
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
www.delta-homes.com
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
www.delta-homes.com
Dobrý den,
dceři se podařilo zavirovat PC. V jakémkoli prohlížeči se jako domovská stránka objevuje http://www.delta-homes.com.
Děkuje za pomoc.
dceři se podařilo zavirovat PC. V jakémkoli prohlížeči se jako domovská stránka objevuje http://www.delta-homes.com.
Děkuje za pomoc.
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: www.delta-homes.com
Zdravím,
Stáhni Shortcut Cleaner http://www.bleepingcomputer.com/downloa ... t-cleaner/
Ulož nejlépe na plochu
Ukonči všechny programy a dvojklikem SC spusť
Proběhne skenování a pak se objevi log, případně bude uložen v místě spuštení jako sc-cleaner.txt, jeho obsah sem vlož
Stáhni Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Ulož jej na plochu a spusť - zobrazí se licenční podminky -> start libovolnou klávesou.
Bude vytvořena záloha a proběhne skenování.
Vyskočí log (nebo je uložen zde c:\JRT jako JRT.txt) - zkopíruj jej sem
Stáhni AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Ulož nejlépe na plochu -> ukonči všechny programy -> spusť AdwCleaner -> klikni na Search po dokončení na Clean
bude provedena oprava, restartuje se - (případně restartuj) a vypadne log C:\AdwCleaner\AdwCleaner[S?].txt , jeho obsah vložíš sem
dej log RSIT - http://forum.viry.cz/viewtopic.php?f=24&t=130784

Ulož nejlépe na plochu
Ukonči všechny programy a dvojklikem SC spusť
Proběhne skenování a pak se objevi log, případně bude uložen v místě spuštení jako sc-cleaner.txt, jeho obsah sem vlož

Ulož jej na plochu a spusť - zobrazí se licenční podminky -> start libovolnou klávesou.
Bude vytvořena záloha a proběhne skenování.
Vyskočí log (nebo je uložen zde c:\JRT jako JRT.txt) - zkopíruj jej sem

Ulož nejlépe na plochu -> ukonči všechny programy -> spusť AdwCleaner -> klikni na Search po dokončení na Clean
bude provedena oprava, restartuje se - (případně restartuj) a vypadne log C:\AdwCleaner\AdwCleaner[S?].txt , jeho obsah vložíš sem

Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: www.delta-homes.com
Shortcut Cleaner 1.2.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/
Windows Version: Windows 7 Ultimate Service Pack 1
Program started at: 09/03/2013 05:24:27 PM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\
* Shortcut Cleaned: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1374137570
* Shortcut Cleaned: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1374137570
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
* Shortcut Cleaned: C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1374137570
Searching C:\Users\Public\Desktop\
Searching C:\Users\Lenovo\Desktop
3 bad shortcuts found.
Program finished at: 09/03/2013 05:24:30 PM
Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.7 (09.01.2013:1)
OS: Windows 7 Ultimate x64
Ran by Lenovo on Łt 03.09.2013 at 17:25:35,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\optimizer pro
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sdp
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\webcake desktop
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.api
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.api.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.layers
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.layers.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\defaulttabbho.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\webcakeieclient.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BB975E58-E769-4E5A-BA12-B765BC559FF3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\default tab
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\defaulttab
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\optimizer pro
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\somoto
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\defaulttab
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\sprotector
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\default tab
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\defaulttab
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\esafeseccontrol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\qvo6software
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowser
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowser.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowseractivex
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowseractivex.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\defaulttab
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\filesfrog update checker
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\optimizer pro_is1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{c670dcae-e392-aa32-6f42-143c7fc4bdfd}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sp global
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sprotector
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT1098640
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2A9C7DA5-4822-4B09-A85B-52CB2A051554}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AF283396-B788-4C5F-93CB-CB1287E96F61}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
~~~ Files
Successfully deleted: [File] C:\Windows\Tasks\amiupdxp.job
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\bettersoft"
Successfully deleted: [Folder] "C:\ProgramData\esafe"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\defaulttab"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\movdap"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\optimizer pro"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\big fish"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\filesfrog update checker"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\minibar"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\locallow\minibar"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\daemon tools toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\defaulttab"
Successfully deleted: [Folder] "C:\Program Files (x86)\minibar"
Successfully deleted: [Folder] "C:\Program Files (x86)\movdap"
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\saveshare"
Successfully deleted: [Folder] "C:\Program Files (x86)\websearch"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\microsoft\windows\start menu\programs\filesfrog update checker"
Successfully deleted: [Folder] "C:\bigfishcache"
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\extensioninstallforcelist [Blacklisted Policy]
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 03.09.2013 at 17:40:34,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.002 - Report created 03/09/2013 at 17:45:24
# Updated 01/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Lenovo - LENOVO-PC
# Running from : C:\Users\Lenovo\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : DefaultTabSearch
[#] Service Deleted : DefaultTabUpdate
[#] Service Deleted : WebCake Desktop Updater
Service Deleted : winzipersvc
[#] Service Deleted : WsysSvc
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\saVeenshare
Folder Deleted : C:\ProgramData\SearchNewTab
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Users\Lenovo\AppData\Local\PackageAware
Folder Deleted : C:\Users\Lenovo\AppData\Local\Temp\eIntaller
Folder Deleted : C:\Users\Lenovo\AppData\LocalLow\saVeenshare
Folder Deleted : C:\Users\Lenovo\AppData\LocalLow\SearchNewTab
Folder Deleted : C:\Users\Lenovo\AppData\Roaming\eIntaller
Folder Deleted : C:\Users\Lenovo\AppData\Roaming\WinZipper
File Deleted : C:\Users\Lenovo\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Lenovo\Desktop\Optimizer Pro.lnk
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
***** [ Registry ] *****
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_703c874a
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Handy Updater]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{539F76FD-084E-4858-86D5-62F02F54AE86}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKLM\Software\delta-homesSoftware
Key Deleted : HKLM\Software\Minibar
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OptimizerPro
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Google Chrome v29.0.1547.62
[ File : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [7059 octets] - [03/09/2013 17:43:05]
AdwCleaner[S0].txt - [5991 octets] - [03/09/2013 17:45:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6051 octets] ##########
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
http://www.bleepingcomputer.com/downloa ... t-cleaner/
Windows Version: Windows 7 Ultimate Service Pack 1
Program started at: 09/03/2013 05:24:27 PM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\
* Shortcut Cleaned: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk => C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1374137570
* Shortcut Cleaned: C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk => C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1374137570
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
* Shortcut Cleaned: C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk => C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&utm_m ... 1374137570
Searching C:\Users\Public\Desktop\
Searching C:\Users\Lenovo\Desktop
3 bad shortcuts found.
