Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
skaza25
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 18 úno 2012 22:05

Prosim o kontrolu logu

#1 Příspěvek od skaza25 »

Dobry den poprosil by som o kontrolu cisto z prevencneho dovodu aj ked mam pocit ze pc reaguje pomalsie ako by mal avsak snazim sa co tyzden upratovat s ccleanerom aspon. Dakujem velmi pekne.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-01-2014 01
Ran by jurtan (administrator) on JURTAN-MSI on 08-01-2014 23:20:52
Running from C:\Users\jurtan\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(ArcSoft, Inc.) C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
() C:\Program Files (x86)\lucky leap\updateluckyleap.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
() C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe
(MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(MICRO-STAR INT'L,.LTD.) C:\Program Files\msi\WMIHookBtnFn\HookKey.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Trusteer Ltd.) C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8123936 2009-09-30] (Realtek Semiconductor)
HKLM\...\Run: [HookKey] - C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [24576 2010-01-06] (MICRO-STAR INT'L,.LTD.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] - C:\windows\system32\rundll32.exe C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [AgentMonitor] - C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [hpqSRMon] - C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-29] (AVAST Software)
HKCU\...\Run: [Google Update] - C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-08-12] (Google Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
HKCU\...\Run: [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\jurtan\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\Mcx1-JURTAN-MSI\...\Winlogon: [Shell] C:\windows\eHome\McrMgr.exe [343552 2009-07-14] (Microsoft Corporation) <==== ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB02B705CB351CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=dn ... 043553&ir=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM-x32 - DefaultScope {6E3AB324-5958-8AAC-7C45-35F099A20406} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {6E3AB324-5958-8AAC-7C45-35F099A20406} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - DefaultScope {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - {62A70663-BF5C-298E-1A10-374A067106A9} URL = http://start.mysearchdial.com/results.p ... 043553&ir=
SearchScopes: HKCU - {F5A7009E-B064-432B-AB20-12204AB6989A} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: lucky leap - {d77aa852-def3-43cb-a3f5-bd679de72f32} - C:\Program Files (x86)\lucky leap\luckyleapBHO.dll (luckyleap)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default
FF user.js: detected! => C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\user.js
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\jurtan\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\jurtan\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\Extensions\staged
FF Extension: Adblock Plus - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=72043553&ir=
CHR RestoreOnStartup: "hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q&cr=72043553&ir=", "hxxp://www.google.com/"
CHR DefaultSearchKeyword: mysearchdial.com
CHR DefaultSearchProvider: Mysearchdial
CHR DefaultSearchURL: http://start.mysearchdial.com/results.p ... 043553&ir=
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Users\jurtan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Google Talk Plugin) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\jurtan\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Extension: (Google Docs) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (lucky leap) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (MySearchDial __MSG_newtab__) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff\9.4.10_0
CHR Extension: (Gmail) - C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx
CHR HKLM-x32\...\Chrome\Extension: [eiimolhnbbbdagljikeckdkldgemmmlj] - C:\Program Files (x86)\lucky leap\eiimolhnbbbdagljikeckdkldgemmmlj.crx
CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx

==================== Services (Whitelisted) =================

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 ADExchange; C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43624 2012-08-14] (ArcSoft, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-29] (AVAST Software)
S2 BitMng; C:\windows\BitAdmin.exe [4279552 2013-12-28] ()
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-08] (NVIDIA Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [1444120 2013-12-02] (Trusteer Ltd.)
R2 Update lucky leap; C:\Program Files (x86)\lucky leap\updateluckyleap.exe [66336 2013-11-07] ()
R2 Util lucky leap; C:\Program Files (x86)\lucky leap\bin\utilluckyleap.exe [66336 2013-11-07] ()
R2 WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [105472 2010-01-07] (MICRO-STAR INT'L,.LTD.)

