeedFan
2013-08-29 23:29:05 ----D---- C:\ProgramData
2013-08-29 23:11:16 ----D---- C:\windows\System32
2013-08-29 23:11:16 ----D---- C:\windows\inf
2013-08-29 23:11:16 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-08-29 14:41:44 ----SHD---- C:\System Volume Information
2013-08-27 12:38:31 ----D---- C:\Program Files (x86)\Voobly
2013-08-21 00:26:20 ----D---- C:\Users\Ervd\AppData\Roaming\vlc
2013-08-18 12:09:51 ----D---- C:\windows\system32\catroot2
2013-08-16 12:54:29 ----D---- C:\Windows
2013-08-15 14:28:33 ----D---- C:\windows\debug
2013-08-15 11:48:24 ----D---- C:\windows\Microsoft.NET
2013-08-15 11:48:22 ----RSD---- C:\windows\assembly
2013-08-15 03:36:58 ----D---- C:\windows\winsxs
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\sl-SI
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\sk-SK
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\hr-HR
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\en-US
2013-08-15 03:34:18 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-08-15 03:34:18 ----D---- C:\windows\SysWOW64
2013-08-15 03:34:18 ----D---- C:\windows\system32\sl-SI
2013-08-15 03:34:18 ----D---- C:\windows\system32\sk-SK
2013-08-15 03:34:18 ----D---- C:\windows\system32\hr-HR
2013-08-15 03:34:18 ----D---- C:\windows\system32\en-US
2013-08-15 03:34:18 ----D---- C:\windows\system32\cs-CZ
2013-08-15 03:34:17 ----D---- C:\windows\system32\drivers
2013-08-15 03:34:17 ----D---- C:\windows\AppPatch
2013-08-15 03:34:17 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-15 03:34:16 ----D---- C:\windows\SYSWOW64\migration
2013-08-15 03:34:16 ----D---- C:\windows\system32\migration
2013-08-15 03:34:16 ----D---- C:\Program Files\Internet Explorer
2013-08-15 03:04:36 ----A---- C:\windows\system32\MRT.exe
2013-08-15 03:03:46 ----A---- C:\windows\win.ini
2013-08-15 03:01:59 ----D---- C:\windows\system32\catroot
2013-08-15 02:41:07 ----D---- C:\Program Files (x86)\The KMPlayer
2013-08-13 00:41:26 ----D---- C:\Program Files (x86)\Diablo III
2013-08-12 06:39:30 ----D---- C:\Users\Ervd\AppData\Roaming\Apple Computer
2013-08-11 12:56:30 ----D---- C:\Program Files (x86)\Common Files
2013-08-11 12:56:15 ----A---- C:\windows\SYSWOW64\msvcr71.dll
2013-08-11 12:56:15 ----A---- C:\windows\SYSWOW64\msvcp71.dll
2013-08-11 12:47:02 ----D---- C:\windows\SYSWOW64\Adobe
2013-08-08 18:55:30 ----RSD---- C:\windows\Fonts
2013-08-08 18:55:08 ----D---- C:\Program Files (x86)\OpenOffice.org 3
2013-08-06 18:05:01 ----D---- C:\Program Files (x86)\Opera
2013-07-31 22:02:28 ----RD---- C:\Program Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;aswRvrt; C:\windows\system32\drivers\aswRvrt.sys [2013-05-09 65336]
R0 aswVmm;aswVmm; C:\windows\system32\drivers\aswVmm.sys [2013-06-28 189936]
R0 hpdskflt;HP Filter; C:\windows\system32\DRIVERS\hpdskflt.sys [2012-09-24 31040]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-01-13 439320]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2013-05-09 72016]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2013-06-28 1030952]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2013-06-28 378944]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2013-05-09 64288]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-04-02 283200]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2013-05-09 33400]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 80816]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\windows\system32\DRIVERS\Accelerometer.sys [2012-09-24 43840]
R3 Afc;PPdus ASPI Shell; C:\windows\SysWOW64\drivers\Afc.sys [2006-11-14 22784]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atikmdag.sys [2011-10-14 10496000]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2011-10-14 326656]
R3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver; C:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\drivers\HpqKbFiltr.sys [2010-12-03 25912]
R3 intelkmd;intelkmd; C:\windows\system32\DRIVERS\igdpmd64.sys [2011-09-01 12306848]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2013-05-24 708200]
R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver; C:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-07-19 1145448]
R3 SPUVCbv;SPUVCb Driver Service; C:\windows\System32\Drivers\SPUVCbv_x64.sys [2011-01-12 2611704]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2013-05-24 543744]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2013-01-29 468720]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BrUsbScn;Ovladač skeneru Brother MFC USB; C:\windows\System32\Drivers\BrUsbScn.sys [2009-06-10 14336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-01-02 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-06-30 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-07-16 30208]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2011-02-08 486144]
S3 ggflt;SEMC USB Flash Driver Filter; C:\windows\system32\DRIVERS\ggflt.sys [2013-01-16 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\windows\system32\DRIVERS\ggsemc.sys [2013-01-16 27760]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-09-01 12306848]
S3 JMCR;JMCR; C:\windows\system32\DRIVERS\jmcr.sys [2013-05-24 175928]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-27 26112]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 trufos;trufos; C:\windows\system32\drivers\trufos.sys [2013-03-07 350160]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\drivers\usb8023x.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2013-05-08 143088]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2013-05-24 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2011-10-14 204288]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-05-09 46808]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2011-02-15 680016]
R2 brmfrsmg;Brother Resource manager service; C:\windows\system32\BrmfRsmg.exe [2009-07-14 52736]
R2 HP Power Assistant Service;HP Power Assistant Service; C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2012-09-27 86528]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-09-06 197536]
R2 hpHotkeyMonitor;hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2012-06-20 523680]
R2 hpsrv;HP Service; C:\windows\system32\Hpservice.exe [2012-09-24 31040]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-01-17 326168]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 PDF Architect Helper Service;PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [2013-04-08 1320496]
R2 PDF Architect Service;PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [2013-04-08 799280]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-08-11 1128952]
R2 PdiService;Portrait Displays SDK Service; C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-04-16 39056]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2013-05-24 323072]
R2 uArcCapture;ArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2011-02-08 4151376]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-06-09 1028096]
R3 hpCMSrv;HP Connection Manager 4 Service; C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2012-09-05 1420192]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2012-09-06 1001376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-19 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-06-03 162408]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-13 257416]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2011-02-28 1189968]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater; C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-06-09 647680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-18 116648]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-08-01 724888]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-06-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: prosím o preventivku
Zdravim
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe


- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte

- Ukoncete vsechny programy
- Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
- Pockejte na dokonceni PreScanu
- Zvolte moznost Prohledat (scan)
- Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
- Detailni postup vc. obrazku mate zde http://forum.viry.cz/viewtopic.php?f=24&t=120452
Re: prosím o preventivku
# AdwCleaner v3.001 - Report created 30/08/2013 at 19:25:18
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Ervd - ERVD-HP
# Running from : C:\Users\Ervd\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Ervd\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Users\Ervd\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Ervd\AppData\Roaming\pdfforge
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\PrivitizeVPNInstallDates
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\PIP
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16502
-\\ Google Chrome v
[ File : C:\Users\Ervd\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1727 octets] - [30/08/2013 19:23:09]
AdwCleaner[S0].txt - [1498 octets] - [30/08/2013 19:25:18]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1558 octets] ##########
RogueKiller V8.6.7 [Aug 28 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Ervd [Práva správce]
Mód : Kontrola -- Datum : 08/30/2013 19:35:53
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 9 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL] HKLM\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: ST9500325AS +++++
--- User ---
[MBR] 76389014698c73da1ecd284cf7ae17bb
[BSP] 8004967edd69358a720b7836bd2190dd : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 455337 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 933146624 | Size: 16179 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 966281216 | Size: 5122 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] b1720ed790fa5382d7b9f8ffea4089de
[BSP] 8004967edd69358a720b7836bd2190dd : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 61440 Mo
2 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 167999488 | Size: 1001 Mo
3 - [XXXXXX] FAT16 (0x06) [VISIBLE] Offset (sectors): 171999232 | Size: 1000 Mo
Dokončeno : << RKreport[0]_S_08302013_193553.txt >>
# Updated 24/08/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Ervd - ERVD-HP
# Running from : C:\Users\Ervd\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Ervd\AppData\Roaming\ExpressFiles
Folder Deleted : C:\Users\Ervd\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Ervd\AppData\Roaming\pdfforge
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\PrivitizeVPNInstallDates
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\PIP
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16502
-\\ Google Chrome v
[ File : C:\Users\Ervd\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1727 octets] - [30/08/2013 19:23:09]
AdwCleaner[S0].txt - [1498 octets] - [30/08/2013 19:25:18]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1558 octets] ##########
RogueKiller V8.6.7 [Aug 28 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Ervd [Práva správce]
Mód : Kontrola -- Datum : 08/30/2013 19:35:53
| ARK || FAK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 9 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL] HKLM\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ naplánované úlohy : 0 ¤¤¤
¤¤¤ spuštění položky : 0 ¤¤¤
¤¤¤ Webové prohlížeče : 0 ¤¤¤
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤
¤¤¤ Externí včelstvo: ¤¤¤
¤¤¤ Nákaza : ¤¤¤
¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: ST9500325AS +++++
--- User ---
[MBR] 76389014698c73da1ecd284cf7ae17bb
[BSP] 8004967edd69358a720b7836bd2190dd : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 455337 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 933146624 | Size: 16179 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 966281216 | Size: 5122 Mo
User = LL1 ... OK!