Program finished at: 09/03/2013 05:24:30 PM
Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.7 (09.01.2013:1)
OS: Windows 7 Ultimate x64
Ran by Lenovo on Łt 03.09.2013 at 17:25:35,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\optimizer pro
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sdp
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\webcake desktop
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.api
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.api.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.layers
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\webcakeieclient.layers.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\defaulttabbho.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\webcakeieclient.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BB975E58-E769-4E5A-BA12-B765BC559FF3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F511AFDB-726E-4458-90E7-1ECB97406544}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{EFDF368C-8DD9-4E05-87CD-16AA5CB03CB8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\bi
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\default tab
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\defaulttab
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\optimizer pro
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\somoto
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\defaulttab
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\sprotector
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\default tab
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\defaulttab
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\esafeseccontrol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\qvo6software
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowser
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowser.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowseractivex
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\defaulttabbho.defaulttabbrowseractivex.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\webcakedesktop_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\defaulttab
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\filesfrog update checker
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\optimizer pro_is1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{c670dcae-e392-aa32-6f42-143c7fc4bdfd}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sp global
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\sprotector
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT1098640
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2A9C7DA5-4822-4B09-A85B-52CB2A051554}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AF283396-B788-4C5F-93CB-CB1287E96F61}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
~~~ Files
Successfully deleted: [File] C:\Windows\Tasks\amiupdxp.job
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\bettersoft"
Successfully deleted: [Folder] "C:\ProgramData\esafe"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\defaulttab"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\movdap"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\optimizer pro"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\big fish"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\filesfrog update checker"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\minibar"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Lenovo\appdata\locallow\minibar"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\daemon tools toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\defaulttab"
Successfully deleted: [Folder] "C:\Program Files (x86)\minibar"
Successfully deleted: [Folder] "C:\Program Files (x86)\movdap"
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\saveshare"
Successfully deleted: [Folder] "C:\Program Files (x86)\websearch"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro"
Successfully deleted: [Folder] "C:\Users\Lenovo\AppData\Roaming\microsoft\windows\start menu\programs\filesfrog update checker"
Successfully deleted: [Folder] "C:\bigfishcache"
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Policies\Google\Chrome\extensioninstallforcelist [Blacklisted Policy]
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\fjoijdanhaiflhibkljeklcghcmmfffh
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 03.09.2013 at 17:40:34,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
# AdwCleaner v3.002 - Report created 03/09/2013 at 17:45:24
# Updated 01/09/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Lenovo - LENOVO-PC
# Running from : C:\Users\Lenovo\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : DefaultTabSearch
[#] Service Deleted : DefaultTabUpdate
[#] Service Deleted : WebCake Desktop Updater
Service Deleted : winzipersvc
[#] Service Deleted : WsysSvc
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\saVeenshare
Folder Deleted : C:\ProgramData\SearchNewTab
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SearchNewTab
Folder Deleted : C:\Program Files (x86)\WinZipper
Folder Deleted : C:\Users\Lenovo\AppData\Local\PackageAware
Folder Deleted : C:\Users\Lenovo\AppData\Local\Temp\eIntaller
Folder Deleted : C:\Users\Lenovo\AppData\LocalLow\saVeenshare
Folder Deleted : C:\Users\Lenovo\AppData\LocalLow\SearchNewTab
Folder Deleted : C:\Users\Lenovo\AppData\Roaming\eIntaller
Folder Deleted : C:\Users\Lenovo\AppData\Roaming\WinZipper
File Deleted : C:\Users\Lenovo\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Lenovo\Desktop\Optimizer Pro.lnk
***** [ Shortcuts ] *****
Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
***** [ Registry ] *****
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_4e24eecb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SP_703c874a
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Handy Updater]
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F753BC67-E7AA-F524-0E1F-B0FFFE37A9D7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AF6B0594-6008-4327-93E5-608AD710A6FA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B35A4A8F-28BF-36C8-0F9D-07DC3E6D6796}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AAA38851-3CFF-475F-B5E0-720D3645E4A5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{539F76FD-084E-4858-86D5-62F02F54AE86}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKLM\Software\delta-homesSoftware
Key Deleted : HKLM\Software\Minibar
Key Deleted : HKLM\Software\V9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OptimizerPro
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
-\\ Google Chrome v29.0.1547.62
[ File : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [7059 octets] - [03/09/2013 17:43:05]
AdwCleaner[S0].txt - [5991 octets] - [03/09/2013 17:45:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6051 octets] ##########
Re: www.delta-homes.com
Logfile of random's system information tool 1.09 (written by random/random)