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-03-06] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [78648 2013-12-29] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-11-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-24] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1034464 2013-12-29] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [422216 2013-12-29] (AVAST Software)
S3 aswStm; C:\windows\system32\drivers\aswStm.sys [79672 2013-12-29] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-29] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [28192 2009-07-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-09-27] (NVIDIA Corporation)
S1 PQNTDrv; C:\Windows\SysWow64\Drivers\PQNTDrv.sys [4228 2003-03-14] (PowerQuest Corporation)
R1 RapportCerberus_59849; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [606672 2013-10-27] ()
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [282648 2013-12-02] (Trusteer Ltd.)
R0 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [316248 2013-12-02] (Trusteer Ltd.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [397784 2013-12-02] (Trusteer Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2014-01-01] ()
U3 aaz1tgtw; C:\Windows\System32\Drivers\aaz1tgtw.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-08 23:20 - 2014-01-08 23:21 - 00021626 _____ C:\Users\jurtan\Desktop\FRST.txt
2014-01-08 23:20 - 2014-01-08 23:20 - 00000000 ____D C:\FRST
2014-01-08 23:15 - 2014-01-08 23:15 - 00112640 _____ (forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
2014-01-08 23:13 - 2014-01-08 23:13 - 01931770 _____ (Farbar) C:\Users\jurtan\Desktop\FRST64.exe
2014-01-04 16:04 - 2014-01-04 16:04 - 00291600 _____ C:\windows\Minidump\010414-14710-01.dmp
2014-01-04 16:04 - 2014-01-04 16:04 - 00000000 ____D C:\windows\Minidump
2014-01-04 06:54 - 2014-01-08 18:37 - 00001680 _____ C:\windows\setupact.log
2014-01-04 06:54 - 2014-01-04 06:54 - 00000000 _____ C:\windows\setuperr.log
2014-01-03 18:38 - 2014-01-03 18:38 - 00048786 _____ C:\Users\jurtan\Documents\cc_20140103_183821.reg
2014-01-01 11:59 - 2014-01-08 18:38 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\newnext.me
2014-01-01 11:59 - 2014-01-03 18:35 - 00000000 ____D C:\Users\jurtan\AppData\Local\Mobogenie
2014-01-01 11:59 - 2014-01-03 18:20 - 00001317 _____ C:\Users\jurtan\daemonprocess.txt
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\Documents\Mobogenie
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\genienext
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\.android
2014-01-01 00:52 - 2014-01-01 00:52 - 00834544 _____ C:\windows\system32\Drivers\sptd.sys
2014-01-01 00:51 - 2014-01-01 00:52 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-30 15:20 - 2013-12-30 15:20 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI
2013-12-30 15:20 - 2012-10-08 02:51 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\Trusteer
2013-12-30 15:20 - 2009-08-14 09:43 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\IsolatedStorage
2013-12-30 15:20 - 2009-08-14 09:39 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\kidoz.52BCFEE1FEAB03D960EAF75B15C2A56D33E8320D.1
2013-12-30 15:20 - 2009-08-14 09:38 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Macromedia
2013-12-30 15:20 - 2009-08-14 09:38 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Adobe
2013-12-30 15:20 - 2009-08-14 09:36 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Skype
2013-12-30 15:20 - 2009-08-14 09:35 - 00067872 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-30 15:20 - 2009-08-14 09:35 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\SRS Labs
2013-12-30 15:20 - 2009-08-14 09:31 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\Documents\My Print Creations
2013-12-30 15:20 - 2009-08-14 09:31 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\ArcSoft
2013-12-30 15:20 - 2009-08-14 09:30 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\ArcSoft
2013-12-30 15:20 - 2009-08-14 09:28 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-12-30 15:20 - 2009-08-14 09:21 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI\AppData\Local\Microsoft Help
2013-12-30 15:20 - 2009-07-14 05:09 - 00001449 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-12-30 15:20 - 2009-07-14 05:09 - 00001415 _____ C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2013-12-30 15:20 - 2009-07-14 05:09 - 00000020 ___SH C:\Users\Mcx1-JURTAN-MSI\ntuser.ini
2013-12-30 15:20 - 2009-07-14 05:09 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-30 15:20 - 2009-07-14 05:09 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-30 15:20 - 2009-07-14 04:54 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-12-30 15:20 - 2009-07-14 04:49 - 00000000 ___RD C:\Users\Mcx1-JURTAN-MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-12-30 12:03 - 2013-12-30 14:06 - 00000258 __RSH C:\ProgramData\ntuser.pol
2013-12-29 14:28 - 2013-12-29 14:29 - 00079672 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2013-12-28 11:58 - 2013-12-28 11:58 - 00001229 _____ C:\Users\Public\Desktop\MediaConverter 8.lnk
2013-12-28 11:57 - 2013-12-28 11:57 - 04279552 _____ C:\windows\BitAdmin.exe
2013-12-21 18:12 - 2013-12-21 18:12 - 00002006 _____ C:\Users\jurtan\Desktop\mkv2vob.lnk
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mkv2vob
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Program Files (x86)\mkv2vob
2013-12-21 18:11 - 2013-12-21 18:11 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-12-20 09:45 - 2013-12-20 09:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 13:52 - 2013-12-15 13:52 - 00011454 _____ C:\Users\jurtan\Desktop\AMY DOCHADZKA 2014.odt
2013-12-15 00:28 - 2013-12-15 00:28 - 00003106 _____ C:\windows\System32\Tasks\{5F48A4DA-9001-44AA-BBAF-D6F9DDE06C21}
2013-12-13 01:27 - 2013-05-10 05:56 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2013-12-13 01:27 - 2013-05-10 05:56 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2013-12-13 01:27 - 2013-05-10 04:56 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2013-12-13 01:27 - 2013-05-10 04:56 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2013-12-13 01:24 - 2013-11-26 11:54 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-13 01:24 - 2013-11-26 10:19 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-12-13 01:24 - 2013-11-26 10:18 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2013-12-13 01:24 - 2013-11-26 10:11 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-13 01:24 - 2013-11-26 09:48 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-12-13 01:24 - 2013-11-26 09:46 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2013-12-13 01:24 - 2013-11-26 09:41 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-13 01:24 - 2013-11-26 09:29 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-12-13 01:24 - 2013-11-26 09:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-12-13 01:24 - 2013-11-26 09:23 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-12-13 01:24 - 2013-11-26 09:21 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-12-13 01:24 - 2013-11-26 09:18 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-12-13 01:24 - 2013-11-26 09:18 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2013-12-13 01:24 - 2013-11-26 09:16 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2013-12-13 01:24 - 2013-11-26 08:57 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-13 01:24 - 2013-11-26 08:38 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-13 01:24 - 2013-11-26 08:38 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-12-13 01:24 - 2013-11-26 08:35 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-13 01:24 - 2013-11-26 08:32 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-12-13 01:24 - 2013-11-26 08:28 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2013-12-13 01:24 - 2013-11-26 08:16 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-13 01:24 - 2013-11-26 08:02 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-12-13 01:24 - 2013-11-26 07:48 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-13 01:24 - 2013-11-26 07:32 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-12-13 01:24 - 2013-11-26 07:26 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-13 01:24 - 2013-11-26 07:07 