User != LL2 ... KO!
--- LL2 ---
[MBR] b1720ed790fa5382d7b9f8ffea4089de
[BSP] 8004967edd69358a720b7836bd2190dd : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 61440 Mo
2 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 167999488 | Size: 1001 Mo
3 - [XXXXXX] FAT16 (0x06) [VISIBLE] Offset (sectors): 171999232 | Size: 1000 Mo
Dokončeno : << RKreport[0]_S_08302013_193553.txt >>
Re: prosím o preventivku
Poprosim o spusteni nasledujiciho
Aplikace ke stažení:
Po stažení FRSTLauncher spustte, objevi se mozna varovani od antiviru, ignorujte a nechte FRSTL spustit
Následně dojde ke stažení FRST a inicializaci



- Po spuštění FRST odsouhlasíme licenční podmínky kliknutím na Ano.
- Dooznačíme položku Addition.txt - viz obrázek.
- Klikneme na tlačítko Scan čímž spustíme skenování.
- Počkáme na dokončení skenování FRST a vytvoření doplňkových informací naší nástavbou.
- Otevře se nám textový soubor FRST.txt, což je požadovaný log a jehož obsah vložíme do svého tématu na fóru.
- Po uzavření logu se FRSTLauncher.exe ukončí a na ploše nám zbyde utilta FRST a dva logy FRST.txt a Addition.txt - nic z toho zatím nemažeme.
Re: prosím o preventivku
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-08-2013
Ran by Ervd (administrator) on 30-08-2013 21:05:38
Running from C:\Users\Ervd\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Brother Industries, Ltd.) C:\windows\system32\BrmfRsmg.exe
(Brother Industries, Ltd.) C:\windows\system32\BrmfRsmg.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Dropbox, Inc.) C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(ArcSoft, Inc.) C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\PDF Architect.exe
(Microsoft Corporation) \\?\C:\windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IME14 JPN Uninstall] - C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110896 2012-03-14] (Microsoft Corporation)
HKLM\...\Run: [IME14 KOR Uninstall] - C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110896 2012-03-14] (Microsoft Corporation)
HKLM\...\Run: [IME14 CHS Uninstall] - C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110896 2012-03-14] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3011824 2013-01-29] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-24] (IDT, Inc.)
HKLM-x32\...\Run: [NUSB3MON] - c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] - C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] ()
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-08-11] (RealNetworks, Inc.)
Startup: C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchab.com/?aff=7&uid=a261b29e ... earchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
Handler: msdaipp - No CLSID Value -
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.100.250
Chrome:
=======
CHR Extension: (MagniPic) - C:\Users\Ervd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbhhfnefnjpcnghkojnkjcomonolammf\1
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143088 2013-05-08] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 brmfrsmg; C:\Windows\system32\BrmfRsmg.exe [52736 2009-07-14] (Brother Industries, Ltd.)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-06-20] (Hewlett-Packard Company)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-11] (PDF Complete Inc)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
==================== Drivers (Whitelisted) ====================
R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] ()
S3 BrUsbScn; C:\Windows\System32\Drivers\BrUsbScn.sys [14336 2009-06-10] (Brother Industries Ltd.)
S3 BTMNET; C:\Windows\System32\DRIVERS\btmnet.sys [30208 2010-07-16] (Motorola, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-04-02] (DT Soft Ltd)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2611704 2011-01-12] (Sunplus Technology)
S3 trufos; C:\Windows\System32\drivers\trufos.sys [350160 2013-03-07] (BitDefender S.R.L.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-30 21:04 - 2013-08-30 21:04 - 00000000 ____D C:\Users\Ervd\AppData\Local\qb59FD53.62
2013-08-30 21:04 - 2013-08-27 21:11 - 01579080 _____ (Farbar) C:\Users\Ervd\Desktop\FRST64.exe
2013-08-30 21:03 - 2013-08-30 21:03 - 00000000 ____D C:\Users\Ervd\Desktop\STAPS
2013-08-30 20:13 - 2013-08-30 20:13 - 00238506 _____ C:\Users\Ervd\Desktop\chyby měření
2013-08-30 19:35 - 2013-08-30 19:35 - 00002699 _____ C:\Users\Ervd\Desktop\RKreport[0]_S_08302013_193553.txt
2013-08-30 19:33 - 2013-08-30 19:44 - 00000000 ____D C:\Users\Ervd\Desktop\RK_Quarantine
2013-08-30 19:33 - 2013-08-30 19:33 - 00913408 _____ C:\Users\Ervd\Desktop\RogueKiller.exe
2013-08-30 19:23 - 2013-08-30 19:25 - 00000000 ____D C:\AdwCleaner
2013-08-30 19:22 - 2013-08-30 19:22 - 00994642 _____ C:\Users\Ervd\Desktop\adwcleaner.exe
2013-08-30 00:09 - 2013-08-30 00:14 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install
2013-08-29 23:33 - 2013-08-30 00:03 - 58283225 _____ C:\Users\Ervd\Desktop\Cimrman - Švestka (divadelní záznam).3gp
2013-08-29 23:27 - 2013-08-29 23:27 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2013-08-29 23:23 - 2013-08-29 23:23 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Youtube Downloader HD
2013-08-29 15:23 - 2013-08-29 15:24 - 31026832 _____ (Opera Software ASA) C:\Users\Ervd\Downloads\Opera_15.0.1147.153_Setup.exe
2013-08-28 12:13 - 2013-08-30 19:27 - 00003200 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-28 12:12 - 2013-08-30 19:27 - 00003336 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-26 15:16 - 2013-08-26 15:23 - 308105840 _____ C:\Users\Ervd\Desktop\Výzkumák IV.zip
2013-08-20 02:53 - 2013-08-20 02:53 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-08-18 01:17 - 2013-08-18 01:17 - 00000125 _____ C:\Users\Ervd\Desktop\film+.m3u
2013-08-16 12:54 - 2013-08-30 19:26 - 00001288 _____ C:\windows\setupact.log
2013-08-16 12:54 - 2013-08-30 09:17 - 00003256 _____ C:\windows\PFRO.log
2013-08-16 12:54 - 2013-08-16 12:54 - 00000000 _____ C:\windows\setuperr.log
2013-08-15 03:04 - 2013-08-15 03:11 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 03:01 - 2013-07-25 05:54 - 17830400 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-15 03:01 - 2013-07-25 05:37 - 02312704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-15 03:01 - 2013-07-25 05:35 - 10926080 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-15 03:01 - 2013-07-25 05:31 - 01346560 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-15 03:01 - 2013-07-25 05:30 - 01392128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-15 03:01 - 2013-07-25 05:29 - 01494528 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-08-15 03:01 - 2013-07-25 05:29 - 00237056 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2013-08-15 03:01 - 2013-07-25 05:29 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 02147840 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00599040 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-08-15 03:01 - 2013-07-25 05:27 - 02382848 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-15 03:01 - 2013-07-25 05:27 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2013-08-15 03:01 - 2013-07-25 05:26 - 00248320 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-15 03:01 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-08-15 03:01 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-08-15 03:01 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-08-15 03:01 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-08-15 03:01 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-08-15 03:01 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-08-15 03:01 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2013-08-15 03:01 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2013-08-15 03:01 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-08-15 03:01 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-08-15 03:01 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2013-08-14 20:29 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-14 20:29 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2013-08-14 