Run by Lenovo at 2013-09-03 17:52:34
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 225 GB (74%) free of 304 GB
Total RAM: 1643 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:52:44, on 3.9.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe
C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files\trend micro\Lenovo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NtVdmSrv] C:\Windows\inf\ntvdm.vbe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [MxDock] C:\Program Files (x86)\Maxthon\Modules\MxDock\MxDock.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Lenovo\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak Software\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [LiveSupport] "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
O4 - HKCU\..\Run: [se] "C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
O4 - HKCU\..\Run: [AppsHat] C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIKE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-302 303 305 306 Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8584 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2c0
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {9574A2FF-A1A5-4894-A5DD-4EABEE844305}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
"C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"
"C:\Windows\System32\spool\drivers\x64\3\E_IATIIKE.EXE" /EPT "EPLTarget\P0000000000000000" /M "XP-302 303 305 306 Series"
szndesktop.exe default start
"C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "988972280-18247345801283311701-19621329581462162354-979525020845889087-1233759756
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\EscSvc64.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\splwow64.exe 8192
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\Lenovo\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\schedule!3036567561.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26 431104]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26 431104]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-07-05 9744800]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-07-05 5399456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-01-31 3013360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MxDock"=C:\Program Files (x86)\Maxthon\Modules\MxDock\MxDock.exe []
"cz.seznam.software.autoupdate"=C:\Users\Lenovo\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"EA Core"=C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent []
"SpeedUpMyComputer"=C:\Program Files (x86)\SmartTweak Software\SpeedUpMyComputer\SpeedUpMyComputer.exe [2013-01-10 2054776]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"LiveSupport"=C:\Program Files (x86)\LiveSupport\LiveSupport.exe [2013-08-12 770048]
"se"=C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe [2013-08-31 5824416]
"AppsHat"=C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752]
"EPLTarget\P0000000000000000"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIKE.EXE [2012-02-29 283232]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"NtVdmSrv"=C:\Windows\inf\ntvdm.vbe [2013-06-14 884]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2011-10-31 1058400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-09-03 17:52:35 ----D---- C:\Program Files\trend micro
2013-09-03 17:52:34 ----D---- C:\rsit
2013-09-03 17:41:41 ----D---- C:\AdwCleaner
2013-09-03 17:25:30 ----D---- C:\Windows\ERUNT
2013-09-03 17:24:27 ----A---- C:\sc-cleaner.txt
2013-08-31 21:58:37 ----D---- C:\Users\Lenovo\AppData\Roaming\Epson
2013-08-31 19:20:58 ----D---- C:\ProgramData\SummerSoft
2013-08-31 19:20:24 ----D---- C:\Users\Lenovo\AppData\Roaming\SkypEmoticons
2013-08-31 19:20:15 ----D---- C:\Windows\SYSWOW64\X86
2013-08-31 19:20:15 ----D---- C:\Windows\SYSWOW64\AMD64
2013-08-31 19:20:15 ----D---- C:\Program Files (x86)\EZDownloader
2013-08-31 19:20:07 ----A---- C:\Users\Lenovo\AppData\Roaming\LiveSupport.exe_log.txt
2013-08-31 19:20:06 ----A---- C:\Users\Lenovo\AppData\Roaming\regsvr32.exe_log.txt
2013-08-31 19:20:03 ----D---- C:\Program Files (x86)\LiveSupport
2013-08-31 19:16:24 ----D---- C:\ProgramData\InstallMate
2013-08-22 20:09:22 ----D---- C:\ProgramData\ABBYY
2013-08-22 20:09:22 ----D---- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2013-08-22 19:57:54 ----D---- C:\Program Files (x86)\EPSON Software
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enspres.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\ensppui.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\ensppmon.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enpres.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enppui.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enppmon.dll
2013-08-22 19:57:21 ----D---- C:\Program Files\EpsonNet
2013-08-22 19:50:19 ----A---- C:\Windows\system32\E_GCINST.DLL
2013-08-22 19:50:16 ----A---- C:\Windows\system32\E_ILMIKE.DLL
2013-08-22 19:50:15 ----A---- C:\Windows\system32\E_ID4BIKE.DLL
2013-08-22 19:49:23 ----A---- C:\Windows\system32\esxw2ud.dll
2013-08-22 19:49:23 ----A---- C:\Windows\system32\escsvc64.exe
2013-08-22 19:49:13 ----D---- C:\Program Files (x86)\epson
2013-08-22 19:43:31 ----D---- C:\Program Files\Common Files\EPSON
2013-08-22 19:43:11 ----D---- C:\ProgramData\EPSON
2013-08-22 19:42:39 ----A---- C:\Windows\system32\E_IBCBIKE.DLL
2013-08-16 13:45:49 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2013-08-16 13:45:33 ----RD---- C:\Program Files (x86)\Skype
2013-08-16 13:45:24 ----D---- C:\ProgramData\Skype
2013-08-16 13:19:07 ----D---- C:\ProgramData\Synaptics
2013-08-16 13:17:22 ----D---- C:\Users\Lenovo\AppData\Roaming\Synaptics
2013-08-16 13:00:36 ----D---- C:\Program Files\Synaptics
2013-08-16 12:50:01 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2013-08-16 12:50:00 ----A---- C:\Windows\SYSWOW64\SynTPCOM.dll
2013-08-16 12:50:00 ----A---- C:\Windows\SYSWOW64\SynCOM.dll
2013-08-16 12:50:00 ----A---- C:\Windows\system32\SynTPCo16.dll
2013-08-16 12:50:00 ----A---- C:\Windows\system32\SynCOM.dll
2013-08-16 12:49:59 ----A---- C:\Windows\system32\SynTPAPI.dll
2013-08-16 12:49:59 ----A---- C:\Windows\system32\drivers\SynTP.sys
2013-08-16 09:20:08 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-08-16 09:20:08 ----A---- C:\Windows\system32\ieui.dll
2013-08-16 09:20:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-16 09:20:05 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\iesetup.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\iernonce.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-16 09:20:03 ----A---- C:\Windows\system32\iertutil.dll
2013-08-16 09:20:02 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-08-16 09:20:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-08-16 09:20:01 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-16 09:20:01 ----A---- C:\Windows\system32\jscript.dll
2013-08-16 09:20:00 ----A---- C:\Windows\system32\jscript9.dll