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-13 01:24 - 2013-11-26 06:40 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-13 01:24 - 2013-11-26 06:34 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-12-13 01:24 - 2013-11-26 06:34 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2013-12-13 01:24 - 2013-11-26 06:33 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-13 01:24 - 2013-11-26 06:27 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-12 13:37 - 2013-11-23 18:26 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-12 13:37 - 2013-11-23 17:47 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-12 13:37 - 2013-11-12 02:23 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-12-12 13:37 - 2013-11-12 02:07 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-12-12 13:37 - 2013-10-30 02:32 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-12 13:37 - 2013-10-30 02:19 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-12 13:37 - 2013-10-30 01:24 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-12 13:37 - 2013-10-19 02:18 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-12 13:37 - 2013-10-19 01:36 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-12 13:36 - 2013-10-12 02:32 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-12 13:36 - 2013-10-12 02:31 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-12 13:36 - 2013-10-12 02:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2013-12-12 13:36 - 2013-10-12 02:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-12 13:36 - 2013-10-12 01:33 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2013-12-12 13:36 - 2013-10-12 01:33 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-12 13:36 - 2013-10-12 01:15 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2013-12-12 13:36 - 2013-10-12 01:15 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-12 13:36 - 2013-10-04 02:16 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2013-12-12 13:36 - 2013-10-04 01:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-08 23:21 - 2014-01-08 23:20 - 00021626 _____ C:\Users\jurtan\Desktop\FRST.txt
2014-01-08 23:20 - 2014-01-08 23:20 - 00000000 ____D C:\FRST
2014-01-08 23:15 - 2014-01-08 23:15 - 00112640 _____ (forum.viry.cz) C:\Users\jurtan\Desktop\FRSTLauncher.exe
2014-01-08 23:13 - 2014-01-08 23:13 - 01931770 _____ (Farbar) C:\Users\jurtan\Desktop\FRST64.exe
2014-01-08 23:08 - 2013-09-18 20:43 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-08 23:07 - 2013-09-18 20:43 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-08 23:05 - 2013-08-12 08:49 - 00000912 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job
2014-01-08 23:05 - 2013-03-15 23:46 - 00000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2014-01-08 22:09 - 2013-03-24 08:37 - 01999152 _____ C:\windows\WindowsUpdate.log
2014-01-08 21:59 - 2009-07-14 03:20 - 00000000 ____D C:\windows\system32\NDF
2014-01-08 18:44 - 2009-07-14 04:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-08 18:44 - 2009-07-14 04:45 - 00017600 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-08 18:38 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\newnext.me
2014-01-08 18:37 - 2014-01-04 06:54 - 00001680 _____ C:\windows\setupact.log
2014-01-08 18:37 - 2013-06-30 00:01 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-08 18:37 - 2009-07-14 05:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-08 07:05 - 2013-08-12 08:49 - 00000860 _____ C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job
2014-01-08 00:10 - 2013-09-18 20:45 - 00002193 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-07 13:39 - 2012-09-13 14:55 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2014-01-06 07:01 - 2009-07-14 05:13 - 00779092 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-04 16:04 - 2014-01-04 16:04 - 00291600 _____ C:\windows\Minidump\010414-14710-01.dmp
2014-01-04 16:04 - 2014-01-04 16:04 - 00000000 ____D C:\windows\Minidump
2014-01-04 06:54 - 2014-01-04 06:54 - 00000000 _____ C:\windows\setuperr.log
2014-01-03 18:38 - 2014-01-03 18:38 - 00048786 _____ C:\Users\jurtan\Documents\cc_20140103_183821.reg
2014-01-03 18:35 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\Mobogenie
2014-01-03 18:20 - 2014-01-01 11:59 - 00001317 _____ C:\Users\jurtan\daemonprocess.txt
2014-01-01 12:07 - 2012-11-28 23:36 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\DAEMON Tools Lite
2014-01-01 12:01 - 2012-11-11 23:42 - 00000000 ____D C:\Users\jurtan\AppData\Local\cache
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\Documents\Mobogenie
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\AppData\Local\genienext
2014-01-01 11:59 - 2014-01-01 11:59 - 00000000 ____D C:\Users\jurtan\.android
2014-01-01 11:59 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan
2014-01-01 01:12 - 2009-08-14 09:12 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2014-01-01 00:52 - 2014-01-01 00:52 - 00834544 _____ C:\windows\system32\Drivers\sptd.sys
2014-01-01 00:52 - 2014-01-01 00:51 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2013-12-30 15:20 - 2013-12-30 15:20 - 00000000 ____D C:\Users\Mcx1-JURTAN-MSI
2013-12-30 14:37 - 2013-04-28 11:35 - 00004608 _____ C:\Users\jurtan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-30 14:06 - 2013-12-30 12:03 - 00000258 __RSH C:\ProgramData\ntuser.pol
2013-12-30 13:14 - 2012-09-13 23:08 - 00000000 ___RD C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-12-30 12:03 - 2009-07-14 03:20 - 00000000 ___HD C:\windows\system32\GroupPolicy
2013-12-29 14:29 - 2013-12-29 14:28 - 00079672 _____ (AVAST Software) C:\windows\system32\Drivers\aswstm.sys
2013-12-29 14:29 - 2013-03-31 07:26 - 00001976 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-29 14:28 - 2013-03-15 05:35 - 00207904 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 01034464 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00422216 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00334136 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-29 14:28 - 2012-09-13 14:55 - 00078648 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-29 14:28 - 2012-09-13 14:55 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-28 12:03 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\ArcSoft
2013-12-28 11:58 - 2013-12-28 11:58 - 00001229 _____ C:\Users\Public\Desktop\MediaConverter 8.lnk
2013-12-28 11:58 - 2012-09-13 23:08 - 00000000 ____D C:\Users\jurtan\AppData\Local\ArcSoft
2013-12-28 11:58 - 2009-08-14 09:30 - 00000000 ____D C:\ProgramData\ArcSoft
2013-12-28 11:57 - 2013-12-28 11:57 - 04279552 _____ C:\windows\BitAdmin.exe
2013-12-28 11:57 - 2009-08-14 09:29 - 00000000 ____D C:\Program Files (x86)\ArcSoft
2013-12-27 13:06 - 2013-06-30 00:02 - 00000000 ____D C:\Users\UpdatusUser.jurtan-msi
2013-12-24 09:19 - 2012-09-13 14:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-21 18:12 - 2013-12-21 18:12 - 00002006 _____ C:\Users\jurtan\Desktop\mkv2vob.lnk
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\mkv2vob
2013-12-21 18:12 - 2013-12-21 18:12 - 00000000 ____D C:\Program Files (x86)\mkv2vob
2013-12-21 18:11 - 2013-12-21 18:11 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-12-20 09:45 - 2013-12-20 09:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 13:52 - 2013-12-15 13:52 - 00011454 _____ C:\Users\jurtan\Desktop\AMY DOCHADZKA 2014.odt
2013-12-15 00:28 - 2013-12-15 00:28 - 00003106 _____ C:\windows\System32\Tasks\{5F48A4DA-9001-44AA-BBAF-D6F9DDE06C21}
2013-12-14 13:50 - 2013-07-16 15:59 - 00000000 ____D C:\windows\system32\MRT
2013-12-14 13:48 - 2012-09-14 07:31 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-14 08:27 - 2009-07-14 05:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2013-12-14 00:33 - 2009-07-14 03:20 - 00000000 ____D C:\windows\rescache
2013-12-13 13:00 - 2009-07-14 04:45 - 00363008 _____ C:\windows\system32\FNTCACHE.DAT
2013-12-13 01:26 - 2009-08-14 09:21 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-10 21:05 - 2013-03-15 23:46 - 00003768 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 21:05 - 2012-09-13 21:59 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 21:05 - 2012-09-13 21:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-09 09:58 - 2009-07-14 05:08 - 00032620 _____ C:\windows\Tasks\SCHEDLGU.TXT