20:29 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-14 20:29 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-08-14 20:29 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-14 20:29 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-14 20:29 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-08-14 20:29 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-14 20:29 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-14 20:29 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-14 20:29 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-14 20:29 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-14 20:29 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-08-14 20:29 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-08-14 20:29 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-08-14 20:29 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2013-08-14 20:29 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2013-08-14 20:29 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-08-14 20:29 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2013-08-14 20:29 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2013-08-14 20:29 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-08-14 20:28 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-08-14 20:28 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-08-14 20:28 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-08-14 20:28 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-08-14 20:28 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-14 20:28 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2013-08-12 14:49 - 2013-08-12 15:17 - 00000000 ____D C:\ICQ
2013-08-12 14:48 - 2013-08-21 05:44 - 00000000 ____D C:\Program Files (x86)\QIP 2012
2013-08-12 14:48 - 2013-08-12 15:18 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\QIP
2013-08-12 14:48 - 2013-08-12 14:48 - 00001078 _____ C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\QIP 2012.lnk
2013-08-12 14:48 - 2013-08-12 14:48 - 00001054 _____ C:\Users\Ervd\Desktop\QIP 2012.lnk
2013-08-11 15:14 - 2013-08-11 15:14 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple Computer
2013-08-11 12:57 - 2013-08-11 12:57 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00272896 _____ (Progressive Networks) C:\windows\SysWOW64\pncrt.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00201872 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\rmoc3260.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00006656 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5016.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00005632 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5032.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\ProgramData\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\Real
2013-08-11 12:55 - 2013-08-11 12:57 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Real
2013-08-11 12:54 - 2013-08-11 12:57 - 00000000 ____D C:\ProgramData\Real
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\ProgramData\Apple Computer
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\ProgramData\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-08-11 12:49 - 2013-08-11 12:49 - 00000000 ____D C:\PFiles
2013-08-09 16:15 - 2013-08-09 16:15 - 00036309 _____ C:\Users\Ervd\Documents\tvrdost b.xlsx
2013-08-08 19:36 - 2013-08-08 19:36 - 00036243 _____ C:\Users\Ervd\Documents\tvrdost a.xlsx
2013-08-08 18:56 - 2013-08-08 18:56 - 00001100 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-08-08 18:56 - 2013-08-08 18:56 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\OpenOffice
2013-08-08 18:55 - 2013-08-08 18:55 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-08 18:52 - 2013-08-08 18:52 - 00000000 ____D C:\Users\Ervd\Desktop\OpenOffice 4.0.0 (cs) Installation Files
2013-08-08 18:49 - 2013-08-08 18:51 - 00027136 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.xls
2013-08-08 18:49 - 2013-08-08 18:49 - 00043124 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00043125 _____ C:\Users\Ervd\Documents\tvrdost - pokus.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00025088 _____ C:\Users\Ervd\Documents\tvrdost - pokus.xls
2013-08-08 18:05 - 2013-08-08 18:05 - 00072055 _____ C:\Users\Ervd\Documents\tvrdostXXX2.ods
2013-08-06 18:04 - 2013-08-06 18:04 - 00001829 _____ C:\Users\Public\Desktop\Opera.lnk
2013-07-31 21:57 - 2013-07-31 21:57 - 00000000 ____D C:\Users\Ervd\AppData\Local\GHISLER
2013-07-31 21:55 - 2013-07-31 21:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-31 21:50 - 2013-07-31 21:50 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\GHISLER
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\UC.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\RAR.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\PKZIP.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\PKUNZIP.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\LHA.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\ARJ.PIF
2013-07-31 21:47 - 2013-07-31 21:47 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\TeamViewer
==================== One Month Modified Files and Folders =======
2013-08-30 21:05 - 2013-08-30 21:05 - 00000000 ____D C:\FRST
2013-08-30 21:04 - 2013-08-30 21:04 - 00000000 ____D C:\Users\Ervd\AppData\Local\qb59FD53.62
2013-08-30 21:04 - 2012-06-09 19:43 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-30 21:03 - 2013-08-30 21:03 - 00000000 ____D C:\Users\Ervd\Desktop\STAPS
2013-08-30 20:48 - 2012-09-18 20:35 - 00000948 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-30 20:32 - 2013-06-13 17:31 - 01218690 _____ C:\windows\WindowsUpdate.log
2013-08-30 20:13 - 2013-08-30 20:13 - 00238506 _____ C:\Users\Ervd\Desktop\chyby měření
2013-08-30 19:44 - 2013-08-30 19:33 - 00000000 ____D C:\Users\Ervd\Desktop\RK_Quarantine
2013-08-30 19:35 - 2013-08-30 19:35 - 00002699 _____ C:\Users\Ervd\Desktop\RKreport[0]_S_08302013_193553.txt
2013-08-30 19:35 - 2009-07-14 06:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-30 19:35 - 2009-07-14 06:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-30 19:33 - 2013-08-30 19:33 - 00913408 _____ C:\Users\Ervd\Desktop\RogueKiller.exe
2013-08-30 19:28 - 2013-05-12 13:40 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-08-30 19:27 - 2013-08-28 12:13 - 00003200 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-30 19:27 - 2013-08-28 12:12 - 00003336 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-30 19:27 - 2012-09-08 12:39 - 00000000 ___RD C:\Users\Ervd\Dropbox
2013-08-30 19:27 - 2012-09-08 12:37 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Dropbox
2013-08-30 19:27 - 2012-01-02 20:41 - 00000000 ____D C:\ProgramData\PDFC
2013-08-30 19:26 - 2013-08-16 12:54 - 00001288 _____ C:\windows\setupact.log
2013-08-30 19:26 - 2013-04-26 22:57 - 00000328 _____ C:\windows\Tasks\HPCeeScheduleForErvd.job
2013-08-30 19:26 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-30 19:25 - 2013-08-30 19:23 - 00000000 ____D C:\AdwCleaner
2013-08-30 19:22 - 2013-08-30 19:22 - 00994642 _____ C:\Users\Ervd\Desktop\adwcleaner.exe
2013-08-30 18:24 - 2012-08-01 17:34 - 00000000 ____D C:\Program Files\trend micro
2013-08-30 18:24 - 2012-08-01 17:32 - 00935175 _____ C:\Users\Ervd\Desktop\RSITx64.exe
2013-08-30 15:09 - 2013-04-26 22:57 - 00003180 _____ C:\windows\System32\Tasks\HPCeeScheduleForErvd
2013-08-30 15:09 - 2012-06-18 11:46 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2013-08-30 15:08 - 2012-06-29 15:24 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-08-30 09:17 - 2013-08-16 12:54 - 00003256 _____ C:\windows\PFRO.log
2013-08-30 09:17 - 2013-06-14 13:04 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2013-08-30 00:16 - 2013-06-26 19:54 - 00001885 _____ C:\Users\Public\Desktop\Media Go.lnk
2013-08-30 00:16 - 2012-06-09 16:08 - 00000000 ____D C:\Users\Ervd
2013-08-30 00:14 - 2013-08-30 00:09 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install
2013-08-30 00:13 - 2012-06-09 16:29 - 00000000 ____D C:\Users\Ervd\AppData\Local\Downloaded Installations