2013-08-16 09:19:58 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-08-16 09:19:57 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-08-16 09:19:56 ----A---- C:\Windows\system32\urlmon.dll
2013-08-16 09:19:54 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-08-16 09:19:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-08-16 09:19:54 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-16 09:19:53 ----A---- C:\Windows\system32\wininet.dll
2013-08-16 09:19:51 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-08-16 09:19:48 ----A---- C:\Windows\system32\ieframe.dll
2013-08-16 09:19:46 ----A---- C:\Windows\system32\mshtml.dll
2013-08-16 09:19:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-08-15 13:43:49 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-08-15 13:43:49 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-08-15 13:43:49 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-08-15 13:43:49 ----A---- C:\Windows\system32\wintrust.dll
2013-08-15 13:43:49 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-15 13:43:49 ----A---- C:\Windows\system32\crypt32.dll
2013-08-15 13:43:48 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-08-15 13:43:48 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-15 13:43:25 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-08-15 13:43:25 ----A---- C:\Windows\system32\tzres.dll
2013-08-15 13:43:15 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-15 13:43:14 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2013-08-15 13:43:13 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2013-08-15 13:43:13 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-15 13:43:10 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-08-15 13:43:08 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-08-15 13:43:08 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-15 13:43:07 ----A---- C:\Windows\system32\ntdll.dll
2013-08-15 13:43:06 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-08-15 13:43:06 ----A---- C:\Windows\system32\wow64.dll
2013-08-15 13:43:05 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\user.exe
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-08-15 13:43:01 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-15 13:42:59 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-08-13 22:51:24 ----D---- C:\Windows\system32\MRT
2013-08-12 12:45:30 ----D---- C:\Users\Lenovo\AppData\Roaming\Microsoft Games
2013-08-12 12:45:30 ----D---- C:\ProgramData\Microsoft Games
2013-08-11 19:49:48 ----D---- C:\Users\Lenovo\AppData\Roaming\turtle_odyssey_ _realore_en
2013-08-11 19:27:00 ----AD---- C:\ProgramData\TEMP
2013-08-11 19:25:24 ----D---- C:\Program Files (x86)\Realore
2013-08-09 22:04:01 ----D---- C:\Program Files (x86)\Alcohol Soft
2013-08-09 22:00:39 ----A---- C:\Windows\system32\drivers\sptd.sys
2013-08-09 20:57:51 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2013-08-09 20:57:21 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-08-09 20:56:46 ----D---- C:\Users\Lenovo\AppData\Roaming\DAEMON Tools Lite
2013-08-09 20:56:46 ----D---- C:\ProgramData\DAEMON Tools Lite
2013-08-09 20:28:14 ----D---- C:\Program Files (x86)\Elaborate Bytes
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\winver.exe
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\user32.dll
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\slmgr.vbs
2013-08-09 10:16:47 ----D---- C:\Users\Lenovo\AppData\Roaming\vlc
2013-08-09 10:15:19 ----D---- C:\Program Files (x86)\VideoLAN
======List of files/folders modified in the last 1 month======
2013-09-03 17:52:37 ----D---- C:\Windows\Temp
2013-09-03 17:52:35 ----RD---- C:\Program Files
2013-09-03 17:52:09 ----D---- C:\Users\Lenovo\AppData\Roaming\Seznam.cz
2013-09-03 17:50:21 ----D---- C:\Windows\system32\config
2013-09-03 17:49:50 ----D---- C:\Windows\system32\FxsTmp
2013-09-03 17:45:30 ----RD---- C:\Program Files (x86)
2013-09-03 17:45:28 ----HD---- C:\ProgramData
2013-09-03 17:26:20 ----D---- C:\Windows\Tasks
2013-09-03 17:26:20 ----D---- C:\Windows\system32\Tasks
2013-09-03 17:25:30 ----D---- C:\Windows
2013-09-03 14:18:11 ----D---- C:\Program Files (x86)\Common Files
2013-09-03 14:18:09 ----D---- C:\Windows\system32\drivers
2013-09-01 11:41:00 ----SHD---- C:\Windows\Installer
2013-09-01 11:39:28 ----D---- C:\Windows\SysWOW64
2013-09-01 11:08:32 ----D---- C:\ProgramData\Adobe
2013-09-01 11:01:21 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2013-09-01 11:00:32 ----D---- C:\Users\Lenovo\AppData\Roaming\Adobe
2013-08-31 22:23:56 ----D---- C:\Windows\System32
2013-08-31 22:09:03 ----D---- C:\Windows\system32\catroot
2013-08-31 22:09:02 ----D---- C:\Windows\system32\DriverStore
2013-08-31 22:09:01 ----D---- C:\Windows\inf
2013-08-31 22:06:03 ----SHD---- C:\System Volume Information
2013-08-31 21:45:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-08-31 21:03:52 ----RSD---- C:\Windows\Fonts
2013-08-23 19:37:35 ----A---- C:\Windows\SYSWOW64\msvcr100.dll
2013-08-23 19:37:35 ----A---- C:\Windows\SYSWOW64\msvcp100.dll
2013-08-23 19:36:27 ----D---- C:\Windows\Prefetch
2013-08-23 18:52:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-22 20:13:19 ----D---- C:\Windows\winsxs
2013-08-22 20:04:20 ----D---- C:\Windows\system32\catroot2
2013-08-22 19:49:13 ----D---- C:\Windows\twain_32
2013-08-22 19:43:31 ----D---- C:\Program Files\Common Files
2013-08-18 12:45:37 ----D---- C:\Windows\rescache
2013-08-16 17:41:21 ----D---- C:\Windows\Microsoft.NET
2013-08-16 17:41:16 ----RSD---- C:\Windows\assembly
2013-08-16 09:40:19 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-08-16 09:40:19 ----D---- C:\Windows\system32\cs-CZ
2013-08-16 09:40:18 ----D---- C:\Program Files\Internet Explorer
2013-08-16 09:40:18 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-16 09:40:16 ----D---- C:\Windows\AppPatch
2013-08-16 09:07:11 ----A---- C:\Windows\system32\MRT.exe
2013-08-12 12:09:30 ----D---- C:\Windows\system32\oobe
2013-08-12 11:30:22 ----D---- C:\Users\Lenovo\AppData\Roaming\uTorrent
2013-08-12 11:16:28 ----D---- C:\ProgramData\Electronic Arts
2013-08-11 20:47:45 ----D---- C:\Program Files (x86)\Google
2013-08-11 15:53:09 ----D---- C:\Program Files (x86)\Electronic Arts
2013-08-10 12:48:25 ----D---- C:\Windows\system32\wdi
2013-08-09 22:04:28 ----RD---- C:\Users
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 LHDmgr;LHDmgr; C:\Windows\System32\DRIVERS\LhdX64.sys [2013-07-05 39008]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-08-09 503352]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-08-09 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2013-07-05 29792]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-12-14 9360896]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-12-14 309760]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-14 3678720]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-06-25 76912]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-01-31 467184]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 507392]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S3 WSDScan;Podpora skenování WSD přes UMB; C:\Windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-12-14 204288]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-11-01 179296]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2012-02-21 151648]