ZeroAccess:
C:\Windows\Installer\{9e5eb2ba-c9bf-e656-3b47-38699ca6115f}

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job => C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job => C:\Users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\jurtan\Desktop" je 1477 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosim o kontrolu logu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Tam toho je :arcisit:

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

skaza25
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 18 úno 2012 22:05

Re: Prosim o kontrolu logu

#3 Příspěvek od skaza25 »

# AdwCleaner v3.016 - Report created 09/01/2014 at 09:10:26
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : jurtan - JURTAN-MSI
# Running from : D:\Downloads\adwcleaner(1).exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : Update lucky leap
[#] Service Deleted : Util lucky leap

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\lucky leap
Folder Deleted : C:\Program Files (x86)\MyPC Backup
Folder Deleted : C:\Users\jurtan\AppData\Local\Mobogenie
Folder Deleted : C:\Users\jurtan\AppData\Roaming\Mysearchdial
Folder Deleted : C:\Users\jurtan\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\jurtan\Documents\Mobogenie
Folder Deleted : C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj
Folder Deleted : C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflphaooapbgpeakohlggbpidpppgdff
File Deleted : C:\Users\jurtan\AppData\Local\mysearchdial_speedial_v9.0.2.crx
File Deleted : C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\user.js
File Deleted : C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eiimolhnbbbdagljikeckdkldgemmmlj
Key Deleted : HKCU\Software\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\pflphaooapbgpeakohlggbpidpppgdff
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D77AA852-DEF3-43CB-A3F5-BD679DE72F32}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B8BFA10F-6FFD-44B5-9DBB-E17CBAA107FF}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D77AA852-DEF3-43CB-A3F5-BD679DE72F32}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D77AA852-DEF3-43CB-A3F5-BD679DE72F32}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\lucky leap
Key Deleted : HKCU\Software\mysearchdial
Key Deleted : HKLM\Software\dt soft\daemon tools toolbar
Key Deleted : HKLM\Software\InstallCore
Key Deleted : HKLM\Software\lucky leap
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\lucky leap