2013-08-30 00:03 - 2013-08-29 23:33 - 58283225 _____ C:\Users\Ervd\Desktop\Cimrman - Švestka (divadelní záznam).3gp
2013-08-29 23:43 - 2013-06-25 10:14 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Audacity
2013-08-29 23:40 - 2013-06-18 11:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-08-29 23:27 - 2013-08-29 23:27 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2013-08-29 23:23 - 2013-08-29 23:23 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Youtube Downloader HD
2013-08-29 23:11 - 2012-01-02 19:36 - 00669736 _____ C:\windows\system32\perfh005.dat
2013-08-29 23:11 - 2012-01-02 19:36 - 00141336 _____ C:\windows\system32\perfc005.dat
2013-08-29 23:11 - 2009-07-14 07:13 - 01585238 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-29 21:42 - 2012-10-02 19:53 - 00000000 ____D C:\Users\Ervd\Documents\FJFI
2013-08-29 15:24 - 2013-08-29 15:23 - 31026832 _____ (Opera Software ASA) C:\Users\Ervd\Downloads\Opera_15.0.1147.153_Setup.exe
2013-08-27 21:11 - 2013-08-30 21:04 - 01579080 _____ (Farbar) C:\Users\Ervd\Desktop\FRST64.exe
2013-08-27 14:08 - 2012-06-09 16:55 - 00000000 ____D C:\Users\Ervd\AppData\Local\PDFC
2013-08-27 12:38 - 2013-03-29 09:38 - 00000000 ____D C:\Program Files (x86)\Voobly
2013-08-26 15:23 - 2013-08-26 15:16 - 308105840 _____ C:\Users\Ervd\Desktop\Výzkumák IV.zip
2013-08-26 02:15 - 2012-06-15 16:30 - 00000000 ____D C:\Users\Ervd\AppData\Local\CrashDumps
2013-08-21 05:44 - 2013-08-12 14:48 - 00000000 ____D C:\Program Files (x86)\QIP 2012
2013-08-21 00:26 - 2013-03-23 16:54 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\vlc
2013-08-20 02:53 - 2013-08-20 02:53 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-08-18 01:17 - 2013-08-18 01:17 - 00000125 _____ C:\Users\Ervd\Desktop\film+.m3u
2013-08-16 12:54 - 2013-08-16 12:54 - 00000000 _____ C:\windows\setuperr.log
2013-08-15 15:12 - 2012-07-11 13:01 - 00003216 _____ C:\windows\System32\Tasks\HPCeeScheduleForERVD-HP$
2013-08-15 15:12 - 2012-07-11 13:01 - 00000340 _____ C:\windows\Tasks\HPCeeScheduleForERVD-HP$.job
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\SysWOW64\sl-SI
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\SysWOW64\sk-SK
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\SysWOW64\hr-HR
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\sl-SI
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\sk-SK
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\hr-HR
2013-08-15 03:11 - 2013-08-15 03:04 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 03:04 - 2012-06-09 18:29 - 78161360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-08-15 03:03 - 2009-07-14 04:34 - 00000876 _____ C:\windows\win.ini
2013-08-15 02:41 - 2013-06-01 23:39 - 00000000 ____D C:\Program Files (x86)\The KMPlayer
2013-08-13 00:41 - 2013-02-13 12:38 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-08-12 15:18 - 2013-08-12 14:48 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\QIP
2013-08-12 15:17 - 2013-08-12 14:49 - 00000000 ____D C:\ICQ
2013-08-12 14:48 - 2013-08-12 14:48 - 00001078 _____ C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\QIP 2012.lnk
2013-08-12 14:48 - 2013-08-12 14:48 - 00001054 _____ C:\Users\Ervd\Desktop\QIP 2012.lnk
2013-08-12 06:39 - 2012-10-18 20:21 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Apple Computer
2013-08-11 15:14 - 2013-08-11 15:14 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple Computer
2013-08-11 12:57 - 2013-08-11 12:57 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\RealNetworks
2013-08-11 12:57 - 2013-08-11 12:55 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Real
2013-08-11 12:57 - 2013-08-11 12:54 - 00000000 ____D C:\ProgramData\Real
2013-08-11 12:56 - 2013-08-11 12:56 - 00272896 _____ (Progressive Networks) C:\windows\SysWOW64\pncrt.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00201872 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\rmoc3260.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00006656 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5016.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00005632 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5032.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\ProgramData\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\Real
2013-08-11 12:56 - 2013-02-14 15:13 - 00499712 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp71.dll
2013-08-11 12:56 - 2013-02-14 15:13 - 00348160 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr71.dll
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\ProgramData\Apple Computer
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\ProgramData\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-08-11 12:49 - 2013-08-11 12:49 - 00000000 ____D C:\PFiles
2013-08-11 12:47 - 2012-11-17 14:46 - 00000000 ____D C:\windows\SysWOW64\Adobe
2013-08-10 09:59 - 2009-07-14 06:45 - 00445272 _____ C:\windows\system32\FNTCACHE.DAT
2013-08-09 16:15 - 2013-08-09 16:15 - 00036309 _____ C:\Users\Ervd\Documents\tvrdost b.xlsx
2013-08-08 19:39 - 2012-06-09 16:52 - 00115688 _____ C:\Users\Ervd\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-08 19:36 - 2013-08-08 19:36 - 00036243 _____ C:\Users\Ervd\Documents\tvrdost a.xlsx
2013-08-08 18:56 - 2013-08-08 18:56 - 00001100 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-08-08 18:56 - 2013-08-08 18:56 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\OpenOffice
2013-08-08 18:55 - 2013-08-08 18:55 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-08 18:55 - 2012-06-12 15:53 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-08-08 18:52 - 2013-08-08 18:52 - 00000000 ____D C:\Users\Ervd\Desktop\OpenOffice 4.0.0 (cs) Installation Files
2013-08-08 18:51 - 2013-08-08 18:49 - 00027136 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.xls
2013-08-08 18:49 - 2013-08-08 18:49 - 00043124 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00043125 _____ C:\Users\Ervd\Documents\tvrdost - pokus.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00025088 _____ C:\Users\Ervd\Documents\tvrdost - pokus.xls
2013-08-08 18:05 - 2013-08-08 18:05 - 00072055 _____ C:\Users\Ervd\Documents\tvrdostXXX2.ods
2013-08-06 18:05 - 2012-06-09 19:41 - 00000000 ____D C:\Program Files (x86)\Opera
2013-08-06 18:04 - 2013-08-06 18:04 - 00001829 _____ C:\Users\Public\Desktop\Opera.lnk
2013-08-01 14:39 - 2012-06-09 16:55 - 00001393 _____ C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-31 21:57 - 2013-07-31 21:57 - 00000000 ____D C:\Users\Ervd\AppData\Local\GHISLER
2013-07-31 21:55 - 2013-07-31 21:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-31 21:50 - 2013-07-31 21:50 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\GHISLER
2013-07-31 21:47 - 2013-07-31 21:47 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\TeamViewer
Files to move or delete:
====================
C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe
C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Scheduled Tasks (whitelisted) ===========
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForERVD-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForErvd.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Supplementary Scan (All) ================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent
rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium
"C:\Program Files (x86)\QIP 2012\qip.exe" /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess
"C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor
"C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete
C:\Program Files (x86)\PDF Complete\pdfsty.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files (x86)\Steam\Steam.exe" -silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader
C:\Program Files\VDownloader\VDownloader.exe /silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly
"C:\Program Files (x86)\Voobly\voobly.exe" --startup [x]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000000
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000000