R2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2011-12-12 135824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-07-25 162672]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-07-03 1255736]
-----------------EOF-----------------
Run by Lenovo at 2013-09-03 17:52:34
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 225 GB (74%) free of 304 GB
Total RAM: 1643 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:52:44, on 3.9.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe
C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files\trend micro\Lenovo.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.cz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.cz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NtVdmSrv] C:\Windows\inf\ntvdm.vbe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKCU\..\Run: [MxDock] C:\Program Files (x86)\Maxthon\Modules\MxDock\MxDock.exe
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Lenovo\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak Software\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [LiveSupport] "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
O4 - HKCU\..\Run: [se] "C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
O4 - HKCU\..\Run: [AppsHat] C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIKE.EXE /EPT "EPLTarget\P0000000000000000" /M "XP-302 303 305 306 Series"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Epson Scanner Service (EpsonScanSvc) - Unknown owner - C:\Windows\system32\EscSvc64.exe (file missing)
O23 - Service: EPSON V5 Service4(04) (EPSON_EB_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
O23 - Service: EPSON V3 Service4(04) (EPSON_PM_RPCV4_04) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8584 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE 0x2c0
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {9574A2FF-A1A5-4894-A5DD-4EABEE844305}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
"C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe"
"C:\Windows\System32\spool\drivers\x64\3\E_IATIIKE.EXE" /EPT "EPLTarget\P0000000000000000" /M "XP-302 303 305 306 Series"
szndesktop.exe default start
"C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "988972280-18247345801283311701-19621329581462162354-979525020845889087-1233759756
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE"
"C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe"
"C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\EscSvc64.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\splwow64.exe 8192
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\Lenovo\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\schedule!3036567561.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26 431104]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26 431104]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2013-07-05 9744800]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2013-07-05 5399456]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-01-31 3013360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MxDock"=C:\Program Files (x86)\Maxthon\Modules\MxDock\MxDock.exe []
"cz.seznam.software.autoupdate"=C:\Users\Lenovo\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Lenovo\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"EA Core"=C:\Program Files (x86)\Electronic Arts\EADM\Core.exe -silent []
"SpeedUpMyComputer"=C:\Program Files (x86)\SmartTweak Software\SpeedUpMyComputer\SpeedUpMyComputer.exe [2013-01-10 2054776]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"LiveSupport"=C:\Program Files (x86)\LiveSupport\LiveSupport.exe [2013-08-12 770048]
"se"=C:\Users\Lenovo\AppData\Roaming\SkypEmoticons\SE.exe [2013-08-31 5824416]
"AppsHat"=C:\Users\Lenovo\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe [2012-10-26 202752]
"EPLTarget\P0000000000000000"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIKE.EXE [2012-02-29 283232]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"NtVdmSrv"=C:\Windows\inf\ntvdm.vbe [2013-06-14 884]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2011-10-31 1058400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2013-09-03 17:52:35 ----D---- C:\Program Files\trend micro
2013-09-03 17:52:34 ----D---- C:\rsit
2013-09-03 17:41:41 ----D---- C:\AdwCleaner
2013-09-03 17:25:30 ----D---- C:\Windows\ERUNT
2013-09-03 17:24:27 ----A---- C:\sc-cleaner.txt
2013-08-31 21:58:37 ----D---- C:\Users\Lenovo\AppData\Roaming\Epson
2013-08-31 19:20:58 ----D---- C:\ProgramData\SummerSoft
2013-08-31 19:20:24 ----D---- C:\Users\Lenovo\AppData\Roaming\SkypEmoticons
2013-08-31 19:20:15 ----D---- C:\Windows\SYSWOW64\X86
2013-08-31 19:20:15 ----D---- C:\Windows\SYSWOW64\AMD64
2013-08-31 19:20:15 ----D---- C:\Program Files (x86)\EZDownloader
2013-08-31 19:20:07 ----A---- C:\Users\Lenovo\AppData\Roaming\LiveSupport.exe_log.txt
2013-08-31 19:20:06 ----A---- C:\Users\Lenovo\AppData\Roaming\regsvr32.exe_log.txt
2013-08-31 19:20:03 ----D---- C:\Program Files (x86)\LiveSupport
2013-08-31 19:16:24 ----D---- C:\ProgramData\InstallMate
2013-08-22 20:09:22 ----D---- C:\ProgramData\ABBYY
2013-08-22 20:09:22 ----D---- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2013-08-22 19:57:54 ----D---- C:\Program Files (x86)\EPSON Software
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enspres.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\ensppui.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\ensppmon.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enpres.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enppui.dll
2013-08-22 19:57:22 ----A---- C:\Windows\system32\enppmon.dll
2013-08-22 19:57:21 ----D---- C:\Program Files\EpsonNet
2013-08-22 19:50:19 ----A---- C:\Windows\system32\E_GCINST.DLL
2013-08-22 19:50:16 ----A---- C:\Windows\system32\E_ILMIKE.DLL
2013-08-22 19:50:15 ----A---- C:\Windows\system32\E_ID4BIKE.DLL
2013-08-22 19:49:23 ----A---- C:\Windows\system32\esxw2ud.dll
2013-08-22 19:49:23 ----A---- C:\Windows\system32\escsvc64.exe
2013-08-22 19:49:13 ----D---- C:\Program Files (x86)\epson
2013-08-22 19:43:31 ----D---- C:\Program Files\Common Files\EPSON
2013-08-22 19:43:11 ----D---- C:\ProgramData\EPSON
2013-08-22 19:42:39 ----A---- C:\Windows\system32\E_IBCBIKE.DLL
2013-08-16 13:45:49 ----D---- C:\Users\Lenovo\AppData\Roaming\Skype
2013-08-16 13:45:33 ----RD---- C:\Program Files (x86)\Skype
2013-08-16 13:45:24 ----D---- C:\ProgramData\Skype
2013-08-16 13:19:07 ----D---- C:\ProgramData\Synaptics
2013-08-16 13:17:22 ----D---- C:\Users\Lenovo\AppData\Roaming\Synaptics
2013-08-16 13:00:36 ----D---- C:\Program Files\Synaptics