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16428

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v26.0 (en-US)

[ File : C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\prefs.js ]

Line Deleted : user_pref("extensions.mysearchdial.aflt", "dnldmsd");
Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
Line Deleted : user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q1H1B1Q");
Line Deleted : user_pref("extensions.mysearchdial.cr", "72043553");
Line Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
Line Deleted : user_pref("extensions.mysearchdial.hmpg", true);
Line Deleted : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I1Q[...]
Line Deleted : user_pref("extensions.mysearchdial.id", "6C626D0B794FE7E8");
Line Deleted : user_pref("extensions.mysearchdial.instlDay", "15987");
Line Deleted : user_pref("extensions.mysearchdial.instlRef", "");
Line Deleted : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G1I[...]
Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");
Line Deleted : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dnldmsd&cd=2XzuyEtN2Y1L1QzuyC0CyCtByC0DtD0ByBzyyE0F0EyB0EzztN0D0Tzu0CyCyEzztN1L2XzutBtFtBtFyEtFyBtAtCtN1L1Czu1Q1G[...]
Line Deleted : user_pref("extensions.mysearchdial.vrsn", "");
Line Deleted : user_pref("extensions.mysearchdial.vrsni", "");
Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "22:31:34");
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url(\"I[...]
Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");

-\\ Google Chrome v32.0.1700.72

[ File : C:\Users\jurtan\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : icon_url
Deleted : search_url
Deleted : keyword
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [8387 octets] - [09/01/2014 09:09:17]
AdwCleaner[S0].txt - [7592 octets] - [09/01/2014 09:10:26]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7652 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosim o kontrolu logu

#4 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

skaza25
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 18 úno 2012 22:05

Re: Prosim o kontrolu logu

#5 Příspěvek od skaza25 »

rkill:


Rkill 2.4.7 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 01/09/2014 12:30:18 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* FontCache => %SystemRoot%\system32\svchost.exe -k LocalService [Incorrect ImagePath]

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 localhost

Program finished at: 01/09/2014 12:30:31 PM
Execution time: 0 hours(s), 0 minute(s), and 13 seconds(s)



combofix:


ComboFix 14-01-08.03 - jurtan 09/01/2014 12:35:05.5.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2815.1599 [GMT 0:00]
Running from: d:\downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\Database\tmp.edb
.
.
((((((((((((((((((((((((( Files Created from 2013-12-09 to 2014-01-09 )))))))))))))))))))))))))))))))
.
.
2014-01-09 09:09 . 2014-01-09 09:10 -------- d-----w- C:\AdwCleaner
2014-01-08 23:20 . 2014-01-08 23:20 -------- d-----w- C:\FRST
2014-01-08 00:33 . 2014-01-09 12:40 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{47E94A55-A4DE-4037-BED5-CED8D505A18A}\offreg.dll
2014-01-07 13:42 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{47E94A55-A4DE-4037-BED5-CED8D505A18A}\mpengine.dll
2014-01-01 11:59 . 2014-01-01 11:59 -------- d-----w- c:\users\jurtan\.android
2014-01-01 11:59 . 2014-01-09 05:54 -------- d-----w- c:\users\jurtan\AppData\Roaming\newnext.me
2014-01-01 11:59 . 2014-01-01 11:59 -------- d-----w- c:\users\jurtan\AppData\Local\genienext
2014-01-01 00:52 . 2014-01-01 00:52 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2014-01-01 00:51 . 2014-01-01 00:52 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-12-30 15:20 . 2013-12-30 15:20 -------- d-----w- c:\users\Mcx1-JURTAN-MSI
2013-12-30 12:04 . 2013-12-30 12:04 895088 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2013-12-30 12:03 . 2013-12-30 12:03 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2013-12-29 14:28 . 2013-12-29 14:29 79672 ----a-w- c:\windows\system32\drivers\aswstm.sys
2013-12-28 12:02 . 2013-12-28 12:02 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Trusteer
2013-12-28 11:57 . 2013-12-28 11:57 4279552 ----a-w- c:\windows\BitAdmin.exe
2013-12-28 11:57 . 2013-12-28 11:57 -------- d-----w- c:\program files (x86)\ArcSoft MediaConverter v8.0.0.16 AutoInstaller
2013-12-21 18:12 . 2013-12-21 18:12 -------- d-----w- c:\users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 . 2013-12-21 18:12 29184 ----a-r- c:\users\jurtan\AppData\Roaming\Microsoft\Installer\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}\Icon21AE04E8.exe
2013-12-21 18:12 . 2013-12-21 18:12 -------- d-----w- c:\program files (x86)\mkv2vob
2013-12-21 18:11 . 2013-12-21 18:11 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-12-21 18:11 . 2013-12-21 18:11 -------- d-----w- c:\program files (x86)\MKVToolNix
2013-12-13 01:27 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-13 01:27 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-13 01:27 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-13 01:27 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-13 01:27 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 13:37 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-12-12 13:37 . 2013-10-30 02:19 301568 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-12-12 13:37 . 2013-10-30 01:24 3155968 ----a-w- c:\windows\system32\win32k.sys
2013-12-12 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-12-12 13:37 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-12-12 13:37 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-12-12 13:37 . 2013-10-19 01:36 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-12-12 13:37 . 2013-11-12 02:23 2048 ----a-w- c:\windows\system32\tzres.dll
2013-12-12 13:37 . 2013-11-12 02:07 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-12-12 13:36 . 2013-10-04 02:16 116736 ----a-w- c:\windows\system32\drivers\drmk.sys
2013-12-12 13:36 . 2013-10-04 01:36 230400 ----a-w- c:\windows\system32\drivers\portcls.sys
2013-12-12 13:36 . 2013-10-12 02:32 150016 ----a-w- c:\windows\system32\wshom.ocx
2013-12-12 13:36 . 2013-10-12 02:04 121856 ----a-w- c:\windows\SysWow64\wshom.ocx
2013-12-12 13:36 . 2013-10-12 02:31 202752 ----a-w- c:\windows\system32\scrrun.dll
2013-12-12 13:36 . 2013-10-12 01:33 156160 ----a-w- c:\windows\system32\cscript.exe
2013-12-12 13:36 . 2013-10-12 01:33 168960 ----a-w- c:\windows\system32\wscript.exe
2013-12-12 13:36 . 2013-10-12 01:15 141824 ----a-w- c:\windows\SysWow64\wscript.exe
2013-12-12 13:36 . 2013-10-12 02:03 163840 ----a-w- c:\windows\SysWow64\scrrun.dll
2013-12-12 13:36 . 2013-10-12 01:15 126976 ----a-w- c:\windows\SysWow64\cscript.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-29 14:28 . 2013-03-15 05:35 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-29 14:28 . 2012-09-13 14:55 422216 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-29 14:28 . 2012-09-13 14:55 1034464 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-29 14:28 . 2012-09-13 14:55 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-29 14:28 . 2012-09-13 14:55 334136 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-29 14:28 . 2012-09-13 14:55 43152 ----a-w- c:\windows\avastSS.scr
2013-12-14 13:48 . 2012-09-14 07:31 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-10 21:05 . 2012-09-13 21:59 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-10 21:05 . 2012-09-13 21:59 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-02 19:00 . 2012-09-17 15:23 316248 ----a-w- c:\windows\system32\drivers\RapportKE64.sys
2013-11-27 00:47 . 2013-11-27 00:47 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-27 00:47 . 2013-11-27 00:47 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-27 00:47 . 2013-11-27 00:47 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-27 00:47 . 2013-11-27 00:47 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-27 00:47 . 2013-11-27 00:47 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-27 00:47 . 2013-11-27 00:47 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-27 00:47 . 2013-11-27 00:47 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-27 00:47 . 2013-11-27 00:47 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-27 00:47 . 2013-11-27 00:47 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-27 00:47 . 2013-11-27 00:47 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-27 00:47 . 2013-11-27 00:47 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-27 00:47 . 2013-11-27 00:47 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-27 00:47 . 2013-11-27 00:47 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-27 00:47 . 2013-11-27 00:47 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-27 00:47 . 2013-11-27 00:47 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-27 00:47 . 2013-11-27 00:47 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-27 00:47 . 2013-11-27 00:47 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-27 00:47 . 2013-11-27 00:47 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-27 00:47 . 2013-11-27 00:47 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-27 00:47 . 2013-11-27 00:47 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-27 00:47 . 2013-11-27 00:47 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-27 00:47 . 2013-11-27 00:47 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-27 00:47 . 2013-11-27 00:47 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-27 00:47 . 2013-11-27 00:47 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-27 00:47 . 2013-11-27 00:47 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-27 00:47 . 2013-11-27 00:47 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-27 00:47 . 2013-11-27 00:47 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-27 00:47 . 2013-11-27 00:47 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-27 00:47 . 2013-11-27 00:47 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-27 00:47 . 2013-11-27 00:47 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-27 00:47 . 2013-11-27 00:47 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-27 00:47 . 2013-11-27 00:47 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-27 00:47 . 2013-11-27 00:47 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-27 00:47 . 2013-11-27 00:47 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-27 00:47 . 2013-11-27 00:47 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-27 00:47 . 2013-11-27 00:47 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-27 00:47 . 2013-11-27 00:47 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-27 00:47 . 2013-11-27 00:47 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-27 00:47 . 2013-11-27 00:47 413696 ----a-w- c:\windows\system32\html.iec
2013-11-27 00:47 . 2013-11-27 00:47 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-27 00:47 . 2013-11-27 00:47 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-27 00:47 . 2013-11-27 00:47 235520 ----a-w- c:\windows\system32\url.dll
2013-11-27 00:47 . 2013-11-27 00:47 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-27 00:47 . 2013-11-27 00:47 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-27 00:47 . 2013-11-27 00:47 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-27 00:47 . 2013-11-27 00:47 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-27 00:47 . 2013-11-27 00:47 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-27 00:47 . 2013-11-27 00:47 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-27 00:47 . 2013-11-27 00:47 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-27 00:47 . 2013-11-27 00:47 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-27 00:47 . 2013-11-27 00:47 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-27 00:47 . 2013-11-27 00:47 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-27 00:47 . 2013-11-27 00:47 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-27 00:47 . 2013-11-27 00:47 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-27 00:47 . 2013-11-27 00:47 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-27 00:47 . 2013-11-27 00:47 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-27 00:47 . 2013-11-27 00:47 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-27 00:47 . 2013-11-27 00:47 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-27 00:47 . 2013-11-27 00:47 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-24 07:10 . 2013-03-15 05:35 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-11-24 07:10 . 2012-09-13 14:55 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-11-19 03:33 . 2012-09-13 14:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-08 20:47 . 2013-10-30 08:30 1064224 ----a-w- c:\windows\system32\nvspcap64.dll
2013-11-08 20:47 . 2013-10-30 08:30 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-10-23 10:30 . 2013-11-03 07:48 1884448 ----a-w- c:\windows\system32\nvdispco6433165.dll
2013-10-23 10:30 . 2013-11-03 07:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433165.dll
2013-10-23 10:30 . 2013-11-03 07:48 12572960 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-10-23 10:30 . 2013-11-03 07:48 9524088 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-10-23 10:30 . 2013-11-03 07:48 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-10-23 10:30 . 2013-11-03 07:48 696096 ----a-w- c:\windows\system32\NvFBC64.dll
2013-10-23 10:30 . 2013-11-03 07:48 655136 ----a-w- c:\windows\system32\NvIFR64.dll
2013-10-23 10:30 . 2013-11-03 07:48 599840 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-10-23 10:30 . 2013-11-03 07:48 560416 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-10-23 10:30 . 2013-11-03 07:48 3131680 ----a-w- c:\windows\system32\nvcuvid.dll
2013-10-23 10:30 . 2013-11-03 07:48 3124512 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-10-23 10:30 . 2013-11-03 07:48 30344480 ----a-w- c:\windows\system32\nvoglv64.dll
2013-10-23 10:30 . 2013-11-03 07:48 2946848 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-10-23 10:30 . 2013-11-03 07:48 2747168 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-10-23 10:30 . 2013-11-03 07:48 22933792 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-10-23 10:30 . 2013-11-03 07:48 18199872 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-10-23 10:30 . 2013-11-03 07:48 11426568 ----a-w- c:\windows\system32\nvcuda.dll
2013-10-23 10:30 . 2013-11-03 07:48 11374520 ----a-w- c:\windows\system32\nvopencl.dll
2013-10-23 10:30 . 2013-11-03 07:48 25257248 ----a-w- c:\windows\system32\nvcompiler.dll
2013-10-23 10:30 . 2013-11-03 07:48 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-10-23 10:30 . 2013-06-29 23:58 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-23 10:30 . 2013-06-29 23:58 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-10-23 10:30 . 2013-06-29 23:58 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:30 . 2013-06-29 23:58 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2013-06-29 23:58 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2012-09-15 08:57 61216 ----a-w- c:\windows\system32\OpenCL.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"AgentMonitor"="c:\program files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [2013-06-20 391040]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-29 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 BitMng;BitMng;c:\windows\BitAdmin.exe;c:\windows\BitAdmin.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 enecirhid;ENE CIR HID Receiver;c:\windows\system32\DRIVERS\enecirhid.sys;c:\windows\SYSNATIVE\DRIVERS\enecirhid.sys [x]
R3 enecirhidma;ENE CIR HIDmini Filter;c:\windows\system32\DRIVERS\enecirhidma.sys;c:\windows\SYSNATIVE\DRIVERS\enecirhidma.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\DRIVERS\NVAMACPI.sys;c:\windows\SYSNATIVE\DRIVERS\NVAMACPI.sys [x]
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys;c:\windows\SYSNATIVE\Drivers\RapportKE64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 RapportCerberus_59849;RapportCerberus_59849;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [x]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [x]
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [x]
S2 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe;c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe [x]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 WMI_Hook_Service;WMI_Hook_Service;c:\program files\msi\WMIHookBtnFn\WMI_Hook_Service.exe;c:\program files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys;c:\windows\SYSNATIVE\DRIVERS\enecir.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-08 00:09 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.72\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-01-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 21:05]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18 20:43]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18 20:43]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job
- c:\users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [2013-08-12 08:49]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job
- c:\users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [2013-08-12 08:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-29 14:28 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-09-30 8123936]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-11-08 1064224]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\
FF - ExtSQL: !HIDDEN! 2013-03-22 08:23; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-HookKey - c:\program files (x86)\msi\WMIHookBtnFn\HookKey.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2014-01-09 12:53:55
ComboFix-quarantined-files.txt 2014-01-09 12:53
.
Pre-Run: 9,048,997,888 bytes free
Post-Run: 8,911,056,896 bytes free
.
- - End Of File - - A2F3CDBCBB71CB6B3986F3D09CAB9153
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosim o kontrolu logu