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=dword:00000099
"NoDrives"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"FirewallDisableNotify"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"VIDC.YVU9"="tsbyuv.dll"
"msacm.l3acm"="l3codecp.acm"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"MSVideo8"="VfWWDM32.dll"
"VIDC.LAGS"="lagarith.dll"
"VIDC.FFDS"="ff_vfw.dll"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:444.67 GB) (Free:192.72 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:15.8 GB) (Free:2.37 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:4.99 GB) (Free:2.11 GB) FAT32
Drive h: () (Removable) (Total:29.82 GB) (Free:5.71 GB) FAT32
Available physical RAM: 1713.11 MB
Total physical RAM: 4030.36 MB
Percentage of memory in use: 57%
LastRegBack: 2013-08-22 18:13
==================== End Of Log ==============================
Ran by Ervd (administrator) on 30-08-2013 21:05:38
Running from C:\Users\Ervd\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Brother Industries, Ltd.) C:\windows\system32\BrmfRsmg.exe
(Brother Industries, Ltd.) C:\windows\system32\BrmfRsmg.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Dropbox, Inc.) C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(ArcSoft, Inc.) C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\PDF Architect.exe
(Microsoft Corporation) \\?\C:\windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IME14 JPN Uninstall] - C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110896 2012-03-14] (Microsoft Corporation)
HKLM\...\Run: [IME14 KOR Uninstall] - C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110896 2012-03-14] (Microsoft Corporation)
HKLM\...\Run: [IME14 CHS Uninstall] - C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110896 2012-03-14] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3011824 2013-01-29] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-24] (IDT, Inc.)
HKLM-x32\...\Run: [NUSB3MON] - c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2011-10-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] - C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] ()
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-08-11] (RealNetworks, Inc.)
Startup: C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Ervd\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchab.com/?aff=7&uid=a261b29e ... earchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/In ... ect119.cab
Handler: msdaipp - No CLSID Value -
Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
Handler-x32: msdaipp - No CLSID Value -
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.100.250
Chrome:
=======
CHR Extension: (MagniPic) - C:\Users\Ervd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbhhfnefnjpcnghkojnkjcomonolammf\1
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
==================== Services (Whitelisted) =================
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [143088 2013-05-08] (SUPERAntiSpyware.com)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 brmfrsmg; C:\Windows\system32\BrmfRsmg.exe [52736 2009-07-14] (Brother Industries, Ltd.)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-06-20] (Hewlett-Packard Company)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-11] (PDF Complete Inc)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
==================== Drivers (Whitelisted) ====================
R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] ()
S3 BrUsbScn; C:\Windows\System32\Drivers\BrUsbScn.sys [14336 2009-06-10] (Brother Industries Ltd.)
S3 BTMNET; C:\Windows\System32\DRIVERS\btmnet.sys [30208 2010-07-16] (Motorola, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-04-02] (DT Soft Ltd)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2611704 2011-01-12] (Sunplus Technology)
S3 trufos; C:\Windows\System32\drivers\trufos.sys [350160 2013-03-07] (BitDefender S.R.L.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-30 21:04 - 2013-08-30 21:04 - 00000000 ____D C:\Users\Ervd\AppData\Local\qb59FD53.62
2013-08-30 21:04 - 2013-08-27 21:11 - 01579080 _____ (Farbar) C:\Users\Ervd\Desktop\FRST64.exe
2013-08-30 21:03 - 2013-08-30 21:03 - 00000000 ____D C:\Users\Ervd\Desktop\STAPS
2013-08-30 20:13 - 2013-08-30 20:13 - 00238506 _____ C:\Users\Ervd\Desktop\chyby měření
2013-08-30 19:35 - 2013-08-30 19:35 - 00002699 _____ C:\Users\Ervd\Desktop\RKreport[0]_S_08302013_193553.txt
2013-08-30 19:33 - 2013-08-30 19:44 - 00000000 ____D C:\Users\Ervd\Desktop\RK_Quarantine
2013-08-30 19:33 - 2013-08-30 19:33 - 00913408 _____ C:\Users\Ervd\Desktop\RogueKiller.exe
2013-08-30 19:23 - 2013-08-30 19:25 - 00000000 ____D C:\AdwCleaner
2013-08-30 19:22 - 2013-08-30 19:22 - 00994642 _____ C:\Users\Ervd\Desktop\adwcleaner.exe
2013-08-30 00:09 - 2013-08-30 00:14 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install
2013-08-29 23:33 - 2013-08-30 00:03 - 58283225 _____ C:\Users\Ervd\Desktop\Cimrman - Švestka (divadelní záznam).3gp
2013-08-29 23:27 - 2013-08-29 23:27 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2013-08-29 23:23 - 2013-08-29 23:23 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Youtube Downloader HD
2013-08-29 15:23 - 2013-08-29 15:24 - 31026832 _____ (Opera Software ASA) C:\Users\Ervd\Downloads\Opera_15.0.1147.153_Setup.exe
2013-08-28 12:13 - 2013-08-30 19:27 - 00003200 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-28 12:12 - 2013-08-30 19:27 - 00003336 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-26 15:16 - 2013-08-26 15:23 - 308105840 _____ C:\Users\Ervd\Desktop\Výzkumák IV.zip
2013-08-20 02:53 - 2013-08-20 02:53 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-08-18 01:17 - 2013-08-18 01:17 - 00000125 _____ C:\Users\Ervd\Desktop\film+.m3u
2013-08-16 12:54 - 2013-08-30 19:26 - 00001288 _____ C:\windows\setupact.log
2013-08-16 12:54 - 2013-08-30 09:17 - 00003256 _____ C:\windows\PFRO.log
2013-08-16 12:54 - 2013-08-16 12:54 - 00000000 _____ C:\windows\setuperr.log
2013-08-15 03:04 - 2013-08-15 03:11 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 03:01 - 2013-07-25 05:54 - 17830400 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-08-15 03:01 - 2013-07-25 05:37 - 02312704 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-08-15 03:01 - 2013-07-25 05:35 - 10926080 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-08-15 03:01 - 2013-07-25 05:31 - 01346560 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-08-15 03:01 - 2013-07-25 05:30 - 01392128 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-08-15 03:01 - 2013-07-25 05:29 - 01494528 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-08-15 03:01 - 2013-07-25 05:29 - 00237056 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2013-08-15 03:01 - 2013-07-25 05:29 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 02147840 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00729088 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00599040 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2013-08-15 03:01 - 2013-07-25 05:28 - 00173056 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-08-15 03:01 - 2013-07-25 05:27 - 02382848 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-08-15 03:01 - 2013-07-25 05:27 - 00096768 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2013-08-15 03:01 - 2013-07-25 05:26 - 00248320 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-08-15 03:01 - 2013-07-25 04:40 - 12334080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-08-15 03:01 - 2013-07-25 04:32 - 01800704 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-08-15 03:01 - 2013-07-25 04:30 - 09738752 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-08-15 03:01 - 2013-07-25 04:26 - 01129472 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-08-15 03:01 - 2013-07-25 04:26 - 01104384 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-08-15 03:01 - 2013-07-25 04:25 - 01427968 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-08-15 03:01 - 2013-07-25 04:24 - 00231936 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2013-08-15 