2013-08-16 12:50:01 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2013-08-16 12:50:00 ----A---- C:\Windows\SYSWOW64\SynTPCOM.dll
2013-08-16 12:50:00 ----A---- C:\Windows\SYSWOW64\SynCOM.dll
2013-08-16 12:50:00 ----A---- C:\Windows\system32\SynTPCo16.dll
2013-08-16 12:50:00 ----A---- C:\Windows\system32\SynCOM.dll
2013-08-16 12:49:59 ----A---- C:\Windows\system32\SynTPAPI.dll
2013-08-16 12:49:59 ----A---- C:\Windows\system32\drivers\SynTP.sys
2013-08-16 09:20:08 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-08-16 09:20:08 ----A---- C:\Windows\system32\ieui.dll
2013-08-16 09:20:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-08-16 09:20:05 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-08-16 09:20:05 ----A---- C:\Windows\system32\iesysprep.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\iesetup.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\iernonce.dll
2013-08-16 09:20:05 ----A---- C:\Windows\system32\ie4uinit.exe
2013-08-16 09:20:03 ----A---- C:\Windows\system32\iertutil.dll
2013-08-16 09:20:02 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-08-16 09:20:01 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-08-16 09:20:01 ----A---- C:\Windows\system32\msfeeds.dll
2013-08-16 09:20:01 ----A---- C:\Windows\system32\jscript.dll
2013-08-16 09:20:00 ----A---- C:\Windows\system32\jscript9.dll
2013-08-16 09:19:58 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-08-16 09:19:57 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-08-16 09:19:56 ----A---- C:\Windows\system32\urlmon.dll
2013-08-16 09:19:54 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-08-16 09:19:54 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-08-16 09:19:54 ----A---- C:\Windows\system32\jsproxy.dll
2013-08-16 09:19:53 ----A---- C:\Windows\system32\wininet.dll
2013-08-16 09:19:51 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-08-16 09:19:48 ----A---- C:\Windows\system32\ieframe.dll
2013-08-16 09:19:46 ----A---- C:\Windows\system32\mshtml.dll
2013-08-16 09:19:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-08-15 13:43:49 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2013-08-15 13:43:49 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2013-08-15 13:43:49 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2013-08-15 13:43:49 ----A---- C:\Windows\system32\wintrust.dll
2013-08-15 13:43:49 ----A---- C:\Windows\system32\cryptsvc.dll
2013-08-15 13:43:49 ----A---- C:\Windows\system32\crypt32.dll
2013-08-15 13:43:48 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2013-08-15 13:43:48 ----A---- C:\Windows\system32\cryptnet.dll
2013-08-15 13:43:25 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-08-15 13:43:25 ----A---- C:\Windows\system32\tzres.dll
2013-08-15 13:43:15 ----A---- C:\Windows\system32\WMVDECOD.DLL
2013-08-15 13:43:14 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2013-08-15 13:43:13 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2013-08-15 13:43:13 ----A---- C:\Windows\system32\rpcrt4.dll
2013-08-15 13:43:10 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-08-15 13:43:08 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-08-15 13:43:08 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-08-15 13:43:07 ----A---- C:\Windows\system32\ntdll.dll
2013-08-15 13:43:06 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-08-15 13:43:06 ----A---- C:\Windows\system32\wow64.dll
2013-08-15 13:43:05 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\user.exe
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-08-15 13:43:04 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-08-15 13:43:01 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2013-08-15 13:42:59 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-08-13 22:51:24 ----D---- C:\Windows\system32\MRT
2013-08-12 12:45:30 ----D---- C:\Users\Lenovo\AppData\Roaming\Microsoft Games
2013-08-12 12:45:30 ----D---- C:\ProgramData\Microsoft Games
2013-08-11 19:49:48 ----D---- C:\Users\Lenovo\AppData\Roaming\turtle_odyssey_ _realore_en
2013-08-11 19:27:00 ----AD---- C:\ProgramData\TEMP
2013-08-11 19:25:24 ----D---- C:\Program Files (x86)\Realore
2013-08-09 22:04:01 ----D---- C:\Program Files (x86)\Alcohol Soft
2013-08-09 22:00:39 ----A---- C:\Windows\system32\drivers\sptd.sys
2013-08-09 20:57:51 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2013-08-09 20:57:21 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2013-08-09 20:56:46 ----D---- C:\Users\Lenovo\AppData\Roaming\DAEMON Tools Lite
2013-08-09 20:56:46 ----D---- C:\ProgramData\DAEMON Tools Lite
2013-08-09 20:28:14 ----D---- C:\Program Files (x86)\Elaborate Bytes
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\winver.exe
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\user32.dll
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\systemcpl.dll
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\sppcomapi.dll
2013-08-09 12:14:14 ----A---- C:\Windows\SYSWOW64\slmgr.vbs
2013-08-09 10:16:47 ----D---- C:\Users\Lenovo\AppData\Roaming\vlc
2013-08-09 10:15:19 ----D---- C:\Program Files (x86)\VideoLAN
======List of files/folders modified in the last 1 month======
2013-09-03 17:52:37 ----D---- C:\Windows\Temp
2013-09-03 17:52:35 ----RD---- C:\Program Files
2013-09-03 17:52:09 ----D---- C:\Users\Lenovo\AppData\Roaming\Seznam.cz
2013-09-03 17:50:21 ----D---- C:\Windows\system32\config
2013-09-03 17:49:50 ----D---- C:\Windows\system32\FxsTmp
2013-09-03 17:45:30 ----RD---- C:\Program Files (x86)
2013-09-03 17:45:28 ----HD---- C:\ProgramData
2013-09-03 17:26:20 ----D---- C:\Windows\Tasks
2013-09-03 17:26:20 ----D---- C:\Windows\system32\Tasks
2013-09-03 17:25:30 ----D---- C:\Windows
2013-09-03 14:18:11 ----D---- C:\Program Files (x86)\Common Files
2013-09-03 14:18:09 ----D---- C:\Windows\system32\drivers
2013-09-01 11:41:00 ----SHD---- C:\Windows\Installer
2013-09-01 11:39:28 ----D---- C:\Windows\SysWOW64
2013-09-01 11:08:32 ----D---- C:\ProgramData\Adobe
2013-09-01 11:01:21 ----SD---- C:\Users\Lenovo\AppData\Roaming\Microsoft
2013-09-01 11:00:32 ----D---- C:\Users\Lenovo\AppData\Roaming\Adobe
2013-08-31 22:23:56 ----D---- C:\Windows\System32
2013-08-31 22:09:03 ----D---- C:\Windows\system32\catroot
2013-08-31 22:09:02 ----D---- C:\Windows\system32\DriverStore
2013-08-31 22:09:01 ----D---- C:\Windows\inf
2013-08-31 22:06:03 ----SHD---- C:\System Volume Information
2013-08-31 21:45:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-08-31 21:03:52 ----RSD---- C:\Windows\Fonts
2013-08-23 19:37:35 ----A---- C:\Windows\SYSWOW64\msvcr100.dll
2013-08-23 19:37:35 ----A---- C:\Windows\SYSWOW64\msvcp100.dll
2013-08-23 19:36:27 ----D---- C:\Windows\Prefetch
2013-08-23 18:52:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-08-22 20:13:19 ----D---- C:\Windows\winsxs
2013-08-22 20:04:20 ----D---- C:\Windows\system32\catroot2
2013-08-22 19:49:13 ----D---- C:\Windows\twain_32
2013-08-22 19:43:31 ----D---- C:\Program Files\Common Files