#6 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe ARM"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    
    Folder::
    C:\Windows\Installer\{9e5eb2ba-c9bf-e656-3b47-38699ca6115f}
    
    File::
    c:\windows\Tasks\Adobe Flash Player Updater.job
    c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job
    c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job
    
    Rebot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

skaza25
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 18 úno 2012 22:05

Re: Prosim o kontrolu logu

#7 Příspěvek od skaza25 »

ComboFix 14-01-08.03 - jurtan 09/01/2014 14:38:12.6.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.2815.1399 [GMT 0:00]
Running from: c:\users\jurtan\Desktop\ComboFix.exe
Command switches used :: c:\users\jurtan\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Installer\{9e5eb2ba-c9bf-e656-3b47-38699ca6115f}
.
.
((((((((((((((((((((((((( Files Created from 2013-12-09 to 2014-01-09 )))))))))))))))))))))))))))))))
.
.
2014-01-09 14:50 . 2014-01-09 14:50 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2014-01-09 14:50 . 2014-01-09 14:50 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-01-09 14:50 . 2014-01-09 14:50 -------- d-----w- c:\users\UpdatusUser.jurtan-msi\AppData\Local\temp
2014-01-09 09:09 . 2014-01-09 09:10 -------- d-----w- C:\AdwCleaner
2014-01-08 23:20 . 2014-01-08 23:20 -------- d-----w- C:\FRST
2014-01-08 00:33 . 2014-01-09 12:40 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{47E94A55-A4DE-4037-BED5-CED8D505A18A}\offreg.dll
2014-01-07 13:42 . 2013-12-04 03:28 10315576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{47E94A55-A4DE-4037-BED5-CED8D505A18A}\mpengine.dll
2014-01-01 11:59 . 2014-01-01 11:59 -------- d-----w- c:\users\jurtan\.android
2014-01-01 11:59 . 2014-01-09 05:54 -------- d-----w- c:\users\jurtan\AppData\Roaming\newnext.me
2014-01-01 11:59 . 2014-01-01 11:59 -------- d-----w- c:\users\jurtan\AppData\Local\genienext
2014-01-01 00:52 . 2014-01-01 00:52 834544 ----a-w- c:\windows\system32\drivers\sptd.sys
2014-01-01 00:51 . 2014-01-01 00:52 -------- d-----w- c:\program files (x86)\DAEMON Tools Lite
2013-12-30 15:20 . 2013-12-30 15:20 -------- d-----w- c:\users\Mcx1-JURTAN-MSI
2013-12-30 12:04 . 2013-12-30 12:04 895088 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2013-12-30 12:03 . 2013-12-30 12:03 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2013-12-29 14:28 . 2013-12-29 14:29 79672 ----a-w- c:\windows\system32\drivers\aswstm.sys
2013-12-28 12:02 . 2013-12-28 12:02 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Trusteer
2013-12-28 11:57 . 2013-12-28 11:57 4279552 ----a-w- c:\windows\BitAdmin.exe
2013-12-28 11:57 . 2013-12-28 11:57 -------- d-----w- c:\program files (x86)\ArcSoft MediaConverter v8.0.0.16 AutoInstaller
2013-12-21 18:12 . 2013-12-21 18:12 -------- d-----w- c:\users\jurtan\AppData\Roaming\mkvtoolnix
2013-12-21 18:12 . 2013-12-21 18:12 29184 ----a-r- c:\users\jurtan\AppData\Roaming\Microsoft\Installer\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}\Icon21AE04E8.exe
2013-12-21 18:12 . 2013-12-21 18:12 -------- d-----w- c:\program files (x86)\mkv2vob
2013-12-21 18:11 . 2013-12-21 18:11 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2013-12-21 18:11 . 2013-12-21 18:11 -------- d-----w- c:\program files (x86)\MKVToolNix
2013-12-13 01:27 . 2013-05-10 04:30 167424 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2013-12-13 01:27 . 2013-05-10 03:48 164864 ----a-w- c:\program files (x86)\Windows Media Player\wmplayer.exe
2013-12-13 01:27 . 2013-05-10 05:56 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2013-12-13 01:27 . 2013-05-10 04:56 12625408 ----a-w- c:\windows\SysWow64\wmploc.DLL
2013-12-13 01:27 . 2013-05-10 05:56 14631424 ----a-w- c:\windows\system32\wmp.dll
2013-12-12 13:37 . 2013-10-30 02:32 335360 ----a-w- c:\windows\system32\msieftp.dll
2013-12-12 13:37 . 2013-10-30 02:19 301568 ----a-w- c:\windows\SysWow64\msieftp.dll
2013-12-12 13:37 . 2013-10-30 01:24 3155968 ----a-w- c:\windows\system32\win32k.sys
2013-12-12 13:37 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
2013-12-12 13:37 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll
2013-12-12 13:37 . 2013-10-19 02:18 81408 ----a-w- c:\windows\system32\imagehlp.dll
2013-12-12 13:37 . 2013-10-19 01:36 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll
2013-12-12 13:37 . 2013-11-12 02:23 2048 ----a-w- c:\windows\system32\tzres.dll
2013-12-12 13:37 . 2013-11-12 02:07 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2013-12-12 13:36 . 2013-10-04 02:16 116736 ----a-w- c:\windows\system32\drivers\drmk.sys
2013-12-12 13:36 . 2013-10-04 01:36 230400 ----a-w- c:\windows\system32\drivers\portcls.sys
2013-12-12 13:36 . 2013-10-12 02:32 150016 ----a-w- c:\windows\system32\wshom.ocx
2013-12-12 13:36 . 2013-10-12 02:04 121856 ----a-w- c:\windows\SysWow64\wshom.ocx
2013-12-12 13:36 . 2013-10-12 02:31 202752 ----a-w- c:\windows\system32\scrrun.dll
2013-12-12 13:36 . 2013-10-12 01:33 156160 ----a-w- c:\windows\system32\cscript.exe
2013-12-12 13:36 . 2013-10-12 01:33 168960 ----a-w- c:\windows\system32\wscript.exe
2013-12-12 13:36 . 2013-10-12 01:15 141824 ----a-w- c:\windows\SysWow64\wscript.exe
2013-12-12 13:36 . 2013-10-12 02:03 163840 ----a-w- c:\windows\SysWow64\scrrun.dll
2013-12-12 13:36 . 2013-10-12 01:15 126976 ----a-w- c:\windows\SysWow64\cscript.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-29 14:28 . 2013-03-15 05:35 207904 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-29 14:28 . 2012-09-13 14:55 422216 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-29 14:28 . 2012-09-13 14:55 1034464 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-29 14:28 . 2012-09-13 14:55 78648 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-29 14:28 . 2012-09-13 14:55 334136 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-29 14:28 . 2012-09-13 14:55 43152 ----a-w- c:\windows\avastSS.scr
2013-12-14 13:48 . 2012-09-14 07:31 90708896 ----a-w- c:\windows\system32\MRT.exe
2013-12-10 21:05 . 2012-09-13 21:59 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-10 21:05 . 2012-09-13 21:59 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-12-02 19:00 . 2012-09-17 15:23 316248 ----a-w- c:\windows\system32\drivers\RapportKE64.sys
2013-11-27 00:47 . 2013-11-27 00:47 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-27 00:47 . 2013-11-27 00:47 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-11-27 00:47 . 2013-11-27 00:47 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2013-11-27 00:47 . 2013-11-27 00:47 235008 ----a-w- c:\windows\system32\elshyph.dll
2013-11-27 00:47 . 2013-11-27 00:47 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-27 00:47 . 2013-11-27 00:47 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2013-11-27 00:47 . 2013-11-27 00:47 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-11-27 00:47 . 2013-11-27 00:47 61952 ----a-w- c:\windows\SysWow64\iesetup.dll
2013-11-27 00:47 . 2013-11-27 00:47 34816 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-27 00:47 . 2013-11-27 00:47 337408 ----a-w- c:\windows\SysWow64\html.iec
2013-11-27 00:47 . 2013-11-27 00:47 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-11-27 00:47 . 2013-11-27 00:47 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-11-27 00:47 . 2013-11-27 00:47 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2013-11-27 00:47 . 2013-11-27 00:47 454656 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-11-27 00:47 . 2013-11-27 00:47 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-11-27 00:47 . 2013-11-27 00:47 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2013-11-27 00:47 . 2013-11-27 00:47 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-11-27 00:47 . 2013-11-27 00:47 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2013-11-27 00:47 . 2013-11-27 00:47 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-27 00:47 . 2013-11-27 00:47 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll
2013-11-27 00:47 . 2013-11-27 00:47 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-11-27 00:47 . 2013-11-27 00:47 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-11-27 00:47 . 2013-11-27 00:47 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2013-11-27 00:47 . 2013-11-27 00:47 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-11-27 00:47 . 2013-11-27 00:47 942592 ----a-w- c:\windows\system32\jsIntl.dll
2013-11-27 00:47 . 2013-11-27 00:47 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2013-11-27 00:47 . 2013-11-27 00:47 247808 ----a-w- c:\windows\system32\msls31.dll
2013-11-27 00:47 . 2013-11-27 00:47 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-11-27 00:47 . 2013-11-27 00:47 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-11-27 00:47 . 2013-11-27 00:47 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-11-27 00:47 . 2013-11-27 00:47 195584 ----a-w- c:\windows\system32\msrating.dll