03:01 - 2013-07-25 04:24 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 01796096 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00717824 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00420864 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2013-08-15 03:01 - 2013-07-25 04:23 - 00142848 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2013-08-15 03:01 - 2013-07-25 04:22 - 02382848 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-08-15 03:01 - 2013-07-25 04:22 - 00176640 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-08-15 03:01 - 2013-07-25 04:22 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2013-08-14 20:29 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2013-08-14 20:29 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2013-08-14 20:29 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-08-14 20:29 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-08-14 20:29 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2013-08-14 20:29 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2013-08-14 20:29 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2013-08-14 20:29 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2013-08-14 20:29 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2013-08-14 20:29 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-08-14 20:29 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2013-08-14 20:29 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
2013-08-14 20:29 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2013-08-14 20:29 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2013-08-14 20:29 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2013-08-14 20:29 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2013-08-14 20:29 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2013-08-14 20:29 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2013-08-14 20:29 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2013-08-14 20:29 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
2013-08-14 20:29 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2013-08-14 20:28 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2013-08-14 20:28 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2013-08-14 20:28 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2013-08-14 20:28 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2013-08-14 20:28 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2013-08-14 20:28 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2013-08-12 14:49 - 2013-08-12 15:17 - 00000000 ____D C:\ICQ
2013-08-12 14:48 - 2013-08-21 05:44 - 00000000 ____D C:\Program Files (x86)\QIP 2012
2013-08-12 14:48 - 2013-08-12 15:18 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\QIP
2013-08-12 14:48 - 2013-08-12 14:48 - 00001078 _____ C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\QIP 2012.lnk
2013-08-12 14:48 - 2013-08-12 14:48 - 00001054 _____ C:\Users\Ervd\Desktop\QIP 2012.lnk
2013-08-11 15:14 - 2013-08-11 15:14 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple Computer
2013-08-11 12:57 - 2013-08-11 12:57 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00272896 _____ (Progressive Networks) C:\windows\SysWOW64\pncrt.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00201872 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\rmoc3260.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00006656 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5016.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00005632 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5032.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\ProgramData\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\Real
2013-08-11 12:55 - 2013-08-11 12:57 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Real
2013-08-11 12:54 - 2013-08-11 12:57 - 00000000 ____D C:\ProgramData\Real
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\ProgramData\Apple Computer
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\ProgramData\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-08-11 12:49 - 2013-08-11 12:49 - 00000000 ____D C:\PFiles
2013-08-09 16:15 - 2013-08-09 16:15 - 00036309 _____ C:\Users\Ervd\Documents\tvrdost b.xlsx
2013-08-08 19:36 - 2013-08-08 19:36 - 00036243 _____ C:\Users\Ervd\Documents\tvrdost a.xlsx
2013-08-08 18:56 - 2013-08-08 18:56 - 00001100 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-08-08 18:56 - 2013-08-08 18:56 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\OpenOffice
2013-08-08 18:55 - 2013-08-08 18:55 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-08 18:52 - 2013-08-08 18:52 - 00000000 ____D C:\Users\Ervd\Desktop\OpenOffice 4.0.0 (cs) Installation Files
2013-08-08 18:49 - 2013-08-08 18:51 - 00027136 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.xls
2013-08-08 18:49 - 2013-08-08 18:49 - 00043124 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00043125 _____ C:\Users\Ervd\Documents\tvrdost - pokus.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00025088 _____ C:\Users\Ervd\Documents\tvrdost - pokus.xls
2013-08-08 18:05 - 2013-08-08 18:05 - 00072055 _____ C:\Users\Ervd\Documents\tvrdostXXX2.ods
2013-08-06 18:04 - 2013-08-06 18:04 - 00001829 _____ C:\Users\Public\Desktop\Opera.lnk
2013-07-31 21:57 - 2013-07-31 21:57 - 00000000 ____D C:\Users\Ervd\AppData\Local\GHISLER
2013-07-31 21:55 - 2013-07-31 21:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-31 21:50 - 2013-07-31 21:50 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\GHISLER
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\UC.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\RAR.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\PKZIP.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\PKUNZIP.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\LHA.PIF
2013-07-31 21:50 - 2012-08-03 08:01 - 00000545 _____ C:\windows\ARJ.PIF
2013-07-31 21:47 - 2013-07-31 21:47 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\TeamViewer
==================== One Month Modified Files and Folders =======
2013-08-30 21:05 - 2013-08-30 21:05 - 00000000 ____D C:\FRST
2013-08-30 21:04 - 2013-08-30 21:04 - 00000000 ____D C:\Users\Ervd\AppData\Local\qb59FD53.62
2013-08-30 21:04 - 2012-06-09 19:43 - 00000914 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-08-30 21:03 - 2013-08-30 21:03 - 00000000 ____D C:\Users\Ervd\Desktop\STAPS
2013-08-30 20:48 - 2012-09-18 20:35 - 00000948 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-30 20:32 - 2013-06-13 17:31 - 01218690 _____ C:\windows\WindowsUpdate.log
2013-08-30 20:13 - 2013-08-30 20:13 - 00238506 _____ C:\Users\Ervd\Desktop\chyby měření
2013-08-30 19:44 - 2013-08-30 19:33 - 00000000 ____D C:\Users\Ervd\Desktop\RK_Quarantine
2013-08-30 19:35 - 2013-08-30 19:35 - 00002699 _____ C:\Users\Ervd\Desktop\RKreport[0]_S_08302013_193553.txt
2013-08-30 19:35 - 2009-07-14 06:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-30 19:35 - 2009-07-14 06:45 - 00028576 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-30 19:33 - 2013-08-30 19:33 - 00913408 _____ C:\Users\Ervd\Desktop\RogueKiller.exe
2013-08-30 19:28 - 2013-05-12 13:40 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-08-30 19:27 - 2013-08-28 12:13 - 00003200 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-30 19:27 - 2013-08-28 12:12 - 00003336 _____ C:\windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3347873718-463703722-4102279566-1001
2013-08-30 19:27 - 2012-09-08 12:39 - 00000000 ___RD C:\Users\Ervd\Dropbox
2013-08-30 19:27 - 2012-09-08 12:37 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Dropbox
2013-08-30 19:27 - 2012-01-02 20:41 - 00000000 ____D C:\ProgramData\PDFC
2013-08-30 19:26 - 2013-08-16 12:54 - 00001288 _____ C:\windows\setupact.log
2013-08-30 19:26 - 2013-04-26 22:57 - 00000328 _____ C:\windows\Tasks\HPCeeScheduleForErvd.job
2013-08-30 19:26 - 2009-07-14 07:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-08-30 19:25 - 2013-08-30 19:23 - 00000000 ____D C:\AdwCleaner
2013-08-30 19:22 - 2013-08-30 19:22 - 00994642 _____ C:\Users\Ervd\Desktop\adwcleaner.exe
2013-08-30 18:24 - 2012-08-01 17:34 - 00000000 ____D C:\Program Files\trend micro
2013-08-30 18:24 - 2012-08-01 17:32 - 00935175 _____ C:\Users\Ervd\Desktop\RSITx64.exe
2013-08-30 15:09 - 2013-04-26 22:57 - 00003180 _____ C:\windows\System32\Tasks\HPCeeScheduleForErvd
2013-08-30 15:09 - 2012-06-18 11:46 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2013-08-30 15:08 - 2012-06-29 15:24 - 00000000 _____ C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-08-30 09:17 - 2013-08-16 12:54 - 00003256 _____ C:\windows\PFRO.log
2013-08-30 09:17 - 2013-06-14 13:04 - 00000000 ____D C:\Program Files (x86)\Pando Networks
2013-08-30 00:16 - 2013-06-26 19:54 - 00001885 _____ C:\Users\Public\Desktop\Media Go.lnk
2013-08-30 00:16 - 2012-06-09 16:08 - 00000000 ____D C:\Users\Ervd
2013-08-30 00:14 - 2013-08-30 00:09 - 00000000 ____D C:\Program Files (x86)\Sony Media Go Install
2013-08-30 00:13 - 2012-06-09 16:29 - 00000000 ____D C:\Users\Ervd\AppData\Local\Downloaded Installations
2013-08-30 00:03 - 2013-08-29 23:33 - 58283225 _____ C:\Users\Ervd\Desktop\Cimrman - Švestka (divadelní záznam).3gp
2013-08-29 23:43 - 2013-06-25 10:14 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Audacity
2013-08-29 23:40 - 2013-06-18 11:38 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2013-08-29 23:27 - 2013-08-29 23:27 - 00000000 ____D C:\Program Files (x86)\GreenTree Applications
2013-08-29 23:23 - 2013-08-29 23:23 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Youtube Downloader HD
2013-08-29 23:11 - 2012-01-02 19:36 - 00669736 _____ C:\windows\system32\perfh005.dat
2013-08-29 23:11 - 2012-01-02 19:36 - 00141336 _____ C:\windows\system32\perfc005.dat
2013-08-29 23:11 - 2009-07-14 07:13 - 01585238 _____ C:\windows\system32\PerfStringBackup.INI
2013-08-29 21:42 - 2012-10-02 19:53 - 00000000 ____D C:\Users\Ervd\Documents\FJFI
2013-08-29 15:24 - 2013-08-29 15:23 - 31026832 _____ (Opera Software ASA) C:\Users\Ervd\Downloads\Opera_15.0.1147.153_Setup.exe
2013-08-27 21:11 - 2013-08-30 21:04 - 01579080 _____ (Farbar) C:\Users\Ervd\Desktop\FRST64.exe
2013-08-27 14:08 - 2012-06-09 16:55 - 00000000 ____D C:\Users\Ervd\AppData\Local\PDFC
2013-08-27 12:38 - 2013-03-29 09:38 - 00000000 ____D C:\Program Files (x86)\Voobly
2013-08-26 15:23 - 2013-08-26 15:16 - 308105840 _____ C:\Users\Ervd\Desktop\Výzkumák IV.zip
2013-08-26 02:15 - 2012-06-15 16:30 - 00000000 ____D C:\Users\Ervd\AppData\Local\CrashDumps
2013-08-21 05:44 - 2013-08-12 14:48 - 00000000 ____D C:\Program Files (x86)\QIP 2012
2013-08-21 00:26 - 2013-03-23 16:54 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\vlc
2013-08-20 02:53 - 2013-08-20 02:53 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-08-18 01:17 - 2013-08-18 01:17 - 00000125 _____ C:\Users\Ervd\Desktop\film+.m3u
2013-08-16 12:54 - 2013-08-16 12:54 - 00000000 _____ C:\windows\setuperr.log
2013-08-15 15:12 - 2012-07-11 13:01 - 00003216 _____ C:\windows\System32\Tasks\HPCeeScheduleForERVD-HP$
2013-08-15 15:12 - 2012-07-11 13:01 - 00000340 _____ C:\windows\Tasks\HPCeeScheduleForERVD-HP$.job
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\SysWOW64\sl-SI
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\SysWOW64\sk-SK
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\SysWOW64\hr-HR
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\sl-SI
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\sk-SK
2013-08-15 03:34 - 2009-07-14 05:20 - 00000000 ____D C:\windows\system32\hr-HR
2013-08-15 03:11 - 2013-08-15 03:04 - 00000000 ____D C:\windows\system32\MRT
2013-08-15 03:04 - 2012-06-09 18:29 - 78161360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-08-15 03:03 - 2009-07-14 04:34 - 00000876 _____ C:\windows\win.ini
2013-08-15 02:41 - 2013-06-01 23:39 - 00000000 ____D C:\Program Files (x86)\The KMPlayer
2013-08-13 00:41 - 2013-02-13 12:38 - 00000000 ____D C:\Program Files (x86)\Diablo III
2013-08-12 15:18 - 2013-08-12 14:48 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\QIP
2013-08-12 15:17 - 2013-08-12 14:49 - 00000000 ____D C:\ICQ
2013-08-12 14:48 - 2013-08-12 14:48 - 00001078 _____ C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\QIP 2012.lnk
2013-08-12 14:48 - 2013-08-12 14:48 - 00001054 _____ C:\Users\Ervd\Desktop\QIP 2012.lnk
2013-08-12 06:39 - 2012-10-18 20:21 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Apple Computer
2013-08-11 15:14 - 2013-08-11 15:14 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple Computer
2013-08-11 12:57 - 2013-08-11 12:57 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\RealNetworks
2013-08-11 12:57 - 2013-08-11 12:55 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\Real
2013-08-11 12:57 - 2013-08-11 12:54 - 00000000 ____D C:\ProgramData\Real
2013-08-11 12:56 - 2013-08-11 12:56 - 00272896 _____ (Progressive Networks) C:\windows\SysWOW64\pncrt.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00201872 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\rmoc3260.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00006656 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5016.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00005632 _____ (RealNetworks, Inc.) C:\windows\SysWOW64\pndx5032.dll
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\ProgramData\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\RealNetworks
2013-08-11 12:56 - 2013-08-11 12:56 - 00000000 ____D C:\Program Files (x86)\Real
2013-08-11 12:56 - 2013-02-14 15:13 - 00499712 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp71.dll
2013-08-11 12:56 - 2013-02-14 15:13 - 00348160 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr71.dll
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\ProgramData\Apple Computer
2013-08-11 12:53 - 2013-08-11 12:53 - 00000000 ____D C:\Program Files (x86)\QuickTime
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Users\Ervd\AppData\Local\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\ProgramData\Apple
2013-08-11 12:52 - 2013-08-11 12:52 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2013-08-11 12:49 - 2013-08-11 12:49 - 00000000 ____D C:\PFiles
2013-08-11 12:47 - 2012-11-17 14:46 - 00000000 ____D C:\windows\SysWOW64\Adobe
2013-08-10 09:59 - 2009-07-14 06:45 - 00445272 _____ C:\windows\system32\FNTCACHE.DAT
2013-08-09 16:15 - 2013-08-09 16:15 - 00036309 _____ C:\Users\Ervd\Documents\tvrdost b.xlsx
2013-08-08 19:39 - 2012-06-09 16:52 - 00115688 _____ C:\Users\Ervd\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-08 19:36 - 2013-08-08 19:36 - 00036243 _____ C:\Users\Ervd\Documents\tvrdost a.xlsx
2013-08-08 18:56 - 2013-08-08 18:56 - 00001100 _____ C:\Users\Public\Desktop\OpenOffice 4.0.0.lnk
2013-08-08 18:56 - 2013-08-08 18:56 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\OpenOffice
2013-08-08 18:55 - 2013-08-08 18:55 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-08-08 18:55 - 2012-06-12 15:53 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-08-08 18:52 - 2013-08-08 18:52 - 00000000 ____D C:\Users\Ervd\Desktop\OpenOffice 4.0.0 (cs) Installation Files
2013-08-08 18:51 - 2013-08-08 18:49 - 00027136 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.xls
2013-08-08 18:49 - 2013-08-08 18:49 - 00043124 _____ C:\Users\Ervd\Documents\tvrdost - pokus2.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00043125 _____ C:\Users\Ervd\Documents\tvrdost - pokus.ods
2013-08-08 18:22 - 2013-08-08 18:22 - 00025088 _____ C:\Users\Ervd\Documents\tvrdost - pokus.xls
2013-08-08 18:05 - 2013-08-08 18:05 - 00072055 _____ C:\Users\Ervd\Documents\tvrdostXXX2.ods
2013-08-06 18:05 - 2012-06-09 19:41 - 00000000 ____D C:\Program Files (x86)\Opera
2013-08-06 18:04 - 2013-08-06 18:04 - 00001829 _____ C:\Users\Public\Desktop\Opera.lnk
2013-08-01 14:39 - 2012-06-09 16:55 - 00001393 _____ C:\Users\Ervd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-07-31 21:57 - 2013-07-31 21:57 - 00000000 ____D C:\Users\Ervd\AppData\Local\GHISLER
2013-07-31 21:55 - 2013-07-31 21:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-31 21:50 - 2013-07-31 21:50 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\GHISLER
2013-07-31 21:47 - 2013-07-31 21:47 - 00000000 ____D C:\Users\Ervd\AppData\Roaming\TeamViewer
Files to move or delete:
====================
C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe
C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== Scheduled Tasks (whitelisted) ===========
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForERVD-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForErvd.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Supplementary Scan (All) ================
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync
"C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTMTrayAgent
rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPPowerAssistant
C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup
C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium
"C:\Program Files (x86)\QIP 2012\qip.exe" /autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess
"C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor
"C:\Program Files (x86)\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" -NoStart [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete
C:\Program Files (x86)\PDF Complete\pdfsty.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion
"C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files (x86)\Steam\Steam.exe" -silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader
C:\Program Files\VDownloader\VDownloader.exe /silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly
"C:\Program Files (x86)\Voobly\voobly.exe" --startup [x]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=dword:00000000
"ConsentPromptBehaviorUser"=dword:00000003
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableUIADesktopToggle"=dword:00000000
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000000
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=dword:00000099
"NoDrives"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=dword:00000001
"FirewallDisableNotify"=dword:00000000
"AntiVirusDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"AntiSpywareOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.msadpcm"="msadp32.acm"
"midimapper"="midimap.dll"
"wavemapper"="msacm32.drv"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.i420"="iyuv_32.dll"
"VIDC.YVU9"="tsbyuv.dll"
"msacm.l3acm"="l3codecp.acm"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"MSVideo8"="VfWWDM32.dll"
"VIDC.LAGS"="lagarith.dll"
"VIDC.FFDS"="ff_vfw.dll"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:444.67 GB) (Free:192.72 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (HP_RECOVERY) (Fixed) (Total:15.8 GB) (Free:2.37 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:4.99 GB) (Free:2.11 GB) FAT32
Drive h: () (Removable) (Total:29.82 GB) (Free:5.71 GB) FAT32
Available physical RAM: 1713.11 MB
Total physical RAM: 4030.36 MB
Percentage of memory in use: 57%
LastRegBack: 2013-08-22 18:13
==================== End Of Log ==============================
Re: prosím o preventivku

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM-x32\...\Run: [] - [x] HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-08-11] (RealNetworks, Inc.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchab.com/?aff=7&uid=a261b29e ... b30fe5c&q={searchTerms} BHO-x32: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly" /f Hosts: CMD: shutdown /r /f /t 2 End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: prosím o preventivku
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-08-2013
Ran by Ervd at 2013-08-30 22:01:56 Run:1
Running from C:\Users\Ervd\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-08-11] (RealNetworks, Inc.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchab.com/?aff=7&uid=a261b29e ... b30fe5c&q={searchTerms}
BHO-x32: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe
C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly" /f
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\SearchAssistant => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\CustomizeSearch => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key deleted successfully.
HKCR\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} => Key not found.
HKCR\PROTOCOLS\Handler\msdaipp => Key deleted successfully.
HKCR\Wow6432Node\PROTOCOLS\Handler\msdaipp => Key not found.
HKCR\PROTOCOLS\Filter\text/xml => Key deleted successfully.
HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945} => Key not found.
C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar =========
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Ran by Ervd at 2013-08-30 22:01:56 Run:1
Running from C:\Users\Ervd\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [TkBellExe] - C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-08-11] (RealNetworks, Inc.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDF
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/redirects/secur ... =20.3.1.22
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = http://searchab.com/?aff=7&uid=a261b29e ... b30fe5c&q={searchTerms}
BHO-x32: No Name - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - No File
Handler: msdaipp - No CLSID Value -
Handler-x32: msdaipp - No CLSID Value -
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe
C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly" /f
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Bar => Value deleted successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\SearchAssistant => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\CustomizeSearch => Value deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key deleted successfully.
HKCR\CLSID\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED} => Key not found.
HKCR\PROTOCOLS\Handler\msdaipp => Key deleted successfully.
HKCR\Wow6432Node\PROTOCOLS\Handler\msdaipp => Key not found.
HKCR\PROTOCOLS\Filter\text/xml => Key deleted successfully.
HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945} => Key not found.
C:\Users\Ervd\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\sfamcc00001.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\vlc-2.0.8-win32.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\HP Support Framework\HPSF_Config1.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\d3dcompiler_46.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\ffmpegsumo.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\icudt.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\launcher_lib.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libEGL.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\libGLESv2.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcp100.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\msvcr100.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\npTestNetscapePlugIn.dll => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\Opera_16.0.1196.62_Autoupdate.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_autoupdate.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\opera_crashreporter.exe => Moved successfully.
C:\Users\Ervd\AppData\Local\Temp\CProgram Files (x86)Opera\ready\wow_helper.exe => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHS Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 CHT Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 JPN Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IME14 KOR Setup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaPCInternetAccess" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar =========
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony PC Companion" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VDownloader" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Voobly" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Re: prosím o preventivku
Tak jeste uklidime
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 


- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy


Re: prosím o preventivku
Děkuji za pomoc!