2013-08-18 12:45:37 ----D---- C:\Windows\rescache
2013-08-16 17:41:21 ----D---- C:\Windows\Microsoft.NET
2013-08-16 17:41:16 ----RSD---- C:\Windows\assembly
2013-08-16 09:40:19 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-08-16 09:40:19 ----D---- C:\Windows\system32\cs-CZ
2013-08-16 09:40:18 ----D---- C:\Program Files\Internet Explorer
2013-08-16 09:40:18 ----D---- C:\Program Files (x86)\Internet Explorer
2013-08-16 09:40:16 ----D---- C:\Windows\AppPatch
2013-08-16 09:07:11 ----A---- C:\Windows\system32\MRT.exe
2013-08-12 12:09:30 ----D---- C:\Windows\system32\oobe
2013-08-12 11:30:22 ----D---- C:\Users\Lenovo\AppData\Roaming\uTorrent
2013-08-12 11:16:28 ----D---- C:\ProgramData\Electronic Arts
2013-08-11 20:47:45 ----D---- C:\Program Files (x86)\Google
2013-08-11 15:53:09 ----D---- C:\Program Files (x86)\Electronic Arts
2013-08-10 12:48:25 ----D---- C:\Windows\system32\wdi
2013-08-09 22:04:28 ----RD---- C:\Users
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 LHDmgr;LHDmgr; C:\Windows\System32\DRIVERS\LhdX64.sys [2013-07-05 39008]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-08-09 503352]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-08-09 254528]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\Windows\system32\DRIVERS\AcpiVpc.sys [2013-07-05 29792]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-12-14 9360896]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-12-14 309760]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-06-14 3678720]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-06-25 76912]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-01-31 467184]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-11-29 44672]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2009-06-03 507392]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 Synth3dVsc;Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [2010-11-21 88960]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\Windows\system32\drivers\tsusbhub.sys [2010-11-21 117248]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2011-01-15 36352]
S3 VGPU;VGPU; C:\Windows\System32\drivers\rdvgkmd.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
S3 WSDScan;Podpora skenování WSD přes UMB; C:\Windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-12-14 204288]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-11-01 179296]
R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04); C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2012-02-21 151648]
R2 EpsonScanSvc;Epson Scanner Service; C:\Windows\system32\EscSvc64.exe [2011-12-12 135824]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-07-25 162672]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-11 116648]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-07-03 1255736]
-----------------EOF-----------------
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: www.delta-homes.com
Pokračujeme
stáhni a spusť http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
některé Antiviry jej mohou blokovat, proto je budeš muset na tu chvíli odstavit
- Zvol možnost Prohledat a poté Smazat a následně Zpráva - otevře se log, ten sem vlož
Stáhni a nainstaluj MBAM zde http://www.malwarebytes.org/products/malwarebytes_free/
Spustit -> na 3.záložce "Aktualizace" -> Kontrola aktualizací
následně na 1.záložce "Kontrolor" -> Rychlá kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení

některé Antiviry jej mohou blokovat, proto je budeš muset na tu chvíli odstavit
- Zvol možnost Prohledat a poté Smazat a následně Zpráva - otevře se log, ten sem vlož

Spustit -> na 3.záložce "Aktualizace" -> Kontrola aktualizací
následně na 1.záložce "Kontrolor" -> Rychlá kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: www.delta-homes.com
RogueKiller se nechce spustit....vyskočí tabulka SPUSTIT, dám ano ,tabulka zmizí a nic.
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.09.03.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Lenovo :: LENOVO-PC [administrátor]
Ochrana: Povolena
3.9.2013 19:12:43
MBAM-log-2013-09-03 (19-23-45).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 220456
Uplynulý čas: 8 minut, 40 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 11
HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B7ABB68E-6263-1CFD-9ECF-0E0392547684} (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1 (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NtVdmSrv (Malware.Trace) -> Data: C:\Windows\inf\ntvdm.vbe -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\Program Files (x86)\EZDownloader (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 45
C:\ProgramData\InstallMate\{9F82F42A-3D83-4BCB-A920-75A14461D6DC}\Setup.exe (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\{9F82F42A-3D83-4BCB-A920-75A14461D6DC}\TsuDll.dll (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\AppData\Local\Temp\appshat-distribution.exe (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\AppData\Local\Temp\Optimizer_Pro.exe (PUP.Optional.PCOptimizerPro) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WADesktop.Updater.exe (PUP.Optional.WebCake.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\FreeMahjongGamesSetup-97bKIyH.exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\Pea Mystie Unicase.exe (PUP.Optional.Installrex) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\Sims3_iso.exe (PUP.Optional.OneClickDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\SmileyMonster_downloader_by_Ffonts (1).exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\SmileyMonster_downloader_by_Ffonts.exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\SoftonicDownloader_for_synaptics-touchpad-driver.exe (PUP.Optional.Softonic) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\The_Sims_3-Razor1911.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\The_Sims_3_iso.exe (PUP.Optional.OneClickDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\Turtle_Odyssey_2.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\1VY4ETVL\OptimizerPro[1].exe (PUP.Optional.OptimizePro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\1VY4ETVL\WebCakesetup[1].exe (Trojan.PUP.WebCake.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\23IDGXGR\agent_setup[1].exe (PUP.Optional.BetterSoft.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\4YGZPKE3\4[1].exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\4YGZPKE3\522225e2afcfd[1].exe (PUP.Optional.SilentInstall.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\4YGZPKE3\CT2412158_RealoreStudios_DM_single_ch[1].exe (PUP.Optional.Conduit.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\ASFAG92V\ezdownloader[1].exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\ASFAG92V\search_defender_166[1].exe (PUP.Optional.SProtect.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\ASFAG92V\search_defender_alternate_166[1].exe (PUP.Optional.SProtect.A) -> Nebyla provedena žádná instrukce.
C:\Users\Public\Desktop\EZDownloader.lnk (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Windows\Tasks\schedule!3036567561.job (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\ntvdm.vbe (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\ntvdm.inf (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Core.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.exe.config (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Extension.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Spider.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\ICSharpCode.SharpZipLib.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\Interop.SHDocVw.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\TabStrip.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\unins000.dat (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\unins000.exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Custom.dll (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Readme.txt (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Setup.dat (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Setup.exe (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Setup.ico (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\TsuDll.dll (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\_Setup.dll (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
(konec)
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org
Verze: v2013.09.03.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Lenovo :: LENOVO-PC [administrátor]
Ochrana: Povolena
3.9.2013 19:12:43
MBAM-log-2013-09-03 (19-23-45).txt
Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 220456
Uplynulý čas: 8 minut, 40 sekund
Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené klíče v registru: 11
HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77} (PUP.Optional.DefaultTab.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B7ABB68E-6263-1CFD-9ECF-0E0392547684} (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1 (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
Nalezené hodnoty v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NtVdmSrv (Malware.Trace) -> Data: C:\Windows\inf\ntvdm.vbe -> Nebyla provedena žádná instrukce.
Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)
Nalezené složky: 2
C:\Program Files (x86)\EZDownloader (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
Nalezené soubory: 45
C:\ProgramData\InstallMate\{9F82F42A-3D83-4BCB-A920-75A14461D6DC}\Setup.exe (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\{9F82F42A-3D83-4BCB-A920-75A14461D6DC}\TsuDll.dll (PUP.Optional.Tarma.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\AppData\Local\Temp\appshat-distribution.exe (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\AppData\Local\Temp\Optimizer_Pro.exe (PUP.Optional.PCOptimizerPro) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WADesktop.Updater.exe (PUP.Optional.WebCake.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\FreeMahjongGamesSetup-97bKIyH.exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\Pea Mystie Unicase.exe (PUP.Optional.Installrex) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\Sims3_iso.exe (PUP.Optional.OneClickDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\SmileyMonster_downloader_by_Ffonts (1).exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\SmileyMonster_downloader_by_Ffonts.exe (PUP.Optional.Somoto) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\SoftonicDownloader_for_synaptics-touchpad-driver.exe (PUP.Optional.Softonic) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\The_Sims_3-Razor1911.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\The_Sims_3_iso.exe (PUP.Optional.OneClickDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Downloads\Turtle_Odyssey_2.exe (PUP.Optional.OpenCandy) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\1VY4ETVL\OptimizerPro[1].exe (PUP.Optional.OptimizePro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\1VY4ETVL\WebCakesetup[1].exe (Trojan.PUP.WebCake.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\23IDGXGR\agent_setup[1].exe (PUP.Optional.BetterSoft.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\4YGZPKE3\4[1].exe (PUP.Optional.MultiPlug.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\4YGZPKE3\522225e2afcfd[1].exe (PUP.Optional.SilentInstall.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\4YGZPKE3\CT2412158_RealoreStudios_DM_single_ch[1].exe (PUP.Optional.Conduit.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\ASFAG92V\ezdownloader[1].exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\ASFAG92V\search_defender_166[1].exe (PUP.Optional.SProtect.A) -> Nebyla provedena žádná instrukce.
C:\Users\Lenovo\Local Settings\Temporary Internet Files\Content.IE5\ASFAG92V\search_defender_alternate_166[1].exe (PUP.Optional.SProtect.A) -> Nebyla provedena žádná instrukce.
C:\Users\Public\Desktop\EZDownloader.lnk (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Windows\Tasks\schedule!3036567561.job (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\ntvdm.vbe (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Windows\inf\ntvdm.inf (Malware.Trace) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Core.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.exe.config (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Extension.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\EZDownloader.Spider.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\ICSharpCode.SharpZipLib.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\Interop.SHDocVw.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\TabStrip.dll (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\unins000.dat (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\EZDownloader\unins000.exe (PUP.Optional.EZDownloader.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Custom.dll (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Readme.txt (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Setup.dat (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Setup.exe (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\Setup.ico (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\TsuDll.dll (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\InstallMate\OptimizerPro\_Setup.dll (PUP.Optional.OptimizerPro.A) -> Nebyla provedena žádná instrukce.
(konec)
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: www.delta-homes.com


Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: www.delta-homes.com
RogueKiller se mnou prostě nemluví. V mbam vše odstraněno.
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: www.delta-homes.com
Jaký je současný problém?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: www.delta-homes.com
Kliknu na RogueKiller, objeví se tabulka "Chcte následujícímu programu..... kliknu na ano a nestane se nic, jrn zmmizí tabulka.
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: www.delta-homes.com
Po nápovědě kolegy - zkus klik pravým a spustit jako správce/administrátor
Můj dotaz na problémy směřoval na chování PC (a nepiš mi houpy-hou) 


Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: www.delta-homes.com
Stejný výsledek. 0
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: www.delta-homes.com
Tak se tím netrap a napiš mi co PC?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: www.delta-homes.com
Tváří se OK. Děkuji.
- Pavuk29
- VIP in memoriam
- Příspěvky: 6953
- Registrován: 31 říj 2003 08:26
- Bydliště: Banská Bystrica
- Kontaktovat uživatele:
Re: www.delta-homes.com
Tak hotovo, chlapi? 

------------------------------------------------------------------------------------------------------------------------------
PLS NEPISTE MI SZ, NA ICQ A MAILY S OTAZKAMI, PISTE DO FORA

------------------------------------------------------------------------------------------------------------------------------
V pripadne akutnych problemov s chodom fora,
pripadne s inymi uzivatelmi,
kontaktujte ma na ICQ alebo mailom
na pavuk29 zavinac forum.viry.cz. Byvam pri pocitaci casto aj ked nie som online na fore.
http://www.icq.com/people/267560078/
hotline: http://forum.viry.cz/viewtopic.php?f=12&t=116821
pravidla fora: http://forum.viry.cz/viewtopic.php?f=12&t=5601



------------------------------------------------------------------------------------------------------------------------------
V pripadne akutnych problemov s chodom fora,



http://www.icq.com/people/267560078/