2013-11-27 00:47 . 2013-11-27 00:47 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2013-11-27 00:47 . 2013-11-27 00:47 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-11-27 00:47 . 2013-11-27 00:47 105984 ----a-w- c:\windows\system32\iesysprep.dll
2013-11-27 00:47 . 2013-11-27 00:47 81408 ----a-w- c:\windows\system32\icardie.dll
2013-11-27 00:47 . 2013-11-27 00:47 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-11-27 00:47 . 2013-11-27 00:47 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2013-11-27 00:47 . 2013-11-27 00:47 453120 ----a-w- c:\windows\system32\dxtmsft.dll
2013-11-27 00:47 . 2013-11-27 00:47 413696 ----a-w- c:\windows\system32\html.iec
2013-11-27 00:47 . 2013-11-27 00:47 40448 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-27 00:47 . 2013-11-27 00:47 296960 ----a-w- c:\windows\system32\dxtrans.dll
2013-11-27 00:47 . 2013-11-27 00:47 235520 ----a-w- c:\windows\system32\url.dll
2013-11-27 00:47 . 2013-11-27 00:47 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-11-27 00:47 . 2013-11-27 00:47 84992 ----a-w- c:\windows\system32\mshtmled.dll
2013-11-27 00:47 . 2013-11-27 00:47 626176 ----a-w- c:\windows\system32\msfeeds.dll
2013-11-27 00:47 . 2013-11-27 00:47 548352 ----a-w- c:\windows\system32\vbscript.dll
2013-11-27 00:47 . 2013-11-27 00:47 30208 ----a-w- c:\windows\system32\licmgr10.dll
2013-11-27 00:47 . 2013-11-27 00:47 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2013-11-27 00:47 . 2013-11-27 00:47 243200 ----a-w- c:\windows\system32\webcheck.dll
2013-11-27 00:47 . 2013-11-27 00:47 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-11-27 00:47 . 2013-11-27 00:47 143872 ----a-w- c:\windows\system32\wextract.exe
2013-11-27 00:47 . 2013-11-27 00:47 101376 ----a-w- c:\windows\system32\inseng.dll
2013-11-27 00:47 . 2013-11-27 00:47 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2013-11-27 00:47 . 2013-11-27 00:47 774144 ----a-w- c:\windows\system32\jscript.dll
2013-11-27 00:47 . 2013-11-27 00:47 62464 ----a-w- c:\windows\system32\pngfilt.dll
2013-11-27 00:47 . 2013-11-27 00:47 48128 ----a-w- c:\windows\system32\imgutil.dll
2013-11-27 00:47 . 2013-11-27 00:47 147968 ----a-w- c:\windows\system32\occache.dll
2013-11-27 00:47 . 2013-11-27 00:47 13824 ----a-w- c:\windows\system32\mshta.exe
2013-11-27 00:47 . 2013-11-27 00:47 135680 ----a-w- c:\windows\system32\iepeers.dll
2013-11-24 07:10 . 2013-03-15 05:35 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-11-24 07:10 . 2012-09-13 14:55 92544 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2013-11-19 03:33 . 2012-09-13 14:27 267936 ------w- c:\windows\system32\MpSigStub.exe
2013-11-08 20:47 . 2013-10-30 08:30 1064224 ----a-w- c:\windows\system32\nvspcap64.dll
2013-11-08 20:47 . 2013-10-30 08:30 955168 ----a-w- c:\windows\SysWow64\nvspcap.dll
2013-10-23 10:30 . 2013-11-03 07:48 1884448 ----a-w- c:\windows\system32\nvdispco6433165.dll
2013-10-23 10:30 . 2013-11-03 07:48 1511712 ----a-w- c:\windows\system32\nvdispgenco6433165.dll
2013-10-23 10:30 . 2013-11-03 07:48 12572960 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-10-23 10:30 . 2013-11-03 07:48 9524088 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-10-23 10:30 . 2013-11-03 07:48 9480328 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-10-23 10:30 . 2013-11-03 07:48 696096 ----a-w- c:\windows\system32\NvFBC64.dll
2013-10-23 10:30 . 2013-11-03 07:48 655136 ----a-w- c:\windows\system32\NvIFR64.dll
2013-10-23 10:30 . 2013-11-03 07:48 599840 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-10-23 10:30 . 2013-11-03 07:48 560416 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-10-23 10:30 . 2013-11-03 07:48 3131680 ----a-w- c:\windows\system32\nvcuvid.dll
2013-10-23 10:30 . 2013-11-03 07:48 3124512 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-10-23 10:30 . 2013-11-03 07:48 30344480 ----a-w- c:\windows\system32\nvoglv64.dll
2013-10-23 10:30 . 2013-11-03 07:48 2946848 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-10-23 10:30 . 2013-11-03 07:48 2747168 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-10-23 10:30 . 2013-11-03 07:48 22933792 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-10-23 10:30 . 2013-11-03 07:48 18199872 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-10-23 10:30 . 2013-11-03 07:48 11426568 ----a-w- c:\windows\system32\nvcuda.dll
2013-10-23 10:30 . 2013-11-03 07:48 11374520 ----a-w- c:\windows\system32\nvopencl.dll
2013-10-23 10:30 . 2013-11-03 07:48 25257248 ----a-w- c:\windows\system32\nvcompiler.dll
2013-10-23 10:30 . 2013-11-03 07:48 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-10-23 10:30 . 2013-06-29 23:58 18286416 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-10-23 10:30 . 2013-06-29 23:58 15855568 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-10-23 10:30 . 2013-06-29 23:58 15212336 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-10-23 10:30 . 2013-06-29 23:58 3067560 ----a-w- c:\windows\system32\nvapi64.dll
2013-10-23 10:30 . 2013-06-29 23:58 2695200 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-10-23 10:30 . 2012-09-15 08:57 61216 ----a-w- c:\windows\system32\OpenCL.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"AgentMonitor"="c:\program files (x86)\VTech\DownloadManager\System\AgentMonitor.exe" [2013-06-20 391040]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-29 3764024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 BitMng;BitMng;c:\windows\BitAdmin.exe;c:\windows\BitAdmin.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 enecirhid;ENE CIR HID Receiver;c:\windows\system32\DRIVERS\enecirhid.sys;c:\windows\SYSNATIVE\DRIVERS\enecirhid.sys [x]
R3 enecirhidma;ENE CIR HIDmini Filter;c:\windows\system32\DRIVERS\enecirhidma.sys;c:\windows\SYSNATIVE\DRIVERS\enecirhidma.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\DRIVERS\NVAMACPI.sys;c:\windows\SYSNATIVE\DRIVERS\NVAMACPI.sys [x]
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys;c:\windows\SYSNATIVE\Drivers\RapportKE64.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 RapportCerberus_59849;RapportCerberus_59849;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_59849.sys [x]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [x]
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [x]
S2 ADExchange;ArcSoft Exchange Service;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe;c:\program files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PanService;PandoraService;c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe;c:\program files (x86)\PANDORA.TV\PanService\KMPService.exe [x]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 WMI_Hook_Service;WMI_Hook_Service;c:\program files\msi\WMIHookBtnFn\WMI_Hook_Service.exe;c:\program files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [x]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys;c:\windows\SYSNATIVE\DRIVERS\enecir.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192se.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-08 00:09 1211672 ----a-w- c:\program files (x86)\Google\Chrome\Application\32.0.1700.72\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-01-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-13 21:05]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18 20:43]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-09-18 20:43]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001Core.job
- c:\users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [2013-08-12 08:49]
.
2014-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2437016804-4177654821-3086567756-1001UA.job
- c:\users\jurtan\AppData\Local\Google\Update\GoogleUpdate.exe [2013-08-12 08:49]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-29 14:28 287280 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-09-30 8123936]
"HookKey"="c:\program files (x86)\msi\WMIHookBtnFn\HookKey.exe" [BU]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-11-08 1028384]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2013-11-08 1064224]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default\
FF - ExtSQL: !HIDDEN! 2013-03-22 08:23; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe
c:\program files (x86)\PANDORA.TV\PanService\KMPProcess.exe
c:\program files (x86)\Trusteer\Rapport\bin\RapportService.exe
.
**************************************************************************
.
Completion time: 2014-01-09 14:57:41 - machine was rebooted
ComboFix-quarantined-files.txt 2014-01-09 14:57
ComboFix2.txt 2014-01-09 12:53
.
Pre-Run: 8,906,743,808 bytes free
Post-Run: 8,732,532,736 bytes free
.
- - End Of File - - 19DB1E53262320BCF363032F9213FA89
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosim o kontrolu logu

#8 Příspěvek od vyosek »

Jak se chova PC :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

skaza25
Návštěvník
Návštěvník
Příspěvky: 84
Registrován: 18 úno 2012 22:05

Re: Prosim o kontrolu logu

#9 Příspěvek od skaza25 »

moc som ho nemal ako odskusat ale dam mu 24h a uvidime...zatial sa javi slubne ;-) dakujem velmi pekne

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosim o kontrolu logu

#10 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět