
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Zavirovaný notebook
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zavirovaný notebook
prosím o pomoc se zavirovaným notebookem.
Po spustění FRST se vytvořil log a následně modrá obrazovka..
Děkuji
Re: Zavirovaný notebook
Zdravim
Kdyz stahujete nelegalni bezpecnostni SW, tak si moc nepomuzete
Odinstalujte Spyware Terminator, SpyHunter a Spybot - Search & Destroy
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner




- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: Zavirovaný notebook
Děkuji za pomoc a čas který mi věnujete..
-------------
# AdwCleaner v3.214 - Report created 01/07/2014 at 00:05:38
# Updated 29/06/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Uživatel - UŽIVATEL-PC
# Running from : C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : nethfdrv
Service Deleted : NethxxpService
Service Deleted : ServiceUpdater
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Adblocker
Folder Deleted : C:\ProgramData\sAAve ooN
Folder Deleted : C:\ProgramData\save on
Folder Deleted : C:\Program Files (x86)\Adblocker
Folder Deleted : C:\Program Files (x86)\sAAve ooN
Folder Deleted : C:\Program Files (x86)\save on
Folder Deleted : C:\Program Files\PCDApp
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Ivuška\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Ivuška\AppData\Local\torch
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
Folder Deleted : C:\Users\Uživatel\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Uživatel\AppData\Local\torch
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\euyieaykq@vmqypv.org
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\fkobfkj.y@vdsj-ydghm.org
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\oaphwtii@ehkqapeeoe.net
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
File Deleted : C:\Windows\SysWOW64\hfpapi.dll
File Deleted : C:\Windows\SysWOW64\installd.exe
File Deleted : C:\Windows\SysWOW64\nethtsrv.exe
File Deleted : C:\Windows\SysWOW64\netupdsrv.exe
File Deleted : C:\Windows\System32\drivers\nethfdrv.sys
File Deleted : C:\Users\Uživatel\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\user.js
File Deleted : C:\Windows\Tasks\AmiUpdXp.job
File Deleted : C:\Windows\System32\Tasks\AmiUpdXp
File Deleted : C:\Windows\Tasks\SW-Booster-S-792098896.job
File Deleted : C:\Windows\System32\Tasks\SW-Booster-S-792098896
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-792098896
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EAB5257A-1FB3-474C-9B42-231F52622E72}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\SW-Booster
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v30.0 (cs)
[ File : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56&l=1&q=");
Line Deleted : user_pref("browser.search.order.1", "WebSearch");
Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
Line Deleted : user_pref("extensions.2c14v_XDa3F2.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]
Line Deleted : user_pref("extensions.OU54vIkJI.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumoro[...]
Line Deleted : user_pref("extensions.Rdn.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.SpfpJuJbT.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumoro[...]
Line Deleted : user_pref("extensions.TyVjM0jrjm.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumor[...]
-\\ Google Chrome v
[ File : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Extension] : chekmmhnmiclcainllcehipibboalong
Deleted [Extension] : lomllnbmgafglogpdgikmklkgndelhgn
Deleted [Extension] : gejiggndngefnfnkpnbhbpkdebnkclkc
[ File : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56
Deleted [Startup_urls] : hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56
Deleted [Homepage] : hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56
Deleted [Extension] : chekmmhnmiclcainllcehipibboalong
Deleted [Extension] : gejiggndngefnfnkpnbhbpkdebnkclkc
Deleted [Extension] : lomllnbmgafglogpdgikmklkgndelhgn
*************************
AdwCleaner[R0].txt - [11731 octets] - [01/07/2014 00:04:47]
AdwCleaner[S0].txt - [11461 octets] - [01/07/2014 00:05:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11522 octets] ##########
-------------
# AdwCleaner v3.214 - Report created 01/07/2014 at 00:05:38
# Updated 29/06/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Uživatel - UŽIVATEL-PC
# Running from : C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : nethfdrv
Service Deleted : NethxxpService
Service Deleted : ServiceUpdater
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\Adblocker
Folder Deleted : C:\ProgramData\sAAve ooN
Folder Deleted : C:\ProgramData\save on
Folder Deleted : C:\Program Files (x86)\Adblocker
Folder Deleted : C:\Program Files (x86)\sAAve ooN
Folder Deleted : C:\Program Files (x86)\save on
Folder Deleted : C:\Program Files\PCDApp
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Ivuška\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Ivuška\AppData\Local\torch
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\torch
Folder Deleted : C:\Users\Uživatel\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Uživatel\AppData\Local\torch
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\pdfforge
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\euyieaykq@vmqypv.org
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\fkobfkj.y@vdsj-ydghm.org
Folder Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\oaphwtii@ehkqapeeoe.net
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
Folder Deleted : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn
File Deleted : C:\Windows\SysWOW64\hfpapi.dll
File Deleted : C:\Windows\SysWOW64\installd.exe
File Deleted : C:\Windows\SysWOW64\nethtsrv.exe
File Deleted : C:\Windows\SysWOW64\netupdsrv.exe
File Deleted : C:\Windows\System32\drivers\nethfdrv.sys
File Deleted : C:\Users\Uživatel\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\user.js
File Deleted : C:\Windows\Tasks\AmiUpdXp.job
File Deleted : C:\Windows\System32\Tasks\AmiUpdXp
File Deleted : C:\Windows\Tasks\SW-Booster-S-792098896.job
File Deleted : C:\Windows\System32\Tasks\SW-Booster-S-792098896
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-792098896
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EAB5257A-1FB3-474C-9B42-231F52622E72}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB2E8122-6B02-C83C-3FFB-F56BEA89081F}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9672FE1-1E58-068C-9337-9C84CEC55573}
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\SW-Booster
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v30.0 (cs)
[ File : C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\prefs.js ]
Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56&l=1&q=");
Line Deleted : user_pref("browser.search.order.1", "WebSearch");
Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
Line Deleted : user_pref("extensions.2c14v_XDa3F2.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]
Line Deleted : user_pref("extensions.OU54vIkJI.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumoro[...]
Line Deleted : user_pref("extensions.Rdn.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.SpfpJuJbT.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumoro[...]
Line Deleted : user_pref("extensions.TyVjM0jrjm.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumor[...]
-\\ Google Chrome v
[ File : C:\Users\Ivuška\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Extension] : chekmmhnmiclcainllcehipibboalong
Deleted [Extension] : lomllnbmgafglogpdgikmklkgndelhgn
Deleted [Extension] : gejiggndngefnfnkpnbhbpkdebnkclkc
[ File : C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://websearch.fastsearchings.info/?l=1&q={searchTerms}&pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56
Deleted [Startup_urls] : hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56
Deleted [Homepage] : hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56
Deleted [Extension] : chekmmhnmiclcainllcehipibboalong
Deleted [Extension] : gejiggndngefnfnkpnbhbpkdebnkclkc
Deleted [Extension] : lomllnbmgafglogpdgikmklkgndelhgn
*************************
AdwCleaner[R0].txt - [11731 octets] - [01/07/2014 00:04:47]
AdwCleaner[S0].txt - [11461 octets] - [01/07/2014 00:05:38]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11522 octets] ##########
Re: Zavirovaný notebook

- Pokud ho havet blokuje, pouzijte jeden z nasledujicich - i ty prejmenovane
Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill iExplore.exe:
http://download.bleepingcomputer.com/gr ... xplore.exe
Rkill uSeRiNiT.exe:
http://download.bleepingcomputer.com/gr ... eRiNiT.exe
Rkill WiNlOgOn.exe:
http://download.bleepingcomputer.com/gr ... NlOgOn.exe - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne do par sekund a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Na plose vznikne log Rkill.txt ten mi sem vlozte
- Ted nerestartujte PC - prisli byste o ucinek RKillu

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Zavirovaný notebook
Rkill 2.6.7 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 07/01/2014 05:28:11 PM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 validation.sls.microsoft.com
Program finished at: 07/01/2014 05:29:14 PM
Execution time: 0 hours(s), 1 minute(s), and 3 seconds(s)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 07/01/2014 05:28:11 PM in x64 mode.
Windows Version: Windows 7 Professional Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 validation.sls.microsoft.com
Program finished at: 07/01/2014 05:29:14 PM
Execution time: 0 hours(s), 1 minute(s), and 3 seconds(s)
Re: Zavirovaný notebook
ComboFix 14-06-30.01 - Uživatel 01.07.2014 17:34:53.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3912.2342 [GMT 2:00]
Spuštěný z: c:\users\U×ivatel\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Uživatel\AppData\Local\MSGBOX.EXE
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-01 do 2014-07-01 )))))))))))))))))))))))))))))))
.
.
2014-06-30 22:05 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-30 22:04 . 2014-06-30 22:06 -------- d-----w- C:\AdwCleaner
2014-06-30 21:40 . 2014-06-30 21:40 687 ----a-w- C:\awh55AD.tmp
2014-06-30 21:09 . 2014-06-30 21:09 687 ----a-w- C:\awh1312.tmp
2014-06-30 21:06 . 2014-06-30 21:06 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C36F7D5-06A3-48B2-A9CC-C3592D4EF851}\offreg.dll
2014-06-30 18:19 . 2014-06-30 18:19 687 ----a-w- C:\awh3E95.tmp
2014-06-30 17:58 . 2014-06-30 17:58 687 ----a-w- C:\awh3DDA.tmp
2014-06-30 17:39 . 2014-06-30 17:39 -------- d-----w- c:\program files\CCleaner
2014-06-30 17:32 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-06-30 17:32 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-06-30 17:32 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-06-30 17:32 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-06-30 17:28 . 2014-05-30 09:11 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-06-30 13:58 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C36F7D5-06A3-48B2-A9CC-C3592D4EF851}\mpengine.dll
2014-06-25 16:53 . 2014-06-20 13:28 61112 ----a-w- c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-25 16:13 . 2014-01-19 17:57 1419 --s-a-w- c:\windows\SysWow64\msstp.vbe
2014-06-25 16:13 . 2014-06-25 16:13 -------- d-----w- c:\program files (x86)\AVG 2013+licence key
2014-06-25 16:06 . 2014-06-25 16:06 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2014-06-25 16:06 . 2014-06-30 21:59 -------- d-----w- c:\program files (x86)\Spyware Terminator
2014-06-25 15:05 . 2014-06-25 15:05 -------- d-----w- c:\users\Uživatel\AppData\Local\6651
2014-06-25 11:10 . 2014-06-25 15:38 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-06-25 11:10 . 2014-06-25 15:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2014-06-25 11:01 . 2014-06-25 11:01 687 ----a-w- C:\awh3BF6.tmp
2014-06-25 10:52 . 2014-06-25 10:52 687 ----a-w- C:\awhADEA.tmp
2014-06-25 10:51 . 2014-06-25 10:51 -------- d-----w- c:\programdata\MySearch
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\programdata\Trusted Publisher
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\users\Uživatel\AppData\Local\Adobe
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-----w- c:\windows\system32\appmgmt
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieUserList
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 10:31 . 2014-06-25 10:31 -------- d-----w- c:\users\Uživatel\AppData\Local\Packages
2014-06-25 10:30 . 2014-06-30 17:43 -------- d-----w- c:\programdata\6b4f3e85ab1ac942
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Uživatel\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Ivuška\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Google
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\HomeGroupUser$
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Guest
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Administrator
2014-06-25 09:05 . 2014-06-25 09:05 -------- d-----w- c:\program files\Enigma Software Group
2014-06-25 09:04 . 2014-06-30 22:02 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-25 09:04 . 2014-06-25 09:04 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-06-25 08:58 . 2014-06-30 21:33 -------- d-----w- C:\FRST
2014-06-25 08:41 . 2014-06-25 08:41 687 ----a-w- C:\awh46BF.tmp
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\SysWow64\Wat
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\system32\Wat
2014-06-25 08:28 . 2014-06-25 08:28 687 ----a-w- C:\awhB441.tmp
2014-06-25 07:59 . 2014-06-25 08:01 -------- d-----w- c:\windows\system32\MRT
2014-06-25 07:36 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-06-25 07:24 . 2014-06-25 07:24 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 859648 ----a-w- c:\windows\system32\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-06-25 07:24 . 2014-06-25 07:24 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-06-25 07:23 . 2014-06-25 07:23 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-06-25 07:23 . 2014-06-25 07:23 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-06-25 07:14 . 2014-06-25 07:14 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-06-25 07:14 . 2014-06-25 07:14 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-06-25 06:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-06-25 05:57 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-06-25 05:57 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-06-25 05:57 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-06-25 05:51 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-06-25 05:50 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-06-25 05:50 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-06-25 05:50 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-06-25 05:50 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:50 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:48 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2014-06-25 05:47 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-06-25 05:46 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2014-06-25 05:45 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2014-06-25 05:36 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-06-25 05:36 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-06-25 05:33 . 2014-06-25 05:33 687 ----a-w- C:\awh1515.tmp
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Oracle
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\windows\Sun
2014-06-25 05:13 . 2014-06-25 05:13 -------- d-----w- c:\programdata\Oracle
2014-06-25 05:12 . 2014-06-25 05:12 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-06-25 05:12 . 2014-05-07 13:02 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-06-25 05:10 . 2014-06-25 05:10 687 ----a-w- C:\awh2F78.tmp
2014-06-25 05:09 . 2014-06-25 05:09 -------- d-----w- c:\programdata\McAfee
2014-06-24 19:55 . 2014-05-02 20:27 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BAB4D77-653B-4B9E-A986-D47B75579054}\gapaengine.dll
2014-06-24 19:54 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-06-20 19:29 . 2014-06-20 19:29 284264 ----a-w- c:\windows\Firefox Setup Stub 30.0.exe
2014-06-19 16:37 . 2014-06-19 16:37 687 ----a-w- C:\awhAFB2.tmp
2014-06-19 16:32 . 2014-06-19 16:32 -------- d-----w- c:\program files (x86)\Common Files\Config
2014-06-18 02:43 . 2014-06-17 12:49 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 11:57 . 2014-06-17 11:57 108544 ----a-w- c:\windows\SysWow64\hfnapi.dll
2014-06-03 19:19 . 2014-06-03 19:19 -------- d-----w- c:\users\Uživatel\AppData\Local\Macromedia
2014-06-03 19:15 . 2014-06-03 19:15 -------- d-----w- c:\users\Uživatel\AppData\Local\Mozilla
2014-06-01 20:02 . 2014-06-25 05:09 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-01 20:02 . 2014-06-25 05:09 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\SysWow64\Macromed
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\system32\Macromed
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-27 13:05 . 2014-05-31 05:57 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys
2014-05-02 20:27 . 2013-08-23 06:05 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2012-03-23 1105488]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-05-07 256896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 esgiguard;esgiguard;c:\program files\ENIGMA SOFTWARE GROUP\SPYHUNTER\esgiguard.sys;c:\program files\ENIGMA SOFTWARE GROUP\SPYHUNTER\esgiguard.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 {3f538614-b636-4023-9ec2-564ada4b07b3}w64;{3f538614-b636-4023-9ec2-564ada4b07b3}w64;c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys;c:\windows\SYSNATIVE\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys [x]
S1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64;{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64;c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys;c:\windows\SYSNATIVE\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys [x]
S1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64;{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64;c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys;c:\windows\SYSNATIVE\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys;c:\windows\SYSNATIVE\DRIVERS\bcmvwl64.sys [x]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 SmbDrv;SmbDrv;c:\windows\system32\DRIVERS\Smb_driver.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-27 12343400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-02-20 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-02-20 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-02-20 440600]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2013-08-16 7138816]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - c:\program files (x86)\Adblocker\8TjqFlez.dll
BHO-{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - c:\program files (x86)\Adblocker\8TjqFlez.x64.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SpywareTerminatorShield - c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM-Run-SpywareTerminatorUpdater - c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Launch Manager\LMutilps32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2014-07-01 17:45:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-07-01 15:45
.
Před spuštěním: Volných bajtů: 79 303 180 288
Po spuštění: Volných bajtů: 78 697 701 376
.
- - End Of File - - 0D1D5CE163D7AD1A2BFE55821D939F4E
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3912.2342 [GMT 2:00]
Spuštěný z: c:\users\U×ivatel\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Uživatel\AppData\Local\MSGBOX.EXE
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-01 do 2014-07-01 )))))))))))))))))))))))))))))))
.
.
2014-06-30 22:05 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-30 22:04 . 2014-06-30 22:06 -------- d-----w- C:\AdwCleaner
2014-06-30 21:40 . 2014-06-30 21:40 687 ----a-w- C:\awh55AD.tmp
2014-06-30 21:09 . 2014-06-30 21:09 687 ----a-w- C:\awh1312.tmp
2014-06-30 21:06 . 2014-06-30 21:06 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C36F7D5-06A3-48B2-A9CC-C3592D4EF851}\offreg.dll
2014-06-30 18:19 . 2014-06-30 18:19 687 ----a-w- C:\awh3E95.tmp
2014-06-30 17:58 . 2014-06-30 17:58 687 ----a-w- C:\awh3DDA.tmp
2014-06-30 17:39 . 2014-06-30 17:39 -------- d-----w- c:\program files\CCleaner
2014-06-30 17:32 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-06-30 17:32 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-06-30 17:32 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-06-30 17:32 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-06-30 17:28 . 2014-05-30 09:11 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-06-30 13:58 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C36F7D5-06A3-48B2-A9CC-C3592D4EF851}\mpengine.dll
2014-06-25 16:53 . 2014-06-20 13:28 61112 ----a-w- c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-25 16:13 . 2014-01-19 17:57 1419 --s-a-w- c:\windows\SysWow64\msstp.vbe
2014-06-25 16:13 . 2014-06-25 16:13 -------- d-----w- c:\program files (x86)\AVG 2013+licence key
2014-06-25 16:06 . 2014-06-25 16:06 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2014-06-25 16:06 . 2014-06-30 21:59 -------- d-----w- c:\program files (x86)\Spyware Terminator
2014-06-25 15:05 . 2014-06-25 15:05 -------- d-----w- c:\users\Uživatel\AppData\Local\6651
2014-06-25 11:10 . 2014-06-25 15:38 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2014-06-25 11:10 . 2014-06-25 15:40 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2014-06-25 11:01 . 2014-06-25 11:01 687 ----a-w- C:\awh3BF6.tmp
2014-06-25 10:52 . 2014-06-25 10:52 687 ----a-w- C:\awhADEA.tmp
2014-06-25 10:51 . 2014-06-25 10:51 -------- d-----w- c:\programdata\MySearch
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\programdata\Trusted Publisher
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\users\Uživatel\AppData\Local\Adobe
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-----w- c:\windows\system32\appmgmt
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieUserList
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 10:31 . 2014-06-25 10:31 -------- d-----w- c:\users\Uživatel\AppData\Local\Packages
2014-06-25 10:30 . 2014-06-30 17:43 -------- d-----w- c:\programdata\6b4f3e85ab1ac942
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Uživatel\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Ivuška\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Google
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\HomeGroupUser$
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Guest
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Administrator
2014-06-25 09:05 . 2014-06-25 09:05 -------- d-----w- c:\program files\Enigma Software Group
2014-06-25 09:04 . 2014-06-30 22:02 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-25 09:04 . 2014-06-25 09:04 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-06-25 08:58 . 2014-06-30 21:33 -------- d-----w- C:\FRST
2014-06-25 08:41 . 2014-06-25 08:41 687 ----a-w- C:\awh46BF.tmp
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\SysWow64\Wat
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\system32\Wat
2014-06-25 08:28 . 2014-06-25 08:28 687 ----a-w- C:\awhB441.tmp
2014-06-25 07:59 . 2014-06-25 08:01 -------- d-----w- c:\windows\system32\MRT
2014-06-25 07:36 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-06-25 07:24 . 2014-06-25 07:24 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 859648 ----a-w- c:\windows\system32\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-06-25 07:24 . 2014-06-25 07:24 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-06-25 07:23 . 2014-06-25 07:23 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-06-25 07:23 . 2014-06-25 07:23 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-06-25 07:14 . 2014-06-25 07:14 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-06-25 07:14 . 2014-06-25 07:14 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-06-25 06:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-06-25 05:57 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-06-25 05:57 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-06-25 05:57 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-06-25 05:51 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-06-25 05:50 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-06-25 05:50 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-06-25 05:50 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-06-25 05:50 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:50 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:48 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2014-06-25 05:47 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-06-25 05:46 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2014-06-25 05:45 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2014-06-25 05:36 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-06-25 05:36 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-06-25 05:33 . 2014-06-25 05:33 687 ----a-w- C:\awh1515.tmp
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Oracle
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\windows\Sun
2014-06-25 05:13 . 2014-06-25 05:13 -------- d-----w- c:\programdata\Oracle
2014-06-25 05:12 . 2014-06-25 05:12 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-06-25 05:12 . 2014-05-07 13:02 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-06-25 05:10 . 2014-06-25 05:10 687 ----a-w- C:\awh2F78.tmp
2014-06-25 05:09 . 2014-06-25 05:09 -------- d-----w- c:\programdata\McAfee
2014-06-24 19:55 . 2014-05-02 20:27 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BAB4D77-653B-4B9E-A986-D47B75579054}\gapaengine.dll
2014-06-24 19:54 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-06-20 19:29 . 2014-06-20 19:29 284264 ----a-w- c:\windows\Firefox Setup Stub 30.0.exe
2014-06-19 16:37 . 2014-06-19 16:37 687 ----a-w- C:\awhAFB2.tmp
2014-06-19 16:32 . 2014-06-19 16:32 -------- d-----w- c:\program files (x86)\Common Files\Config
2014-06-18 02:43 . 2014-06-17 12:49 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 11:57 . 2014-06-17 11:57 108544 ----a-w- c:\windows\SysWow64\hfnapi.dll
2014-06-03 19:19 . 2014-06-03 19:19 -------- d-----w- c:\users\Uživatel\AppData\Local\Macromedia
2014-06-03 19:15 . 2014-06-03 19:15 -------- d-----w- c:\users\Uživatel\AppData\Local\Mozilla
2014-06-01 20:02 . 2014-06-25 05:09 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-01 20:02 . 2014-06-25 05:09 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\SysWow64\Macromed
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\system32\Macromed
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-27 13:05 . 2014-05-31 05:57 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys
2014-05-02 20:27 . 2013-08-23 06:05 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2012-03-23 1105488]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-05-07 256896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 esgiguard;esgiguard;c:\program files\ENIGMA SOFTWARE GROUP\SPYHUNTER\esgiguard.sys;c:\program files\ENIGMA SOFTWARE GROUP\SPYHUNTER\esgiguard.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 {3f538614-b636-4023-9ec2-564ada4b07b3}w64;{3f538614-b636-4023-9ec2-564ada4b07b3}w64;c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys;c:\windows\SYSNATIVE\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys [x]
S1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64;{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64;c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys;c:\windows\SYSNATIVE\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys [x]
S1 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64;{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64;c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys;c:\windows\SYSNATIVE\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys;c:\windows\SYSNATIVE\DRIVERS\bcmvwl64.sys [x]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 SmbDrv;SmbDrv;c:\windows\system32\DRIVERS\Smb_driver.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-27 12343400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-02-20 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-02-20 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-02-20 440600]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2013-08-16 7138816]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - c:\program files (x86)\Adblocker\8TjqFlez.dll
BHO-{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - c:\program files (x86)\Adblocker\8TjqFlez.x64.dll
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SpywareTerminatorShield - c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM-Run-SpywareTerminatorUpdater - c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Launch Manager\LMutilps32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2014-07-01 17:45:12 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-07-01 15:45
.
Před spuštěním: Volných bajtů: 79 303 180 288
Po spuštění: Volných bajtů: 78 697 701 376
.
- - End Of File - - 0D1D5CE163D7AD1A2BFE55821D939F4E
Re: Zavirovaný notebook

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: C:\awh55AD.tmp C:\awh1312.tmp C:\awh3E95.tmp C:\awh3DDA.tmp C:\awh3BF6.tmp C:\awhADEA.tmp c:\windows\system32\drivers\stflt.sys C:\awh46BF.tmp C:\awhB441.tmp C:\awh1515.tmp C:\awh2F78.tmp C:\awhAFB2.tmp Collect:: c:\windows\SysWow64\msstp.vbe Rootkit:: c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys Folder:: c:\program files (x86)\AVG 2013+licence key c:\program files (x86)\Spyware Terminator c:\users\Uživatel\AppData\Local\6651 c:\programdata\Spybot - Search & Destroy c:\program files (x86)\Spybot - Search & Destroy 2 c:\programdata\MySearch c:\program files\Enigma Software Group c:\programdata\McAfee c:\program files\ENIGMA SOFTWARE GROUP Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"=- "SunJavaUpdateSched"=- Driver:: esgiguard {3f538614-b636-4023-9ec2-564ada4b07b3}w64 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64 RegLock:: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] ClearJavaCache:: Reboot::
- Ulozte vytvoreny TXT jako CFScript.txt tez primo na c:\
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte


Re: Zavirovaný notebook
Ještě chtěl nahrávat nějaké vzorky na server, což se mu ale nepodařilo.
----------------
ComboFix 14-06-30.01 - Uživatel 01.07.2014 21:00:56.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3912.2469 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\awh1312.tmp"
"C:\awh1515.tmp"
"C:\awh2F78.tmp"
"C:\awh3BF6.tmp"
"C:\awh3DDA.tmp"
"C:\awh3E95.tmp"
"C:\awh46BF.tmp"
"C:\awh55AD.tmp"
"C:\awhADEA.tmp"
"C:\awhAFB2.tmp"
"C:\awhB441.tmp"
"c:\windows\system32\drivers\stflt.sys"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AVG 2013+licence key
c:\program files (x86)\AVG 2013+licence key\AVG 2013+licence key.rar
c:\program files (x86)\AVG 2013+licence key\unins000.dat
c:\program files (x86)\AVG 2013+licence key\unins000.exe
c:\program files (x86)\Spybot - Search & Destroy 2
c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe.log
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-install-bdcore-update.exe
c:\program files (x86)\Spyware Terminator
c:\program files\Enigma Software Group
c:\program files\Enigma Software Group\SpyHunter\cos.dat
c:\program files\Enigma Software Group\SpyHunter\gas.dat
c:\program files\Enigma Software Group\SpyHunter\gil.dat
c:\program files\Enigma Software Group\SpyHunter\INSTALL.LOG
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_110537.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_124048.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_172119.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_174635.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_174915.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_195639.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_230132.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_230444.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_233504.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_235932.log
c:\program files\Enigma Software Group\SpyHunter\safeol.dat
c:\program files\Enigma Software Group\SpyHunter\scanlog.log
c:\program files\Enigma Software Group\SpyHunter\supportlog.txt
c:\program files\Enigma Software Group\SpyHunter\unkcache.dat
c:\programdata\McAfee
c:\programdata\MySearch
c:\programdata\MySearch\QhpcGpue.dat
c:\programdata\MySearch\QhpcGpue.exe
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\140625-131626.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140625-135641.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140625-151918.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\140625-131626.xml.cleaning.log
c:\programdata\Spybot - Search & Destroy\Logs\140625-135641.xml.cleaning.log
c:\programdata\Spybot - Search & Destroy\Logs\140625-151918.xml.cleaning.log
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140625-1353.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140625-1429.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140625-1701.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ESGIGUARD
-------\Legacy_{3F538614-B636-4023-9EC2-564ADA4B07B3}W64
-------\Legacy_{B2DB3058-74EE-4ACE-BCD8-8CD0FBE3A4F6}GW64
-------\Legacy_{B2DB3058-74EE-4ACE-BCD8-8CD0FBE3A4F6}W64
-------\Service_{3f538614-b636-4023-9ec2-564ada4b07b3}w64
-------\Service_{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64
-------\Service_{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64
-------\Service_esgiguard
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-01 do 2014-07-01 )))))))))))))))))))))))))))))))
.
.
2014-07-01 19:06 . 2014-07-01 19:06 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-07-01 19:06 . 2014-07-01 19:06 -------- d-----w- c:\users\Ivuška\AppData\Local\temp
2014-07-01 19:06 . 2014-07-01 19:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-01 15:51 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FDF8CEE8-21DA-4FC1-A3C3-A032C86CD2B1}\mpengine.dll
2014-06-30 22:05 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-30 22:04 . 2014-06-30 22:06 -------- d-----w- C:\AdwCleaner
2014-06-30 21:40 . 2014-06-30 21:40 687 ----a-w- C:\awh55AD.tmp
2014-06-30 21:09 . 2014-06-30 21:09 687 ----a-w- C:\awh1312.tmp
2014-06-30 18:19 . 2014-06-30 18:19 687 ----a-w- C:\awh3E95.tmp
2014-06-30 17:58 . 2014-06-30 17:58 687 ----a-w- C:\awh3DDA.tmp
2014-06-30 17:39 . 2014-06-30 17:39 -------- d-----w- c:\program files\CCleaner
2014-06-30 17:32 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-06-30 17:32 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-06-30 17:32 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-06-30 17:32 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-06-30 17:28 . 2014-05-30 09:11 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-06-25 16:53 . 2014-06-20 13:28 61112 ----a-w- c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-25 16:13 . 2014-01-19 17:57 1419 ------w- c:\windows\SysWow64\msstp.vbe
2014-06-25 16:06 . 2014-06-25 16:06 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2014-06-25 15:05 . 2014-06-25 15:05 -------- d-----w- c:\users\Uživatel\AppData\Local\6651
2014-06-25 11:01 . 2014-06-25 11:01 687 ----a-w- C:\awh3BF6.tmp
2014-06-25 10:52 . 2014-06-25 10:52 687 ----a-w- C:\awhADEA.tmp
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\programdata\Trusted Publisher
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\users\Uživatel\AppData\Local\Adobe
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-----w- c:\windows\system32\appmgmt
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieUserList
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 10:31 . 2014-06-25 10:31 -------- d-----w- c:\users\Uživatel\AppData\Local\Packages
2014-06-25 10:30 . 2014-06-30 17:43 -------- d-----w- c:\programdata\6b4f3e85ab1ac942
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Uživatel\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Ivuška\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Google
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\HomeGroupUser$
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Guest
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Administrator
2014-06-25 09:04 . 2014-06-30 22:02 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-25 09:04 . 2014-06-25 09:04 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-06-25 08:58 . 2014-06-30 21:33 -------- d-----w- C:\FRST
2014-06-25 08:41 . 2014-06-25 08:41 687 ----a-w- C:\awh46BF.tmp
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\SysWow64\Wat
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\system32\Wat
2014-06-25 08:28 . 2014-06-25 08:28 687 ----a-w- C:\awhB441.tmp
2014-06-25 07:59 . 2014-06-25 08:01 -------- d-----w- c:\windows\system32\MRT
2014-06-25 07:36 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-06-25 07:24 . 2014-06-25 07:24 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 859648 ----a-w- c:\windows\system32\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-06-25 07:24 . 2014-06-25 07:24 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-06-25 07:23 . 2014-06-25 07:23 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-06-25 07:23 . 2014-06-25 07:23 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-06-25 07:14 . 2014-06-25 07:14 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-06-25 07:14 . 2014-06-25 07:14 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-06-25 06:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-06-25 05:57 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-06-25 05:57 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-06-25 05:57 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-06-25 05:51 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-06-25 05:50 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-06-25 05:50 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-06-25 05:50 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-06-25 05:50 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:50 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:48 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2014-06-25 05:47 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-06-25 05:46 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2014-06-25 05:45 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2014-06-25 05:36 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-06-25 05:36 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-06-25 05:33 . 2014-06-25 05:33 687 ----a-w- C:\awh1515.tmp
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Oracle
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\windows\Sun
2014-06-25 05:13 . 2014-06-25 05:13 -------- d-----w- c:\programdata\Oracle
2014-06-25 05:12 . 2014-06-25 05:12 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-06-25 05:12 . 2014-05-07 13:02 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-06-25 05:10 . 2014-06-25 05:10 687 ----a-w- C:\awh2F78.tmp
2014-06-24 19:55 . 2014-05-02 20:27 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BAB4D77-653B-4B9E-A986-D47B75579054}\gapaengine.dll
2014-06-24 19:54 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-06-20 19:29 . 2014-06-20 19:29 284264 ----a-w- c:\windows\Firefox Setup Stub 30.0.exe
2014-06-19 16:37 . 2014-06-19 16:37 687 ----a-w- C:\awhAFB2.tmp
2014-06-19 16:32 . 2014-06-19 16:32 -------- d-----w- c:\program files (x86)\Common Files\Config
2014-06-18 02:43 . 2014-06-17 12:49 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 11:57 . 2014-06-17 11:57 108544 ----a-w- c:\windows\SysWow64\hfnapi.dll
2014-06-03 19:19 . 2014-06-03 19:19 -------- d-----w- c:\users\Uživatel\AppData\Local\Macromedia
2014-06-03 19:15 . 2014-06-03 19:15 -------- d-----w- c:\users\Uživatel\AppData\Local\Mozilla
2014-06-01 20:02 . 2014-06-25 05:09 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-01 20:02 . 2014-06-25 05:09 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\SysWow64\Macromed
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\system32\Macromed
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-27 13:05 . 2014-05-31 05:57 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys
2014-05-02 20:27 . 2013-08-23 06:05 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1}]
c:\program files (x86)\Adblocker\8TjqFlez.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2012-03-23 1105488]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys;c:\windows\SYSNATIVE\DRIVERS\bcmvwl64.sys [x]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 SmbDrv;SmbDrv;c:\windows\system32\DRIVERS\Smb_driver.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-27 12343400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-02-20 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-02-20 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-02-20 440600]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2013-08-16 7138816]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"SpywareTerminatorShield"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe" [BU]
"SpywareTerminatorUpdater"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{A8F39FF4-17BA-839D-1B2E-578BB64D4A1B}_is1 - c:\program files (x86)\AVG 2013+licence key\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Launch Manager\LMutilps32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2014-07-01 21:11:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-07-01 19:11
ComboFix2.txt 2014-07-01 15:45
.
Před spuštěním: Volných bajtů: 78 509 051 904
Po spuštění: Volných bajtů: 78 432 894 976
.
- - End Of File - - C199EE70EC325186E683E958FA6AF218
----------------
ComboFix 14-06-30.01 - Uživatel 01.07.2014 21:00:56.2.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3912.2469 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"C:\awh1312.tmp"
"C:\awh1515.tmp"
"C:\awh2F78.tmp"
"C:\awh3BF6.tmp"
"C:\awh3DDA.tmp"
"C:\awh3E95.tmp"
"C:\awh46BF.tmp"
"C:\awh55AD.tmp"
"C:\awhADEA.tmp"
"C:\awhAFB2.tmp"
"C:\awhB441.tmp"
"c:\windows\system32\drivers\stflt.sys"
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\AVG 2013+licence key
c:\program files (x86)\AVG 2013+licence key\AVG 2013+licence key.rar
c:\program files (x86)\AVG 2013+licence key\unins000.dat
c:\program files (x86)\AVG 2013+licence key\unins000.exe
c:\program files (x86)\Spybot - Search & Destroy 2
c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe.log
c:\program files (x86)\Spybot - Search & Destroy 2\spybotsd2-install-bdcore-update.exe
c:\program files (x86)\Spyware Terminator
c:\program files\Enigma Software Group
c:\program files\Enigma Software Group\SpyHunter\cos.dat
c:\program files\Enigma Software Group\SpyHunter\gas.dat
c:\program files\Enigma Software Group\SpyHunter\gil.dat
c:\program files\Enigma Software Group\SpyHunter\INSTALL.LOG
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_110537.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_124048.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_172119.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_174635.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140625_174915.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_195639.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_230132.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_230444.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_233504.log
c:\program files\Enigma Software Group\SpyHunter\Log\SpyHunter4_20140630_235932.log
c:\program files\Enigma Software Group\SpyHunter\safeol.dat
c:\program files\Enigma Software Group\SpyHunter\scanlog.log
c:\program files\Enigma Software Group\SpyHunter\supportlog.txt
c:\program files\Enigma Software Group\SpyHunter\unkcache.dat
c:\programdata\McAfee
c:\programdata\MySearch
c:\programdata\MySearch\QhpcGpue.dat
c:\programdata\MySearch\QhpcGpue.exe
c:\programdata\Spybot - Search & Destroy
c:\programdata\Spybot - Search & Destroy\Cleaning\140625-131626.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140625-135641.xml
c:\programdata\Spybot - Search & Destroy\Cleaning\140625-151918.xml
c:\programdata\Spybot - Search & Destroy\ClientCount.bin
c:\programdata\Spybot - Search & Destroy\Immunization.ini
c:\programdata\Spybot - Search & Destroy\Logs\140625-131626.xml.cleaning.log
c:\programdata\Spybot - Search & Destroy\Logs\140625-135641.xml.cleaning.log
c:\programdata\Spybot - Search & Destroy\Logs\140625-151918.xml.cleaning.log
c:\programdata\Spybot - Search & Destroy\Logs\Firewall.log
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140625-1353.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140625-1429.txt
c:\programdata\Spybot - Search & Destroy\Logs\Checks.140625-1701.txt
c:\programdata\Spybot - Search & Destroy\Logs\Immunization-Browsers.log
c:\programdata\Spybot - Search & Destroy\Logs\Scanner.log
c:\programdata\Spybot - Search & Destroy\Logs\Updates.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ESGIGUARD
-------\Legacy_{3F538614-B636-4023-9EC2-564ADA4B07B3}W64
-------\Legacy_{B2DB3058-74EE-4ACE-BCD8-8CD0FBE3A4F6}GW64
-------\Legacy_{B2DB3058-74EE-4ACE-BCD8-8CD0FBE3A4F6}W64
-------\Service_{3f538614-b636-4023-9ec2-564ada4b07b3}w64
-------\Service_{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64
-------\Service_{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64
-------\Service_esgiguard
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-01 do 2014-07-01 )))))))))))))))))))))))))))))))
.
.
2014-07-01 19:06 . 2014-07-01 19:06 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2014-07-01 19:06 . 2014-07-01 19:06 -------- d-----w- c:\users\Ivuška\AppData\Local\temp
2014-07-01 19:06 . 2014-07-01 19:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-07-01 15:51 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FDF8CEE8-21DA-4FC1-A3C3-A032C86CD2B1}\mpengine.dll
2014-06-30 22:05 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-06-30 22:04 . 2014-06-30 22:06 -------- d-----w- C:\AdwCleaner
2014-06-30 21:40 . 2014-06-30 21:40 687 ----a-w- C:\awh55AD.tmp
2014-06-30 21:09 . 2014-06-30 21:09 687 ----a-w- C:\awh1312.tmp
2014-06-30 18:19 . 2014-06-30 18:19 687 ----a-w- C:\awh3E95.tmp
2014-06-30 17:58 . 2014-06-30 17:58 687 ----a-w- C:\awh3DDA.tmp
2014-06-30 17:39 . 2014-06-30 17:39 -------- d-----w- c:\program files\CCleaner
2014-06-30 17:32 . 2013-12-24 23:09 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-06-30 17:32 . 2013-12-24 22:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-06-30 17:32 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
2014-06-30 17:32 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll
2014-06-30 17:28 . 2014-05-30 09:11 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2014-06-25 16:53 . 2014-06-20 13:28 61112 ----a-w- c:\windows\system32\drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-25 16:13 . 2014-01-19 17:57 1419 ------w- c:\windows\SysWow64\msstp.vbe
2014-06-25 16:06 . 2014-06-25 16:06 51496 ----a-w- c:\windows\system32\drivers\stflt.sys
2014-06-25 15:05 . 2014-06-25 15:05 -------- d-----w- c:\users\Uživatel\AppData\Local\6651
2014-06-25 11:01 . 2014-06-25 11:01 687 ----a-w- C:\awh3BF6.tmp
2014-06-25 10:52 . 2014-06-25 10:52 687 ----a-w- C:\awhADEA.tmp
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\programdata\Trusted Publisher
2014-06-25 10:50 . 2014-06-25 10:50 -------- d-----w- c:\users\Uživatel\AppData\Local\Adobe
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-----w- c:\windows\system32\appmgmt
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieUserList
2014-06-25 10:44 . 2014-06-25 10:44 -------- d-sh--w- c:\users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 10:31 . 2014-06-25 10:31 -------- d-----w- c:\users\Uživatel\AppData\Local\Packages
2014-06-25 10:30 . 2014-06-30 17:43 -------- d-----w- c:\programdata\6b4f3e85ab1ac942
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Uživatel\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Ivuška\AppData\Local\Comodo
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\Google
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\HomeGroupUser$
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Guest
2014-06-25 10:30 . 2014-06-25 10:30 -------- d-----w- c:\users\Administrator
2014-06-25 09:04 . 2014-06-30 22:02 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-25 09:04 . 2014-06-25 09:04 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-06-25 08:58 . 2014-06-30 21:33 -------- d-----w- C:\FRST
2014-06-25 08:41 . 2014-06-25 08:41 687 ----a-w- C:\awh46BF.tmp
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\SysWow64\Wat
2014-06-25 08:30 . 2014-06-25 08:30 -------- d-----w- c:\windows\system32\Wat
2014-06-25 08:28 . 2014-06-25 08:28 687 ----a-w- C:\awhB441.tmp
2014-06-25 07:59 . 2014-06-25 08:01 -------- d-----w- c:\windows\system32\MRT
2014-06-25 07:36 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2014-06-25 07:24 . 2014-06-25 07:24 878080 ----a-w- c:\windows\system32\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 859648 ----a-w- c:\windows\system32\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 640512 ----a-w- c:\windows\SysWow64\advapi32.dll
2014-06-25 07:24 . 2014-06-25 07:24 619520 ----a-w- c:\windows\SysWow64\tdh.dll
2014-06-25 07:24 . 2014-06-25 07:24 1732032 ----a-w- c:\windows\system32\ntdll.dll
2014-06-25 07:24 . 2014-06-25 07:24 1292192 ----a-w- c:\windows\SysWow64\ntdll.dll
2014-06-25 07:23 . 2014-06-25 07:23 327168 ----a-w- c:\windows\system32\mswsock.dll
2014-06-25 07:23 . 2014-06-25 07:23 231424 ----a-w- c:\windows\SysWow64\mswsock.dll
2014-06-25 07:14 . 2014-06-25 07:14 1887232 ----a-w- c:\windows\system32\d3d11.dll
2014-06-25 07:14 . 2014-06-25 07:14 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2014-06-25 06:38 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2014-06-25 05:57 . 2012-03-01 06:46 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2014-06-25 05:57 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-06-25 05:57 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-06-25 05:51 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll
2014-06-25 05:50 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-06-25 05:50 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-06-25 05:50 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-06-25 05:50 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:50 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2014-06-25 05:48 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2014-06-25 05:47 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2014-06-25 05:46 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2014-06-25 05:45 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2014-06-25 05:36 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2014-06-25 05:36 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2014-06-25 05:33 . 2014-06-25 05:33 687 ----a-w- C:\awh1515.tmp
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Oracle
2014-06-25 05:17 . 2014-06-25 05:17 -------- d-----w- c:\windows\Sun
2014-06-25 05:13 . 2014-06-25 05:13 -------- d-----w- c:\programdata\Oracle
2014-06-25 05:12 . 2014-06-25 05:12 -------- d-----w- c:\program files (x86)\Common Files\Java
2014-06-25 05:12 . 2014-05-07 13:02 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-06-25 05:10 . 2014-06-25 05:10 687 ----a-w- C:\awh2F78.tmp
2014-06-24 19:55 . 2014-05-02 20:27 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BAB4D77-653B-4B9E-A986-D47B75579054}\gapaengine.dll
2014-06-24 19:54 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 19:30 . 2014-06-20 19:30 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2014-06-20 19:29 . 2014-06-20 19:29 284264 ----a-w- c:\windows\Firefox Setup Stub 30.0.exe
2014-06-19 16:37 . 2014-06-19 16:37 687 ----a-w- C:\awhAFB2.tmp
2014-06-19 16:32 . 2014-06-19 16:32 -------- d-----w- c:\program files (x86)\Common Files\Config
2014-06-18 02:43 . 2014-06-17 12:49 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 11:57 . 2014-06-17 11:57 108544 ----a-w- c:\windows\SysWow64\hfnapi.dll
2014-06-03 19:19 . 2014-06-03 19:19 -------- d-----w- c:\users\Uživatel\AppData\Local\Macromedia
2014-06-03 19:15 . 2014-06-03 19:15 -------- d-----w- c:\users\Uživatel\AppData\Local\Mozilla
2014-06-01 20:02 . 2014-06-25 05:09 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-01 20:02 . 2014-06-25 05:09 699056 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\SysWow64\Macromed
2014-06-01 20:02 . 2014-06-01 20:02 -------- d-----w- c:\windows\system32\Macromed
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-05-27 13:05 . 2014-05-31 05:57 61112 ----a-w- c:\windows\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}Gw64.sys
2014-05-02 20:27 . 2013-08-23 06:05 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1}]
c:\program files (x86)\Adblocker\8TjqFlez.dll [BU]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-02-29 56088]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2012-03-23 1105488]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x]
S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys;c:\windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x]
S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl64.sys;c:\windows\SYSNATIVE\DRIVERS\bcmvwl64.sys [x]
S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x]
S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys;c:\windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x]
S3 SmbDrv;SmbDrv;c:\windows\system32\DRIVERS\Smb_driver.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-12-27 12343400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-02-20 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-02-20 398616]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-02-20 440600]
"Broadcom Wireless Manager UI"="c:\program files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe" [2013-08-16 7138816]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"SpywareTerminatorShield"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe" [BU]
"SpywareTerminatorUpdater"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-{A8F39FF4-17BA-839D-1B2E-578BB64D4A1B}_is1 - c:\program files (x86)\AVG 2013+licence key\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Launch Manager\LMutilps32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Celkový čas: 2014-07-01 21:11:23 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-07-01 19:11
ComboFix2.txt 2014-07-01 15:45
.
Před spuštěním: Volných bajtů: 78 509 051 904
Po spuštění: Volných bajtů: 78 432 894 976
.
- - End Of File - - C199EE70EC325186E683E958FA6AF218
Re: Zavirovaný notebook
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by Uživatel (administrator) on UŽIVATEL-PC on 01-07-2014 21:32:23
Running from C:\Users\Uživatel\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2868496 2012-02-14] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [7138816 2013-08-16] (Broadcom Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-23] (Dritek System Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [247144 2012-10-12] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll => c:\Windows\SysWOW64\nvinit.dll [203112 2012-10-12] (NVIDIA Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {09B720EA-4969-44D2-B4B2-4D13880E6506} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {39C65F92-485E-435D-8E5D-EB2449F0E1E5} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {9E6DD42C-AF93-46A6-9377-20FC7D5A1935} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {A1AD9730-5AFF-47D7-B1A6-0FDA00368578} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {A3D5D9FF-BDE9-483C-AE0B-BB6BA1EB3067} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {B4978D87-22AA-4B2B-9B37-B6F811A466BA} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {CE59F1FD-74DD-4E58-8BCA-578B2053C927} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {EB7822C2-95FD-4D1B-82CD-1F4392E9B8CF} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {F9F5545F-5731-427D-B819-C26576D08199} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adblocker - {5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - C:\Program Files (x86)\Adblocker\8TjqFlez.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Adblocker - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com [2014-06-25]
FF Extension: MySearch - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com [2014-06-25]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56"
CHR NewTab: "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Extension: (Dokumenty Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-16]
CHR Extension: (Disk Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-16]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-16]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong [2014-06-25]
CHR Extension: (Vyhledávání Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-16]
CHR Extension: (Chrome Notepad) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffbhefmlcoihbjcmibbfkocmnaiacinp [2014-06-25]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc [2014-06-25]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn [2014-06-25]
CHR Extension: (MySearch) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\neioceapaiibomegejgcpmbcmkmmhmmf [2014-06-25]
CHR Extension: (Peněženka Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-05-31]
CHR Extension: (Gmail) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-16]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [5824512 2013-08-16] (Broadcom Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [22800 2012-02-14] (Synaptics Incorporated)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-01 21:32 - 2014-07-01 21:32 - 00014169 _____ () C:\Users\Uživatel\Desktop\FRST.txt
2014-07-01 21:11 - 2014-07-01 21:11 - 00021710 _____ () C:\ComboFix.txt
2014-07-01 21:00 - 2014-07-01 21:00 - 00001204 _____ () C:\CF-Submit.htm
2014-07-01 17:33 - 2014-07-01 21:12 - 00000000 ____D () C:\Qoobox
2014-07-01 17:33 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-01 17:33 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-01 17:33 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-01 17:32 - 2014-07-01 21:06 - 00000000 ____D () C:\Windows\erdnt
2014-07-01 17:30 - 2014-07-01 17:31 - 05212874 ____R (Swearware) C:\ComboFix.exe
2014-07-01 17:28 - 2014-07-01 17:29 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt
2014-07-01 17:26 - 2014-07-01 17:27 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com
2014-07-01 00:05 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-01 00:04 - 2014-07-01 00:06 - 00000000 ____D () C:\AdwCleaner
2014-07-01 00:04 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe
2014-06-30 23:59 - 2014-06-30 23:59 - 00285888 _____ () C:\Windows\Minidump\063014-23088-01.dmp
2014-06-30 23:56 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe
2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe
2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar
2014-06-30 23:42 - 2014-06-30 23:33 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt
2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp
2014-06-30 23:34 - 2014-06-30 23:59 - 482614978 _____ () C:\Windows\MEMORY.DMP
2014-06-30 23:34 - 2014-06-30 23:59 - 00000000 ____D () C:\Windows\Minidump
2014-06-30 23:34 - 2014-06-30 23:34 - 00285792 _____ () C:\Windows\Minidump\063014-21153-01.dmp
2014-06-30 23:29 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Desktop\FRST64.exe
2014-06-30 23:29 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe
2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe
2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp
2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp
2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp
2014-06-30 19:53 - 2014-07-01 21:07 - 00003196 _____ () C:\Windows\PFRO.log
2014-06-30 19:53 - 2014-07-01 21:07 - 00000448 _____ () C:\Windows\setupact.log
2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-30 19:42 - 2014-06-30 19:42 - 00043120 _____ () C:\Users\Uživatel\Documents\cc_20140630_194158.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00007954 _____ () C:\Users\Uživatel\Documents\cc_20140630_194224.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00000540 _____ () C:\Users\Uživatel\Documents\cc_20140630_194241.reg
2014-06-30 19:39 - 2014-06-30 19:39 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-30 19:39 - 2014-06-30 19:39 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-30 19:36 - 2014-06-30 19:38 - 04812672 _____ (Piriform Ltd) C:\Users\Uživatel\Downloads\ccsetup415.exe
2014-06-30 19:32 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-06-30 19:32 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-06-30 19:32 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-06-30 19:32 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-06-30 19:28 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-25 18:53 - 2014-06-20 15:28 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk
2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key
2014-06-25 18:13 - 2014-01-19 19:57 - 00001419 ____N () C:\Windows\SysWOW64\msstp.vbe
2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-06-25 18:12 - 2014-03-05 22:19 - 00007670 ____S () C:\Windows\SysWOW64\mncevdfbt.vbe
2014-06-25 18:12 - 2013-12-10 00:30 - 10236928 ____S () C:\Windows\SysWOW64\acumncevdfbt.exe
2014-06-25 18:12 - 2013-10-26 20:30 - 01704448 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00972814 ____S () C:\Windows\SysWOW64\dcgmncevdfbt.exe
2014-06-25 18:12 - 2013-10-26 20:30 - 00538126 ____S () C:\Windows\SysWOW64\libcurl-4.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00364544 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\ssleay32.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00192512 ____S () C:\Windows\SysWOW64\libidn-11.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00171008 ____S (The libssh2 library, http://www.libssh2.org/) C:\Windows\SysWOW64\libssh2.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00133632 ____S () C:\Windows\SysWOW64\librtmp.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00044727 ____S () C:\Windows\SysWOW64\diablo130302.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00043810 ____S () C:\Windows\SysWOW64\poclbm130302.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00030802 ____S () C:\Windows\SysWOW64\diakgcn121016.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00023825 ____S () C:\Windows\SysWOW64\scrypt130511.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00013062 ____S () C:\Windows\SysWOW64\phatk121016.cl
2014-06-25 18:12 - 2013-07-18 16:06 - 00187904 ____S () C:\Windows\SysWOW64\lcpmncevdfbt.exe
2014-06-25 18:12 - 2013-06-12 15:15 - 00119888 ____S (Open Source Software community LGPL) C:\Windows\SysWOW64\pthreadGC2.dll
2014-06-25 18:12 - 2013-06-12 15:15 - 00100864 ____S () C:\Windows\SysWOW64\zlib1.dll
2014-06-25 18:12 - 2012-09-25 23:46 - 00472424 ____S (NVIDIA Corporation) C:\Windows\SysWOW64\cudart32_50_35.dll
2014-06-25 18:12 - 2012-05-27 01:36 - 00055808 ____S (Open Source Software community LGPL) C:\Windows\SysWOW64\pthreadVC2.dll
2014-06-25 18:11 - 2014-06-25 18:12 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe
2014-06-25 17:37 - 2014-06-25 17:38 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651
2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe
2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-25 13:08 - 2014-06-25 13:09 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe
2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp
2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Adobe
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\ProgramData\Trusted Publisher
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieUserList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-06-25 12:31 - 2014-06-25 12:31 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Packages
2014-06-25 12:30 - 2014-06-30 19:43 - 00000000 ____D () C:\ProgramData\6b4f3e85ab1ac942
2014-06-25 12:30 - 2014-06-25 12:50 - 00000406 __RSH () C:\ProgramData\ntuser.pol
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Ivuška\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator
2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe
2014-06-25 11:05 - 2014-06-25 11:05 - 00000000 _____ () C:\autoexec.bat
2014-06-25 11:04 - 2014-07-01 00:02 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe
2014-06-25 11:00 - 2014-06-25 11:01 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt
2014-06-25 10:59 - 2014-06-25 11:01 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt
2014-06-25 10:58 - 2014-07-01 21:32 - 00000000 ____D () C:\FRST
2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe
2014-06-25 10:57 - 2014-06-25 10:57 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64.exe
2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp
2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp
2014-06-25 09:59 - 2014-06-25 10:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-25 09:58 - 2014-06-01 17:17 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-25 09:36 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-06-25 09:26 - 2014-06-25 09:26 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00266456 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00240856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-06-25 08:38 - 2010-02-23 10:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe
2014-06-25 07:57 - 2012-03-01 08:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-06-25 07:57 - 2012-03-01 08:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-06-25 07:57 - 2012-03-01 07:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-06-25 07:52 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-06-25 07:52 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-06-25 07:52 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-06-25 07:52 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-06-25 07:52 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-06-25 07:52 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-06-25 07:52 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-06-25 07:52 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-06-25 07:52 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-06-25 07:52 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-06-25 07:52 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-06-25 07:52 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-06-25 07:52 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-06-25 07:52 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-06-25 07:52 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-06-25 07:52 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-06-25 07:52 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-06-25 07:52 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-06-25 07:52 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-06-25 07:52 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-06-25 07:52 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-06-25 07:52 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-06-25 07:52 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-06-25 07:52 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-06-25 07:52 - 2013-09-25 04:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-06-25 07:52 - 2013-09-25 03:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-06-25 07:52 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-06-25 07:52 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-06-25 07:52 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-06-25 07:52 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-06-25 07:52 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-06-25 07:52 - 2013-07-04 14:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-06-25 07:52 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-06-25 07:52 - 2011-02-23 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-06-25 07:52 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-06-25 07:51 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-06-25 07:51 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-06-25 07:51 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-06-25 07:51 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-06-25 07:51 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-06-25 07:51 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-06-25 07:51 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-06-25 07:51 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-06-25 07:49 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-25 07:49 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-25 07:49 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-25 07:49 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-25 07:49 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-25 07:49 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-25 07:49 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-25 07:49 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-25 07:49 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-25 07:49 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-25 07:49 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-06-25 07:49 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-06-25 07:49 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-06-25 07:49 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-06-25 07:49 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-06-25 07:49 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-06-25 07:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-06-25 07:49 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-06-25 07:49 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-06-25 07:49 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-06-25 07:49 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-06-25 07:49 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-06-25 07:49 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-06-25 07:49 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-06-25 07:49 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-06-25 07:49 - 2012-11-29 00:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-06-25 07:49 - 2012-11-29 00:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-06-25 07:49 - 2012-11-29 00:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-06-25 07:49 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-06-25 07:49 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-06-25 07:49 - 2011-03-11 08:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-06-25 07:49 - 2011-03-11 08:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-06-25 07:49 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-06-25 07:49 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-06-25 07:49 - 2010-12-23 12:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-06-25 07:49 - 2010-12-23 12:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-06-25 07:49 - 2010-12-23 12:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-06-25 07:49 - 2010-12-23 07:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-06-25 07:49 - 2010-12-23 07:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-06-25 07:49 - 2010-12-23 07:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-06-25 07:48 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-06-25 07:48 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-06-25 07:48 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-06-25 07:48 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-06-25 07:48 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-06-25 07:48 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-06-25 07:48 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-06-25 07:48 - 2013-02-15 08:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-06-25 07:48 - 2013-02-15 08:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-06-25 07:48 - 2013-02-15 08:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-06-25 07:48 - 2013-02-15 06:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-06-25 07:48 - 2013-02-15 06:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-06-25 07:48 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-06-25 07:48 - 2011-11-17 08:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-06-25 07:48 - 2011-11-17 07:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-06-25 07:48 - 2011-10-15 08:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-06-25 07:48 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-06-25 07:47 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-06-25 07:47 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-06-25 07:47 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-06-25 07:47 - 2013-10-05 22:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-06-25 07:47 - 2013-10-05 21:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-06-25 07:47 - 2013-09-28 03:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-06-25 07:47 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-06-25 07:47 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-06-25 07:47 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-06-25 07:47 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-06-25 07:47 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-06-25 07:47 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-06-25 07:47 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-06-25 07:47 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-06-25 07:47 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-06-25 07:47 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-06-25 07:47 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-06-25 07:47 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-06-25 07:47 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-06-25 07:47 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-06-25 07:47 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-06-25 07:47 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-06-25 07:47 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-06-25 07:47 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-06-25 07:47 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-06-25 07:47 - 2012-07-05 00:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-06-25 07:47 - 2012-07-05 00:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-06-25 07:47 - 2012-07-05 00:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-06-25 07:47 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-06-25 07:47 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-06-25 07:47 - 2012-05-14 07:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-06-25 07:47 - 2012-04-28 05:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-06-25 07:47 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-06-25 07:47 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-06-25 07:47 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-06-25 07:47 - 2011-12-16 10:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-06-25 07:47 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-06-25 07:47 - 2011-10-26 07:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-06-25 07:47 - 2011-10-26 07:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-06-25 07:47 - 2011-10-26 06:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-06-25 07:47 - 2011-10-26 06:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-06-25 07:47 - 2011-08-27 07:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-06-25 07:47 - 2011-08-27 07:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-06-25 07:47 - 2011-08-27 06:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-06-25 07:47 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-06-25 07:47 - 2011-07-09 04:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-06-25 07:47 - 2011-06-15 12:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-06-25 07:47 - 2011-06-15 12:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-06-25 07:47 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-06-25 07:47 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-06-25 07:47 - 2011-05-24 13:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-06-25 07:47 - 2011-05-24 12:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-06-25 07:47 - 2011-05-24 12:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-06-25 07:47 - 2011-05-24 12:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-06-25 07:47 - 2011-05-24 12:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-06-25 07:47 - 2011-05-03 07:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-06-25 07:47 - 2011-05-03 06:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-06-25 07:47 - 2011-04-29 05:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-06-25 07:47 - 2011-04-29 05:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-25 07:47 - 2011-04-29 05:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-06-25 07:47 - 2011-04-27 04:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-06-25 07:47 - 2011-04-27 04:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-06-25 07:47 - 2011-02-05 19:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-06-25 07:47 - 2011-02-05 19:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-06-25 07:47 - 2011-02-05 19:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-06-25 07:46 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-25 07:46 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-25 07:46 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-06-25 07:46 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-06-25 07:46 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-06-25 07:46 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-06-25 07:46 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-06-25 07:46 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-06-25 07:46 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-06-25 07:46 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-06-25 07:46 - 2013-10-03 04:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-25 07:46 - 2013-10-03 04:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-25 07:46 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-06-25 07:46 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
Ran by Uživatel (administrator) on UŽIVATEL-PC on 01-07-2014 21:32:23
Running from C:\Users\Uživatel\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2868496 2012-02-14] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12343400 2011-12-27] (Realtek Semiconductor)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [7138816 2013-08-16] (Broadcom Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-23] (Dritek System Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [247144 2012-10-12] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll => c:\Windows\SysWOW64\nvinit.dll [203112 2012-10-12] (NVIDIA Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {09B720EA-4969-44D2-B4B2-4D13880E6506} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {39C65F92-485E-435D-8E5D-EB2449F0E1E5} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {9E6DD42C-AF93-46A6-9377-20FC7D5A1935} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {A1AD9730-5AFF-47D7-B1A6-0FDA00368578} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {A3D5D9FF-BDE9-483C-AE0B-BB6BA1EB3067} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {B4978D87-22AA-4B2B-9B37-B6F811A466BA} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {CE59F1FD-74DD-4E58-8BCA-578B2053C927} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {EB7822C2-95FD-4D1B-82CD-1F4392E9B8CF} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {F9F5545F-5731-427D-B819-C26576D08199} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adblocker - {5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - C:\Program Files (x86)\Adblocker\8TjqFlez.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: No Name - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Adblocker - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com [2014-06-25]
FF Extension: MySearch - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com [2014-06-25]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56"
CHR NewTab: "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Extension: (Dokumenty Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-16]
CHR Extension: (Disk Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-16]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2014-05-31]
CHR Extension: (YouTube) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-16]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\chekmmhnmiclcainllcehipibboalong [2014-06-25]
CHR Extension: (Vyhledávání Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-16]
CHR Extension: (Chrome Notepad) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffbhefmlcoihbjcmibbfkocmnaiacinp [2014-06-25]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc [2014-06-25]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn [2014-06-25]
CHR Extension: (MySearch) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\neioceapaiibomegejgcpmbcmkmmhmmf [2014-06-25]
CHR Extension: (Peněženka Google) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-05-31]
CHR Extension: (Gmail) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-16]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [5824512 2013-08-16] (Broadcom Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 SmbDrv; C:\Windows\System32\DRIVERS\Smb_driver.sys [22800 2012-02-14] (Synaptics Incorporated)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-01 21:32 - 2014-07-01 21:32 - 00014169 _____ () C:\Users\Uživatel\Desktop\FRST.txt
2014-07-01 21:11 - 2014-07-01 21:11 - 00021710 _____ () C:\ComboFix.txt
2014-07-01 21:00 - 2014-07-01 21:00 - 00001204 _____ () C:\CF-Submit.htm
2014-07-01 17:33 - 2014-07-01 21:12 - 00000000 ____D () C:\Qoobox
2014-07-01 17:33 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-01 17:33 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-01 17:33 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-01 17:33 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-01 17:32 - 2014-07-01 21:06 - 00000000 ____D () C:\Windows\erdnt
2014-07-01 17:30 - 2014-07-01 17:31 - 05212874 ____R (Swearware) C:\ComboFix.exe
2014-07-01 17:28 - 2014-07-01 17:29 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt
2014-07-01 17:26 - 2014-07-01 17:27 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com
2014-07-01 00:05 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-01 00:04 - 2014-07-01 00:06 - 00000000 ____D () C:\AdwCleaner
2014-07-01 00:04 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe
2014-06-30 23:59 - 2014-06-30 23:59 - 00285888 _____ () C:\Windows\Minidump\063014-23088-01.dmp
2014-06-30 23:56 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe
2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe
2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar
2014-06-30 23:42 - 2014-06-30 23:33 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt
2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp
2014-06-30 23:34 - 2014-06-30 23:59 - 482614978 _____ () C:\Windows\MEMORY.DMP
2014-06-30 23:34 - 2014-06-30 23:59 - 00000000 ____D () C:\Windows\Minidump
2014-06-30 23:34 - 2014-06-30 23:34 - 00285792 _____ () C:\Windows\Minidump\063014-21153-01.dmp
2014-06-30 23:29 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Desktop\FRST64.exe
2014-06-30 23:29 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe
2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe
2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp
2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp
2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp
2014-06-30 19:53 - 2014-07-01 21:07 - 00003196 _____ () C:\Windows\PFRO.log
2014-06-30 19:53 - 2014-07-01 21:07 - 00000448 _____ () C:\Windows\setupact.log
2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-30 19:42 - 2014-06-30 19:42 - 00043120 _____ () C:\Users\Uživatel\Documents\cc_20140630_194158.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00007954 _____ () C:\Users\Uživatel\Documents\cc_20140630_194224.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00000540 _____ () C:\Users\Uživatel\Documents\cc_20140630_194241.reg
2014-06-30 19:39 - 2014-06-30 19:39 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-30 19:39 - 2014-06-30 19:39 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-30 19:36 - 2014-06-30 19:38 - 04812672 _____ (Piriform Ltd) C:\Users\Uživatel\Downloads\ccsetup415.exe
2014-06-30 19:32 - 2013-12-25 01:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-06-30 19:32 - 2013-12-25 00:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-06-30 19:32 - 2013-11-26 10:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-06-30 19:32 - 2013-11-23 00:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-06-30 19:28 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-25 18:53 - 2014-06-20 15:28 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk
2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key
2014-06-25 18:13 - 2014-01-19 19:57 - 00001419 ____N () C:\Windows\SysWOW64\msstp.vbe
2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-06-25 18:12 - 2014-03-05 22:19 - 00007670 ____S () C:\Windows\SysWOW64\mncevdfbt.vbe
2014-06-25 18:12 - 2013-12-10 00:30 - 10236928 ____S () C:\Windows\SysWOW64\acumncevdfbt.exe
2014-06-25 18:12 - 2013-10-26 20:30 - 01704448 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00972814 ____S () C:\Windows\SysWOW64\dcgmncevdfbt.exe
2014-06-25 18:12 - 2013-10-26 20:30 - 00538126 ____S () C:\Windows\SysWOW64\libcurl-4.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00364544 ____S (The OpenSSL Project, http://www.openssl.org/) C:\Windows\SysWOW64\ssleay32.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00192512 ____S () C:\Windows\SysWOW64\libidn-11.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00171008 ____S (The libssh2 library, http://www.libssh2.org/) C:\Windows\SysWOW64\libssh2.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00133632 ____S () C:\Windows\SysWOW64\librtmp.dll
2014-06-25 18:12 - 2013-10-26 20:30 - 00044727 ____S () C:\Windows\SysWOW64\diablo130302.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00043810 ____S () C:\Windows\SysWOW64\poclbm130302.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00030802 ____S () C:\Windows\SysWOW64\diakgcn121016.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00023825 ____S () C:\Windows\SysWOW64\scrypt130511.cl
2014-06-25 18:12 - 2013-10-26 20:30 - 00013062 ____S () C:\Windows\SysWOW64\phatk121016.cl
2014-06-25 18:12 - 2013-07-18 16:06 - 00187904 ____S () C:\Windows\SysWOW64\lcpmncevdfbt.exe
2014-06-25 18:12 - 2013-06-12 15:15 - 00119888 ____S (Open Source Software community LGPL) C:\Windows\SysWOW64\pthreadGC2.dll
2014-06-25 18:12 - 2013-06-12 15:15 - 00100864 ____S () C:\Windows\SysWOW64\zlib1.dll
2014-06-25 18:12 - 2012-09-25 23:46 - 00472424 ____S (NVIDIA Corporation) C:\Windows\SysWOW64\cudart32_50_35.dll
2014-06-25 18:12 - 2012-05-27 01:36 - 00055808 ____S (Open Source Software community LGPL) C:\Windows\SysWOW64\pthreadVC2.dll
2014-06-25 18:11 - 2014-06-25 18:12 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe
2014-06-25 17:37 - 2014-06-25 17:38 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651
2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe
2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-25 13:08 - 2014-06-25 13:09 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe
2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp
2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Adobe
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\ProgramData\Trusted Publisher
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieUserList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-06-25 12:31 - 2014-06-25 12:31 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Packages
2014-06-25 12:30 - 2014-06-30 19:43 - 00000000 ____D () C:\ProgramData\6b4f3e85ab1ac942
2014-06-25 12:30 - 2014-06-25 12:50 - 00000406 __RSH () C:\ProgramData\ntuser.pol
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Ivuška\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator
2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe
2014-06-25 11:05 - 2014-06-25 11:05 - 00000000 _____ () C:\autoexec.bat
2014-06-25 11:04 - 2014-07-01 00:02 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe
2014-06-25 11:00 - 2014-06-25 11:01 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt
2014-06-25 10:59 - 2014-06-25 11:01 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt
2014-06-25 10:58 - 2014-07-01 21:32 - 00000000 ____D () C:\FRST
2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe
2014-06-25 10:57 - 2014-06-25 10:57 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64.exe
2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp
2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp
2014-06-25 09:59 - 2014-06-25 10:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-25 09:58 - 2014-06-01 17:17 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-25 09:36 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-06-25 09:26 - 2014-06-25 09:26 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00266456 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00240856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-06-25 08:38 - 2010-02-23 10:16 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\browserchoice.exe
2014-06-25 07:57 - 2012-03-01 08:46 - 00023408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-06-25 07:57 - 2012-03-01 08:28 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-06-25 07:57 - 2012-03-01 07:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmi.dll
2014-06-25 07:52 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-06-25 07:52 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-06-25 07:52 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-06-25 07:52 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-06-25 07:52 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-06-25 07:52 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-06-25 07:52 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-06-25 07:52 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-06-25 07:52 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-06-25 07:52 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-06-25 07:52 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-06-25 07:52 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-06-25 07:52 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-06-25 07:52 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-06-25 07:52 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-06-25 07:52 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-06-25 07:52 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-06-25 07:52 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-06-25 07:52 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-06-25 07:52 - 2013-10-12 04:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-06-25 07:52 - 2013-10-12 04:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-06-25 07:52 - 2013-10-12 04:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2014-06-25 07:52 - 2013-10-12 04:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2014-06-25 07:52 - 2013-10-12 03:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-06-25 07:52 - 2013-10-12 03:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-06-25 07:52 - 2013-10-12 03:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2014-06-25 07:52 - 2013-10-12 03:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2014-06-25 07:52 - 2013-09-25 04:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-06-25 07:52 - 2013-09-25 03:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-06-25 07:52 - 2013-08-02 04:12 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-06-25 07:52 - 2013-08-02 04:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2014-06-25 07:52 - 2013-08-02 03:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2014-06-25 07:52 - 2013-08-02 02:59 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-06-25 07:52 - 2013-08-01 14:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-06-25 07:52 - 2013-07-04 14:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-06-25 07:52 - 2013-04-10 08:01 - 00265064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-06-25 07:52 - 2011-02-23 06:55 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-06-25 07:52 - 2011-02-03 13:25 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-06-25 07:51 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-06-25 07:51 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-06-25 07:51 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-06-25 07:51 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-06-25 07:51 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-06-25 07:51 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-06-25 07:51 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-06-25 07:51 - 2013-08-02 04:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 04:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 03:09 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-06-25 07:51 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-06-25 07:51 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2014-06-25 07:49 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-25 07:49 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-25 07:49 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-25 07:49 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-25 07:49 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-25 07:49 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-25 07:49 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-25 07:49 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-25 07:49 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-25 07:49 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-25 07:49 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-06-25 07:49 - 2013-11-26 13:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-06-25 07:49 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-06-25 07:49 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2014-06-25 07:49 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-06-25 07:49 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-06-25 07:49 - 2013-06-26 00:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-06-25 07:49 - 2013-05-13 07:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-06-25 07:49 - 2013-05-13 05:43 - 01192448 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-06-25 07:49 - 2013-05-13 05:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2014-06-25 07:49 - 2013-05-13 05:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2014-06-25 07:49 - 2013-02-27 08:02 - 00111448 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-06-25 07:49 - 2013-02-27 07:48 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-06-25 07:49 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-06-25 07:49 - 2013-02-27 06:49 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-06-25 07:49 - 2012-11-29 00:56 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-06-25 07:49 - 2012-11-29 00:56 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-06-25 07:49 - 2012-11-29 00:56 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-06-25 07:49 - 2011-04-09 08:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-06-25 07:49 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2014-06-25 07:49 - 2011-03-11 08:34 - 01395712 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-06-25 07:49 - 2011-03-11 08:34 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-06-25 07:49 - 2011-03-11 07:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2014-06-25 07:49 - 2011-03-11 07:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2014-06-25 07:49 - 2010-12-23 12:42 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-06-25 07:49 - 2010-12-23 12:42 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-06-25 07:49 - 2010-12-23 12:36 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-06-25 07:49 - 2010-12-23 07:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2014-06-25 07:49 - 2010-12-23 07:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2014-06-25 07:49 - 2010-12-23 07:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mpg2splt.ax
2014-06-25 07:48 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-06-25 07:48 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-06-25 07:48 - 2013-07-26 04:24 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-06-25 07:48 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2014-06-25 07:48 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-06-25 07:48 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-06-25 07:48 - 2013-04-12 16:45 - 01656680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-06-25 07:48 - 2013-02-15 08:08 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-06-25 07:48 - 2013-02-15 08:06 - 03717632 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-06-25 07:48 - 2013-02-15 08:02 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2014-06-25 07:48 - 2013-02-15 06:37 - 03217408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-06-25 07:48 - 2013-02-15 06:34 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-06-25 07:48 - 2013-02-15 05:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2014-06-25 07:48 - 2011-11-17 08:35 - 00395776 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-06-25 07:48 - 2011-11-17 07:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2014-06-25 07:48 - 2011-10-15 08:31 - 00723456 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-06-25 07:48 - 2011-10-15 07:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2014-06-25 07:47 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-06-25 07:47 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-06-25 07:47 - 2013-11-27 03:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-06-25 07:47 - 2013-11-27 03:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-06-25 07:47 - 2013-10-05 22:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-06-25 07:47 - 2013-10-05 21:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-06-25 07:47 - 2013-09-28 03:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-06-25 07:47 - 2013-07-12 12:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-06-25 07:47 - 2013-07-12 12:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-06-25 07:47 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-06-25 07:47 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-06-25 07:47 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-06-25 07:47 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2014-06-25 07:47 - 2013-07-03 06:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-06-25 07:47 - 2013-07-03 06:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-06-25 07:47 - 2013-06-06 07:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-06-25 07:47 - 2013-06-06 07:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-06-25 07:47 - 2013-06-06 07:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-06-25 07:47 - 2013-06-06 07:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-06-25 07:47 - 2013-06-06 06:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2014-06-25 07:47 - 2013-06-06 06:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2014-06-25 07:47 - 2013-06-06 06:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2014-06-25 07:47 - 2013-06-06 05:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-06-25 07:47 - 2013-06-06 05:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2014-06-25 07:47 - 2013-06-06 05:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2014-06-25 07:47 - 2013-02-12 06:12 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-06-25 07:47 - 2012-07-05 00:16 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-06-25 07:47 - 2012-07-05 00:13 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-06-25 07:47 - 2012-07-05 00:13 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-06-25 07:47 - 2012-07-04 23:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2014-06-25 07:47 - 2012-07-04 23:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2014-06-25 07:47 - 2012-05-14 07:26 - 00956928 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-06-25 07:47 - 2012-04-28 05:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-06-25 07:47 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-06-25 07:47 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2014-06-25 07:47 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-06-25 07:47 - 2011-12-16 10:46 - 00634880 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-06-25 07:47 - 2011-12-16 09:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcrt.dll
2014-06-25 07:47 - 2011-10-26 07:25 - 01572864 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-06-25 07:47 - 2011-10-26 07:25 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-06-25 07:47 - 2011-10-26 06:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-06-25 07:47 - 2011-10-26 06:32 - 00514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-06-25 07:47 - 2011-08-27 07:37 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-06-25 07:47 - 2011-08-27 07:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-06-25 07:47 - 2011-08-27 06:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-06-25 07:47 - 2011-08-27 06:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2014-06-25 07:47 - 2011-07-09 04:46 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-06-25 07:47 - 2011-06-15 12:02 - 00212992 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-06-25 07:47 - 2011-06-15 12:02 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-06-25 07:47 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-06-25 07:47 - 2011-06-15 12:02 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcjt32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbctrac.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccp32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccu32.dll
2014-06-25 07:47 - 2011-06-15 10:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbccr32.dll
2014-06-25 07:47 - 2011-05-24 13:42 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-06-25 07:47 - 2011-05-24 12:40 - 00064512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devobj.dll
2014-06-25 07:47 - 2011-05-24 12:40 - 00044544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devrtl.dll
2014-06-25 07:47 - 2011-05-24 12:39 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cfgmgr32.dll
2014-06-25 07:47 - 2011-05-24 12:37 - 00252928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drvinst.exe
2014-06-25 07:47 - 2011-05-03 07:29 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-06-25 07:47 - 2011-05-03 06:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2014-06-25 07:47 - 2011-04-29 05:06 - 00467456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-06-25 07:47 - 2011-04-29 05:05 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-25 07:47 - 2011-04-29 05:05 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-06-25 07:47 - 2011-04-27 04:40 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-06-25 07:47 - 2011-04-27 04:39 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-06-25 07:47 - 2011-02-05 19:06 - 00605552 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-06-25 07:47 - 2011-02-05 19:06 - 00566208 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-06-25 07:47 - 2011-02-05 19:06 - 00518672 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-06-25 07:46 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-25 07:46 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-25 07:46 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-06-25 07:46 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-06-25 07:46 - 2013-11-12 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-06-25 07:46 - 2013-11-12 04:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-06-25 07:46 - 2013-10-19 04:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-06-25 07:46 - 2013-10-19 03:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2014-06-25 07:46 - 2013-10-04 04:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-06-25 07:46 - 2013-10-04 03:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-06-25 07:46 - 2013-10-03 04:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-25 07:46 - 2013-10-03 04:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-25 07:46 - 2013-07-20 12:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-06-25 07:46 - 2013-07-20 12:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
Re: Zavirovaný notebook
2014-06-25 07:46 - 2013-07-04 14:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-06-25 07:46 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-06-25 07:46 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-06-25 07:46 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-06-25 07:46 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-06-25 07:46 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-06-25 07:46 - 2012-11-02 07:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-06-25 07:46 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-06-25 07:46 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-06-25 07:46 - 2012-09-26 00:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-06-25 07:46 - 2012-04-26 07:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-06-25 07:46 - 2012-04-26 07:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-06-25 07:46 - 2012-04-26 07:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-06-25 07:46 - 2012-03-17 09:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-06-25 07:46 - 2011-08-17 07:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-06-25 07:46 - 2011-08-17 07:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-06-25 07:46 - 2011-08-17 06:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-06-25 07:46 - 2011-08-17 06:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-06-25 07:46 - 2011-03-03 08:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-06-25 07:46 - 2011-03-03 08:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-06-25 07:46 - 2011-03-03 08:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-06-25 07:46 - 2011-03-03 07:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-06-25 07:46 - 2011-03-03 07:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-06-25 07:46 - 2011-02-12 13:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-06-25 07:46 - 2011-02-05 19:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-06-25 07:46 - 2011-02-05 19:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-06-25 07:46 - 2011-02-05 19:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-06-25 07:46 - 2011-02-05 19:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-06-25 07:45 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-06-25 07:45 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-06-25 07:45 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-06-25 07:45 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-06-25 07:45 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-06-25 07:45 - 2012-06-06 08:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-06-25 07:45 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-06-25 07:36 - 2011-11-19 16:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-06-25 07:36 - 2011-11-19 16:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Windows\Sun
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Oracle
2014-06-25 07:13 - 2014-06-25 07:13 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-25 07:12 - 2014-06-25 07:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-25 07:12 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-06-25 07:12 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-06-25 07:12 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-06-25 07:12 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-06-25 07:11 - 2014-06-25 07:12 - 00006026 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp
2014-06-20 21:30 - 2014-06-20 21:30 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-20 21:29 - 2014-06-20 21:29 - 00284264 _____ (Mozilla) C:\Windows\Firefox Setup Stub 30.0.exe
2014-06-20 21:16 - 2014-07-01 21:24 - 00003994 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7A457C8B-B88C-41C6-B3B9-33DA69AED102}
2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp
2014-06-18 04:43 - 2014-06-17 14:49 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 13:57 - 2014-06-17 13:57 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-06-03 21:19 - 2014-06-03 21:19 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Macromedia
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Mozilla
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\ProgramData\Mozilla
2014-06-01 22:02 - 2014-06-25 07:09 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-01 22:02 - 2014-06-25 07:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\system32\Macromed
==================== One Month Modified Files and Folders =======
2014-07-01 21:32 - 2014-07-01 21:32 - 00014169 _____ () C:\Users\Uživatel\Desktop\FRST.txt
2014-07-01 21:32 - 2014-06-25 10:58 - 00000000 ____D () C:\FRST
2014-07-01 21:24 - 2014-06-20 21:16 - 00003994 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7A457C8B-B88C-41C6-B3B9-33DA69AED102}
2014-07-01 21:15 - 2009-07-14 06:45 - 00021280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-01 21:15 - 2009-07-14 06:45 - 00021280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-01 21:12 - 2014-07-01 17:33 - 00000000 ____D () C:\Qoobox
2014-07-01 21:11 - 2014-07-01 21:11 - 00021710 _____ () C:\ComboFix.txt
2014-07-01 21:11 - 2013-08-16 19:11 - 01453189 _____ () C:\Windows\WindowsUpdate.log
2014-07-01 21:11 - 2011-04-12 10:34 - 00666656 _____ () C:\Windows\system32\perfh005.dat
2014-07-01 21:11 - 2011-04-12 10:34 - 00140320 _____ () C:\Windows\system32\perfc005.dat
2014-07-01 21:11 - 2009-07-14 07:13 - 01577410 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-01 21:07 - 2014-06-30 19:53 - 00003196 _____ () C:\Windows\PFRO.log
2014-07-01 21:07 - 2014-06-30 19:53 - 00000448 _____ () C:\Windows\setupact.log
2014-07-01 21:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-01 21:07 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-01 21:06 - 2014-07-01 17:32 - 00000000 ____D () C:\Windows\erdnt
2014-07-01 21:06 - 2009-07-14 04:34 - 68976640 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 17825792 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 00327680 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 00143360 _____ () C:\Windows\system32\config\SAM.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-01 21:00 - 2014-07-01 21:00 - 00001204 _____ () C:\CF-Submit.htm
2014-07-01 17:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-01 17:31 - 2014-07-01 17:30 - 05212874 ____R (Swearware) C:\ComboFix.exe
2014-07-01 17:29 - 2014-07-01 17:28 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt
2014-07-01 17:27 - 2014-07-01 17:26 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com
2014-07-01 00:06 - 2014-07-01 00:04 - 00000000 ____D () C:\AdwCleaner
2014-07-01 00:03 - 2014-07-01 00:04 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe
2014-07-01 00:02 - 2014-06-25 11:04 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-30 23:59 - 2014-06-30 23:59 - 00285888 _____ () C:\Windows\Minidump\063014-23088-01.dmp
2014-06-30 23:59 - 2014-06-30 23:34 - 482614978 _____ () C:\Windows\MEMORY.DMP
2014-06-30 23:59 - 2014-06-30 23:34 - 00000000 ____D () C:\Windows\Minidump
2014-06-30 23:54 - 2014-06-30 23:56 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe
2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe
2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar
2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp
2014-06-30 23:34 - 2014-06-30 23:34 - 00285792 _____ () C:\Windows\Minidump\063014-21153-01.dmp
2014-06-30 23:33 - 2014-06-30 23:42 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt
2014-06-30 23:28 - 2014-06-30 23:29 - 02083328 _____ (Farbar) C:\Users\Uživatel\Desktop\FRST64.exe
2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe
2014-06-30 23:27 - 2014-06-30 23:29 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe
2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp
2014-06-30 20:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp
2014-06-30 20:01 - 2014-05-30 23:24 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Seznam.cz
2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp
2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-30 19:47 - 2013-08-16 13:35 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-30 19:45 - 2013-08-16 13:35 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-06-30 19:43 - 2014-06-25 12:30 - 00000000 ____D () C:\ProgramData\6b4f3e85ab1ac942
2014-06-30 19:42 - 2014-06-30 19:42 - 00043120 _____ () C:\Users\Uživatel\Documents\cc_20140630_194158.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00007954 _____ () C:\Users\Uživatel\Documents\cc_20140630_194224.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00000540 _____ () C:\Users\Uživatel\Documents\cc_20140630_194241.reg
2014-06-30 19:41 - 2013-08-16 20:07 - 00000000 ____D () C:\Windows\Panther
2014-06-30 19:41 - 2013-08-16 13:18 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-06-30 19:41 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini
2014-06-30 19:39 - 2014-06-30 19:39 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-30 19:39 - 2014-06-30 19:39 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-30 19:38 - 2014-06-30 19:36 - 04812672 _____ (Piriform Ltd) C:\Users\Uživatel\Downloads\ccsetup415.exe
2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk
2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key
2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-06-25 18:12 - 2014-06-25 18:11 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe
2014-06-25 17:38 - 2014-06-25 17:37 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651
2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe
2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-25 13:09 - 2014-06-25 13:08 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe
2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp
2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Adobe
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\ProgramData\Trusted Publisher
2014-06-25 12:50 - 2014-06-25 12:30 - 00000406 __RSH () C:\ProgramData\ntuser.pol
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieUserList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-06-25 12:31 - 2014-06-25 12:31 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Packages
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Ivuška\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator
2014-06-25 12:30 - 2013-08-26 20:27 - 00000000 ____D () C:\Users\Ivuška\AppData\Local\Google
2014-06-25 12:30 - 2013-08-16 13:48 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Google
2014-06-25 12:30 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-25 12:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe
2014-06-25 11:05 - 2014-06-25 11:05 - 00000000 _____ () C:\autoexec.bat
2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe
2014-06-25 11:01 - 2014-06-25 11:00 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt
2014-06-25 11:01 - 2014-06-25 10:59 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt
2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe
2014-06-25 10:57 - 2014-06-25 10:57 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64.exe
2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp
2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp
2014-06-25 10:20 - 2009-07-14 06:45 - 00346088 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-25 10:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-06-25 10:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-25 10:15 - 2011-04-12 10:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-06-25 10:15 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-06-25 10:15 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-06-25 10:06 - 2013-11-12 18:58 - 01555904 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-06-25 10:01 - 2014-06-25 09:59 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-25 09:26 - 2014-06-25 09:26 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00266456 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00240856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-06-25 08:48 - 2013-08-16 13:53 - 00002057 _____ () C:\Windows\epplauncher.mif
2014-06-25 08:27 - 2013-08-16 13:53 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-06-25 08:27 - 2013-08-16 13:52 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-06-25 08:27 - 2013-08-16 13:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-06-25 08:27 - 2013-08-16 13:33 - 00086096 _____ () C:\Users\Uživatel\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-25 08:06 - 2013-08-16 13:37 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Windows\Sun
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Oracle
2014-06-25 07:13 - 2014-06-25 07:13 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-25 07:12 - 2014-06-25 07:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-25 07:12 - 2014-06-25 07:11 - 00006026 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-06-25 07:12 - 2013-08-16 13:54 - 00000000 ____D () C:\Program Files (x86)\Java
2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp
2014-06-25 07:09 - 2014-06-01 22:02 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-25 07:09 - 2014-06-01 22:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-25 07:05 - 2014-05-31 21:04 - 00000000 _____ () C:\Windows\SysWOW64\s.o
2014-06-20 21:30 - 2014-06-20 21:30 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-20 21:29 - 2014-06-20 21:29 - 00284264 _____ (Mozilla) C:\Windows\Firefox Setup Stub 30.0.exe
2014-06-20 21:15 - 2013-08-16 13:48 - 00000000 ____D () C:\Program Files (x86)\Google
2014-06-20 15:28 - 2014-06-25 18:53 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-20 08:41 - 2013-08-18 16:34 - 00000000 ____D () C:\Users\Uživatel\fotky
2014-06-19 20:33 - 2013-08-16 13:08 - 00000000 ____D () C:\Users\Uživatel
2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp
2014-06-17 14:49 - 2014-06-18 04:43 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 13:57 - 2014-06-17 13:57 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-06-03 21:19 - 2014-06-03 21:19 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Macromedia
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Mozilla
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\ProgramData\Mozilla
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\system32\Macromed
2014-06-01 21:47 - 2014-05-30 23:25 - 00000000 ____D () C:\ProgramData\DivX
2014-06-01 21:47 - 2014-05-30 23:25 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-06-01 21:38 - 2013-08-16 13:52 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-06-01 17:17 - 2014-06-25 09:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-30 20:44
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:146.39 GB) (Free:73.15 GB) NTFS
Drive d: (DATA) (Fixed) (Total:319.28 GB) (Free:317.09 GB) NTFS
Available physical RAM: 2359.13 MB
Total physical RAM: 3912.36 MB
Percentage of memory in use: 39%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 9ABFF84B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=146 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=319 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\U�ivatel\Desktop" je 6 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"C:\Users\U�ivatel\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"C:\Users\U�ivatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv
C:\Windows\system32\mncevdfbt.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv
C:\Windows\inf\mncrnysd.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp
C:\Windows\system32\msstp.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv
C:\Windows\inf\ntvdm.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
2014-06-25 07:46 - 2013-07-04 13:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2014-06-25 07:46 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-06-25 07:46 - 2013-04-26 07:51 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-06-25 07:46 - 2013-04-26 06:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2014-06-25 07:46 - 2012-11-23 05:13 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-06-25 07:46 - 2012-11-02 07:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-06-25 07:46 - 2012-11-02 07:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll
2014-06-25 07:46 - 2012-09-26 00:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2014-06-25 07:46 - 2012-09-26 00:46 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-06-25 07:46 - 2012-04-26 07:41 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-06-25 07:46 - 2012-04-26 07:41 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-06-25 07:46 - 2012-04-26 07:34 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-06-25 07:46 - 2012-03-17 09:58 - 00075120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-06-25 07:46 - 2011-08-17 07:26 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-06-25 07:46 - 2011-08-17 07:25 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-06-25 07:46 - 2011-08-17 06:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisdecd.dll
2014-06-25 07:46 - 2011-08-17 06:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\psisrndr.ax
2014-06-25 07:46 - 2011-03-03 08:24 - 00357888 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-06-25 07:46 - 2011-03-03 08:24 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-06-25 07:46 - 2011-03-03 08:21 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-06-25 07:46 - 2011-03-03 07:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2014-06-25 07:46 - 2011-03-03 07:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnscacheugc.exe
2014-06-25 07:46 - 2011-02-12 13:34 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-06-25 07:46 - 2011-02-05 19:10 - 00642944 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-06-25 07:46 - 2011-02-05 19:10 - 00020352 _____ (Microsoft Corporation) C:\Windows\system32\kdusb.dll
2014-06-25 07:46 - 2011-02-05 19:10 - 00019328 _____ (Microsoft Corporation) C:\Windows\system32\kd1394.dll
2014-06-25 07:46 - 2011-02-05 19:10 - 00017792 _____ (Microsoft Corporation) C:\Windows\system32\kdcom.dll
2014-06-25 07:45 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-06-25 07:45 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-06-25 07:45 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-06-25 07:45 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2014-06-25 07:45 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2014-06-25 07:45 - 2012-06-06 08:02 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-06-25 07:45 - 2012-06-06 07:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2014-06-25 07:36 - 2011-11-19 16:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-06-25 07:36 - 2011-11-19 16:01 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Windows\Sun
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Oracle
2014-06-25 07:13 - 2014-06-25 07:13 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-25 07:12 - 2014-06-25 07:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-25 07:12 - 2014-05-07 15:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-06-25 07:12 - 2014-05-07 14:59 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-06-25 07:12 - 2014-05-07 14:59 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-06-25 07:12 - 2014-05-07 14:58 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-06-25 07:11 - 2014-06-25 07:12 - 00006026 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp
2014-06-20 21:30 - 2014-06-20 21:30 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-20 21:29 - 2014-06-20 21:29 - 00284264 _____ (Mozilla) C:\Windows\Firefox Setup Stub 30.0.exe
2014-06-20 21:16 - 2014-07-01 21:24 - 00003994 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7A457C8B-B88C-41C6-B3B9-33DA69AED102}
2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp
2014-06-18 04:43 - 2014-06-17 14:49 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 13:57 - 2014-06-17 13:57 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-06-03 21:19 - 2014-06-03 21:19 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Macromedia
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Mozilla
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\ProgramData\Mozilla
2014-06-01 22:02 - 2014-06-25 07:09 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-01 22:02 - 2014-06-25 07:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\system32\Macromed
==================== One Month Modified Files and Folders =======
2014-07-01 21:32 - 2014-07-01 21:32 - 00014169 _____ () C:\Users\Uživatel\Desktop\FRST.txt
2014-07-01 21:32 - 2014-06-25 10:58 - 00000000 ____D () C:\FRST
2014-07-01 21:24 - 2014-06-20 21:16 - 00003994 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{7A457C8B-B88C-41C6-B3B9-33DA69AED102}
2014-07-01 21:15 - 2009-07-14 06:45 - 00021280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-01 21:15 - 2009-07-14 06:45 - 00021280 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-01 21:12 - 2014-07-01 17:33 - 00000000 ____D () C:\Qoobox
2014-07-01 21:11 - 2014-07-01 21:11 - 00021710 _____ () C:\ComboFix.txt
2014-07-01 21:11 - 2013-08-16 19:11 - 01453189 _____ () C:\Windows\WindowsUpdate.log
2014-07-01 21:11 - 2011-04-12 10:34 - 00666656 _____ () C:\Windows\system32\perfh005.dat
2014-07-01 21:11 - 2011-04-12 10:34 - 00140320 _____ () C:\Windows\system32\perfc005.dat
2014-07-01 21:11 - 2009-07-14 07:13 - 01577410 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-01 21:07 - 2014-06-30 19:53 - 00003196 _____ () C:\Windows\PFRO.log
2014-07-01 21:07 - 2014-06-30 19:53 - 00000448 _____ () C:\Windows\setupact.log
2014-07-01 21:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-01 21:07 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-01 21:06 - 2014-07-01 17:32 - 00000000 ____D () C:\Windows\erdnt
2014-07-01 21:06 - 2009-07-14 04:34 - 68976640 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 17825792 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 00327680 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 00143360 _____ () C:\Windows\system32\config\SAM.bak
2014-07-01 21:06 - 2009-07-14 04:34 - 00028672 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-01 21:00 - 2014-07-01 21:00 - 00001204 _____ () C:\CF-Submit.htm
2014-07-01 17:45 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-01 17:31 - 2014-07-01 17:30 - 05212874 ____R (Swearware) C:\ComboFix.exe
2014-07-01 17:29 - 2014-07-01 17:28 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt
2014-07-01 17:27 - 2014-07-01 17:26 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com
2014-07-01 00:06 - 2014-07-01 00:04 - 00000000 ____D () C:\AdwCleaner
2014-07-01 00:03 - 2014-07-01 00:04 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe
2014-07-01 00:02 - 2014-06-25 11:04 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-30 23:59 - 2014-06-30 23:59 - 00285888 _____ () C:\Windows\Minidump\063014-23088-01.dmp
2014-06-30 23:59 - 2014-06-30 23:34 - 482614978 _____ () C:\Windows\MEMORY.DMP
2014-06-30 23:59 - 2014-06-30 23:34 - 00000000 ____D () C:\Windows\Minidump
2014-06-30 23:54 - 2014-06-30 23:56 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe
2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe
2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar
2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp
2014-06-30 23:34 - 2014-06-30 23:34 - 00285792 _____ () C:\Windows\Minidump\063014-21153-01.dmp
2014-06-30 23:33 - 2014-06-30 23:42 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt
2014-06-30 23:28 - 2014-06-30 23:29 - 02083328 _____ (Farbar) C:\Users\Uživatel\Desktop\FRST64.exe
2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe
2014-06-30 23:27 - 2014-06-30 23:29 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe
2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp
2014-06-30 20:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp
2014-06-30 20:01 - 2014-05-30 23:24 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Seznam.cz
2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp
2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-30 19:47 - 2013-08-16 13:35 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-30 19:45 - 2013-08-16 13:35 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-06-30 19:43 - 2014-06-25 12:30 - 00000000 ____D () C:\ProgramData\6b4f3e85ab1ac942
2014-06-30 19:42 - 2014-06-30 19:42 - 00043120 _____ () C:\Users\Uživatel\Documents\cc_20140630_194158.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00007954 _____ () C:\Users\Uživatel\Documents\cc_20140630_194224.reg
2014-06-30 19:42 - 2014-06-30 19:42 - 00000540 _____ () C:\Users\Uživatel\Documents\cc_20140630_194241.reg
2014-06-30 19:41 - 2013-08-16 20:07 - 00000000 ____D () C:\Windows\Panther
2014-06-30 19:41 - 2013-08-16 13:18 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-06-30 19:41 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini
2014-06-30 19:39 - 2014-06-30 19:39 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-06-30 19:39 - 2014-06-30 19:39 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-06-30 19:39 - 2014-06-30 19:39 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-30 19:38 - 2014-06-30 19:36 - 04812672 _____ (Piriform Ltd) C:\Users\Uživatel\Downloads\ccsetup415.exe
2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk
2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key
2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-06-25 18:12 - 2014-06-25 18:11 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys
2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe
2014-06-25 17:38 - 2014-06-25 17:37 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651
2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe
2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-25 13:09 - 2014-06-25 13:08 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe
2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp
2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Adobe
2014-06-25 12:50 - 2014-06-25 12:50 - 00000000 ____D () C:\ProgramData\Trusted Publisher
2014-06-25 12:50 - 2014-06-25 12:30 - 00000406 __RSH () C:\ProgramData\ntuser.pol
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieUserList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 __SHD () C:\Users\Uživatel\AppData\Local\EmieSiteList
2014-06-25 12:44 - 2014-06-25 12:44 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-06-25 12:31 - 2014-06-25 12:31 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Packages
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Ivuška\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\HomeGroupUser$
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Guest
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-25 12:30 - 2014-06-25 12:30 - 00000000 ____D () C:\Users\Administrator
2014-06-25 12:30 - 2013-08-26 20:27 - 00000000 ____D () C:\Users\Ivuška\AppData\Local\Google
2014-06-25 12:30 - 2013-08-16 13:48 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Google
2014-06-25 12:30 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-25 12:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe
2014-06-25 11:05 - 2014-06-25 11:05 - 00000000 _____ () C:\autoexec.bat
2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe
2014-06-25 11:01 - 2014-06-25 11:00 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt
2014-06-25 11:01 - 2014-06-25 10:59 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt
2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe
2014-06-25 10:57 - 2014-06-25 10:57 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64.exe
2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp
2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp
2014-06-25 10:20 - 2009-07-14 06:45 - 00346088 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-25 10:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-06-25 10:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-25 10:15 - 2011-04-12 10:45 - 00000000 ____D () C:\Program Files\Windows Journal
2014-06-25 10:15 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-06-25 10:15 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\zh-HK
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\tr-TR
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-06-25 10:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-06-25 10:06 - 2013-11-12 18:58 - 01555904 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-06-25 10:01 - 2014-06-25 09:59 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-25 09:26 - 2014-06-25 09:26 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-25 09:26 - 2014-06-25 09:26 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-25 09:26 - 2014-06-25 09:26 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-06-25 09:26 - 2014-06-25 09:26 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-06-25 09:26 - 2014-06-25 09:26 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00266456 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00240856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-06-25 09:26 - 2014-06-25 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-06-25 09:26 - 2014-06-25 09:26 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-06-25 09:26 - 2014-06-25 09:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2014-06-25 09:24 - 2014-06-25 09:24 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-06-25 09:23 - 2014-06-25 09:23 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 02284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 01080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:16 - 2014-06-25 09:16 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-06-25 09:14 - 2014-06-25 09:14 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2014-06-25 08:48 - 2013-08-16 13:53 - 00002057 _____ () C:\Windows\epplauncher.mif
2014-06-25 08:27 - 2013-08-16 13:53 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-06-25 08:27 - 2013-08-16 13:52 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-06-25 08:27 - 2013-08-16 13:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-06-25 08:27 - 2013-08-16 13:33 - 00086096 _____ () C:\Users\Uživatel\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-25 08:06 - 2013-08-16 13:37 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Windows\Sun
2014-06-25 07:17 - 2014-06-25 07:17 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Oracle
2014-06-25 07:13 - 2014-06-25 07:13 - 00000000 ____D () C:\ProgramData\Oracle
2014-06-25 07:12 - 2014-06-25 07:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-06-25 07:12 - 2014-06-25 07:11 - 00006026 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log
2014-06-25 07:12 - 2013-08-16 13:54 - 00000000 ____D () C:\Program Files (x86)\Java
2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp
2014-06-25 07:09 - 2014-06-01 22:02 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-25 07:09 - 2014-06-01 22:02 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-25 07:05 - 2014-05-31 21:04 - 00000000 _____ () C:\Windows\SysWOW64\s.o
2014-06-20 21:30 - 2014-06-20 21:30 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Users\Uživatel\AppData\Roaming\Mozilla
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-20 21:30 - 2014-06-20 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-20 21:29 - 2014-06-20 21:29 - 00284264 _____ (Mozilla) C:\Windows\Firefox Setup Stub 30.0.exe
2014-06-20 21:15 - 2013-08-16 13:48 - 00000000 ____D () C:\Program Files (x86)\Google
2014-06-20 15:28 - 2014-06-25 18:53 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{3f538614-b636-4023-9ec2-564ada4b07b3}w64.sys
2014-06-20 08:41 - 2013-08-18 16:34 - 00000000 ____D () C:\Users\Uživatel\fotky
2014-06-19 20:33 - 2013-08-16 13:08 - 00000000 ____D () C:\Users\Uživatel
2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp
2014-06-17 14:49 - 2014-06-18 04:43 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}w64.sys
2014-06-17 13:57 - 2014-06-17 13:57 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-06-03 21:19 - 2014-06-03 21:19 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Macromedia
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\Mozilla
2014-06-03 21:15 - 2014-06-03 21:15 - 00000000 ____D () C:\ProgramData\Mozilla
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-06-01 22:02 - 2014-06-01 22:02 - 00000000 ____D () C:\Windows\system32\Macromed
2014-06-01 21:47 - 2014-05-30 23:25 - 00000000 ____D () C:\ProgramData\DivX
2014-06-01 21:47 - 2014-05-30 23:25 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-06-01 21:38 - 2013-08-16 13:52 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-06-01 17:17 - 2014-06-25 09:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-30 20:44
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:146.39 GB) (Free:73.15 GB) NTFS
Drive d: (DATA) (Fixed) (Total:319.28 GB) (Free:317.09 GB) NTFS
Available physical RAM: 2359.13 MB
Total physical RAM: 3912.36 MB
Percentage of memory in use: 39%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 9ABFF84B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=146 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=319 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\U�ivatel\Desktop" je 6 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate
"C:\Users\U�ivatel\AppData\Roaming\Seznam.cz\szninstall.exe" -c [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop
"C:\Users\U�ivatel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv
C:\Windows\system32\mncevdfbt.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv
C:\Windows\inf\mncrnysd.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp
C:\Windows\system32\msstp.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv
C:\Windows\inf\ntvdm.vbe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: Zavirovaný notebook


- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe GroupPolicy: Group Policy on Chrome detected <======= ATTENTION SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO-x32: Adblocker - {5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - C:\Program Files (x86)\Adblocker\8TjqFlez.dll No File BHO-x32: No Name - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - No File FF Extension: Adblocker - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com [2014-06-25] FF Extension: MySearch - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com [2014-06-25] CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56" CHR NewTab: "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html" CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc [2014-06-25] CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn [2014-06-25] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S3 catchme; \??\C:\ComboFix\catchme.sys [X] 2014-07-01 17:28 - 2014-07-01 17:29 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt 2014-07-01 17:26 - 2014-07-01 17:27 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com 2014-07-01 00:05 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-01 00:04 - 2014-07-01 00:06 - 00000000 ____D () C:\AdwCleaner 2014-07-01 00:04 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe 2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe 2014-06-30 23:56 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe 2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe 2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar 2014-06-30 23:42 - 2014-06-30 23:33 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt 2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp 2014-06-30 23:29 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe 2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe 2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe 2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp 2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp 2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp 2014-06-30 19:53 - 2014-07-01 21:07 - 00003196 _____ () C:\Windows\PFRO.log 2014-06-30 19:53 - 2014-07-01 21:07 - 00000448 _____ () C:\Windows\setupact.log 2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk 2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key 2014-06-25 18:13 - 2014-01-19 19:57 - 00001419 ____N () C:\Windows\SysWOW64\msstp.vbe 2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams 2014-06-25 18:12 - 2014-03-05 22:19 - 00007670 ____S () C:\Windows\SysWOW64\mncevdfbt.vbe 2014-06-25 18:12 - 2013-12-10 00:30 - 10236928 ____S () C:\Windows\SysWOW64\acumncevdfbt.exe 2014-06-25 18:12 - 2013-10-26 20:30 - 00972814 ____S () C:\Windows\SysWOW64\dcgmncevdfbt.exe 2014-06-25 18:11 - 2014-06-25 18:12 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe 2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe 2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe 2014-06-25 17:37 - 2014-06-25 17:38 - 00000085 _____ () C:\Windows\wininit.ini 2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651 2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe 2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-06-25 13:08 - 2014-06-25 13:09 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe 2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp 2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp 2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe 2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe 2014-06-25 11:00 - 2014-06-25 11:01 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt 2014-06-25 10:59 - 2014-06-25 11:01 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt 2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe 2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp 2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp 2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp 2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp 2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f C:\Windows\inf\ntvdm.vbe C:\Windows\system32\msstp.vbe C:\Windows\inf\mncrnysd.vbe C:\Windows\system32\mncevdfbt.vbe C:\Program Files (x86)\Spyware Terminator CMD: del /f /s /q C:\awh*.tmp Hosts: Reboot: End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: Zavirovaný notebook
Spyware Terminator jsem odinstaloval již jak jste to požadoval poprvé na začátku. Nemám ho teď ani nikde v programech a jeho složka v Programe files x86 taky není, co s tím?
Re: Zavirovaný notebook
Vytvorte tedy fixlist a provedte opravu pres FRST jak jsem psal vyse - tim i odpalime zbytky SpywareTerminatoru
Re: Zavirovaný notebook
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-07-2014
Ran by Uživatel at 2014-07-01 22:55:42 Run:1
Running from C:\Users\Uživatel\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO-x32: Adblocker - {5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - C:\Program Files (x86)\Adblocker\8TjqFlez.dll No File
BHO-x32: No Name - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - No File
FF Extension: Adblocker - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com [2014-06-25]
FF Extension: MySearch - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com [2014-06-25]
CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56"
CHR NewTab: "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc [2014-06-25]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn [2014-06-25]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
2014-07-01 17:28 - 2014-07-01 17:29 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt
2014-07-01 17:26 - 2014-07-01 17:27 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com
2014-07-01 00:05 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-01 00:04 - 2014-07-01 00:06 - 00000000 ____D () C:\AdwCleaner
2014-07-01 00:04 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe
2014-06-30 23:56 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe
2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe
2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar
2014-06-30 23:42 - 2014-06-30 23:33 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt
2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp
2014-06-30 23:29 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe
2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe
2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp
2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp
2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp
2014-06-30 19:53 - 2014-07-01 21:07 - 00003196 _____ () C:\Windows\PFRO.log
2014-06-30 19:53 - 2014-07-01 21:07 - 00000448 _____ () C:\Windows\setupact.log
2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk
2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key
2014-06-25 18:13 - 2014-01-19 19:57 - 00001419 ____N () C:\Windows\SysWOW64\msstp.vbe
2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-06-25 18:12 - 2014-03-05 22:19 - 00007670 ____S () C:\Windows\SysWOW64\mncevdfbt.vbe
2014-06-25 18:12 - 2013-12-10 00:30 - 10236928 ____S () C:\Windows\SysWOW64\acumncevdfbt.exe
2014-06-25 18:12 - 2013-10-26 20:30 - 00972814 ____S () C:\Windows\SysWOW64\dcgmncevdfbt.exe
2014-06-25 18:11 - 2014-06-25 18:12 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe
2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe
2014-06-25 17:37 - 2014-06-25 17:38 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651
2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe
2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-25 13:08 - 2014-06-25 13:09 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe
2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp
2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp
2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe
2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe
2014-06-25 11:00 - 2014-06-25 11:01 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt
2014-06-25 10:59 - 2014-06-25 11:01 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt
2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe
2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp
2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp
2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp
2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp
2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f
C:\Windows\inf\ntvdm.vbe
C:\Windows\system32\msstp.vbe
C:\Windows\inf\mncrnysd.vbe
C:\Windows\system32\mncevdfbt.vbe
C:\Program Files (x86)\Spyware Terminator
CMD: del /f /s /q C:\awh*.tmp
Hosts:
Reboot:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorShield => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorUpdater => value deleted successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1}' => Key deleted successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C42510-9B41-42c1-9DCD-7282A2D07C61}'=> Key not found.
'HKCR\Wow6432Node\CLSID\{C9C42510-9B41-42c1-9DCD-7282A2D07C61}' => Key deleted successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com => Moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com => Moved successfully.
CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56" ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc => Moved successfully.
C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn => Moved successfully.
'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully.
catchme => Service deleted successfully.
C:\Users\Uživatel\Desktop\Rkill.txt => Moved successfully.
C:\Users\Uživatel\Desktop\rkill.com => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe => Moved successfully.
C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe => Moved successfully.
C:\Users\Uživatel\Desktop\RSITx64.exe => Moved successfully.
C:\Users\Uživatel\Downloads\RSITx64.exe => Moved successfully.
C:\Users\Uživatel\Desktop\FRST – kopie.rar => Moved successfully.
C:\Users\Uživatel\Desktop\FRST – kopie.txt => Moved successfully.
C:\awh55AD.tmp => Moved successfully.
"C:\Users\Uživatel\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Users\Uživatel\Downloads\FRST64(2).exe => Moved successfully.
C:\Users\Uživatel\Downloads\FRSTLauncher.exe => Moved successfully.
C:\awh1312.tmp => Moved successfully.
C:\awh3E95.tmp => Moved successfully.
C:\awh3DDA.tmp => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Users\Public\Desktop\AVG 2013+licence key.lnk => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key => Moved successfully.
C:\Windows\SysWOW64\msstp.vbe => Moved successfully.
C:\Windows\SysWOW64\bitstreams => Moved successfully.
C:\Windows\SysWOW64\mncevdfbt.vbe => Moved successfully.
C:\Windows\SysWOW64\acumncevdfbt.exe => Moved successfully.
C:\Windows\SysWOW64\dcgmncevdfbt.exe => Moved successfully.
C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe => Moved successfully.
C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe => Moved successfully.
C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe => Moved successfully.
C:\Windows\wininit.ini => Moved successfully.
C:\Users\Uživatel\AppData\Local\6651 => Moved successfully.
C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Users\Uživatel\Downloads\spybot-2.3.exe => Moved successfully.
C:\awh3BF6.tmp => Moved successfully.
C:\awhADEA.tmp => Moved successfully.
C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe => Moved successfully.
C:\Users\Uživatel\Downloads\SpyHunter-installer.exe => Moved successfully.
C:\Users\Uživatel\Downloads\Addition.txt => Moved successfully.
C:\Users\Uživatel\Downloads\FRST.txt => Moved successfully.
C:\Users\Uživatel\Downloads\FRST64(1).exe => Moved successfully.
C:\awh46BF.tmp => Moved successfully.
C:\awhB441.tmp => Moved successfully.
C:\awh1515.tmp => Moved successfully.
C:\awh2F78.tmp => Moved successfully.
C:\awhAFB2.tmp => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\inf\ntvdm.vbe => Moved successfully.
"C:\Windows\system32\msstp.vbe" => File/Directory not found.
C:\Windows\inf\mncrnysd.vbe => Moved successfully.
"C:\Windows\system32\mncevdfbt.vbe" => File/Directory not found.
"C:\Program Files (x86)\Spyware Terminator" => File/Directory not found.
========= del /f /s /q C:\awh*.tmp =========
Nelze naj�t C:\awh*.tmp.
========= End of CMD: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
The system needed a reboot.
==== End of Fixlog ====
Ran by Uživatel at 2014-07-01 22:55:42 Run:1
Running from C:\Users\Uživatel\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO-x32: Adblocker - {5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1} - C:\Program Files (x86)\Adblocker\8TjqFlez.dll No File
BHO-x32: No Name - {C9C42510-9B41-42c1-9DCD-7282A2D07C61}C - No File
FF Extension: Adblocker - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com [2014-06-25]
FF Extension: MySearch - C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com [2014-06-25]
CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56"
CHR NewTab: "chrome-extension://olfeabkoenfaoljndfecamgilllcpiak/core/chrome/content/speedDial/speedDial.html"
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc [2014-06-25]
CHR Extension: (No Name) - C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn [2014-06-25]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
2014-07-01 17:28 - 2014-07-01 17:29 - 00002146 _____ () C:\Users\Uživatel\Desktop\Rkill.txt
2014-07-01 17:26 - 2014-07-01 17:27 - 01942776 _____ (Bleeping Computer, LLC) C:\Users\Uživatel\Desktop\rkill.com
2014-07-01 00:05 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-01 00:04 - 2014-07-01 00:06 - 00000000 ____D () C:\AdwCleaner
2014-07-01 00:04 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe
2014-07-01 00:03 - 2014-07-01 00:03 - 01346519 _____ () C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe
2014-06-30 23:56 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Desktop\RSITx64.exe
2014-06-30 23:54 - 2014-06-30 23:54 - 01222144 _____ () C:\Users\Uživatel\Downloads\RSITx64.exe
2014-06-30 23:42 - 2014-06-30 23:42 - 00015241 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.rar
2014-06-30 23:42 - 2014-06-30 23:33 - 00129539 _____ () C:\Users\Uživatel\Desktop\FRST – kopie.txt
2014-06-30 23:40 - 2014-06-30 23:40 - 00000687 _____ () C:\awh55AD.tmp
2014-06-30 23:29 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Desktop\FRSTLauncher.exe
2014-06-30 23:28 - 2014-06-30 23:28 - 02083328 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(2).exe
2014-06-30 23:27 - 2014-06-30 23:27 - 00112640 _____ (forum.viry.cz) C:\Users\Uživatel\Downloads\FRSTLauncher.exe
2014-06-30 23:09 - 2014-06-30 23:09 - 00000687 _____ () C:\awh1312.tmp
2014-06-30 20:19 - 2014-06-30 20:19 - 00000687 _____ () C:\awh3E95.tmp
2014-06-30 19:58 - 2014-06-30 19:58 - 00000687 _____ () C:\awh3DDA.tmp
2014-06-30 19:53 - 2014-07-01 21:07 - 00003196 _____ () C:\Windows\PFRO.log
2014-06-30 19:53 - 2014-07-01 21:07 - 00000448 _____ () C:\Windows\setupact.log
2014-06-30 19:53 - 2014-06-30 19:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-25 18:13 - 2014-06-25 18:13 - 00001155 _____ () C:\Users\Public\Desktop\AVG 2013+licence key.lnk
2014-06-25 18:13 - 2014-06-25 18:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key
2014-06-25 18:13 - 2014-01-19 19:57 - 00001419 ____N () C:\Windows\SysWOW64\msstp.vbe
2014-06-25 18:12 - 2014-06-25 18:12 - 00000000 ____D () C:\Windows\SysWOW64\bitstreams
2014-06-25 18:12 - 2014-03-05 22:19 - 00007670 ____S () C:\Windows\SysWOW64\mncevdfbt.vbe
2014-06-25 18:12 - 2013-12-10 00:30 - 10236928 ____S () C:\Windows\SysWOW64\acumncevdfbt.exe
2014-06-25 18:12 - 2013-10-26 20:30 - 00972814 ____S () C:\Windows\SysWOW64\dcgmncevdfbt.exe
2014-06-25 18:11 - 2014-06-25 18:12 - 13079391 _____ ( ) C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe
2014-06-25 18:06 - 2014-06-25 18:06 - 04978376 _____ (Crawler.com ) C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe
2014-06-25 17:57 - 2014-06-25 17:57 - 29183200 _____ (Microsoft Corporation) C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe
2014-06-25 17:37 - 2014-06-25 17:38 - 00000085 _____ () C:\Windows\wininit.ini
2014-06-25 17:05 - 2014-06-25 17:05 - 00000000 ____D () C:\Users\Uživatel\AppData\Local\6651
2014-06-25 13:23 - 2014-06-25 13:23 - 00346584 _____ () C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe
2014-06-25 13:10 - 2014-06-25 13:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-06-25 13:08 - 2014-06-25 13:09 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\Uživatel\Downloads\spybot-2.3.exe
2014-06-25 13:01 - 2014-06-25 13:01 - 00000687 _____ () C:\awh3BF6.tmp
2014-06-25 12:52 - 2014-06-25 12:52 - 00000687 _____ () C:\awhADEA.tmp
2014-06-25 12:29 - 2014-06-25 12:29 - 00766200 _____ (SQL) C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe
2014-06-25 11:03 - 2014-06-25 11:03 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Uživatel\Downloads\SpyHunter-installer.exe
2014-06-25 11:00 - 2014-06-25 11:01 - 00025839 _____ () C:\Users\Uživatel\Downloads\Addition.txt
2014-06-25 10:59 - 2014-06-25 11:01 - 00108174 _____ () C:\Users\Uživatel\Downloads\FRST.txt
2014-06-25 10:58 - 2014-06-25 10:58 - 02082816 _____ (Farbar) C:\Users\Uživatel\Downloads\FRST64(1).exe
2014-06-25 10:41 - 2014-06-25 10:41 - 00000687 _____ () C:\awh46BF.tmp
2014-06-25 10:28 - 2014-06-25 10:28 - 00000687 _____ () C:\awhB441.tmp
2014-06-25 07:33 - 2014-06-25 07:33 - 00000687 _____ () C:\awh1515.tmp
2014-06-25 07:10 - 2014-06-25 07:10 - 00000687 _____ () C:\awh2F78.tmp
2014-06-19 18:37 - 2014-06-19 18:37 - 00000687 _____ () C:\awhAFB2.tmp
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f
C:\Windows\inf\ntvdm.vbe
C:\Windows\system32\msstp.vbe
C:\Windows\inf\mncrnysd.vbe
C:\Windows\system32\mncevdfbt.vbe
C:\Program Files (x86)\Spyware Terminator
CMD: del /f /s /q C:\awh*.tmp
Hosts:
Reboot:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorShield => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SpywareTerminatorUpdater => value deleted successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{5878FA1A-6A8B-1B43-F541-AD7AC6D9E5C1}' => Key deleted successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C42510-9B41-42c1-9DCD-7282A2D07C61}'=> Key not found.
'HKCR\Wow6432Node\CLSID\{C9C42510-9B41-42c1-9DCD-7282A2D07C61}' => Key deleted successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\maplxhib@djhuyufgvo.com => Moved successfully.
C:\Users\Uživatel\AppData\Roaming\Mozilla\Firefox\Profiles\avjkl0uw.default\Extensions\uioi_3eiyi@yhgueeuo.com => Moved successfully.
CHR RestoreOnStartup: "hxxp://websearch.fastsearchings.info/?pid=2145&r=2014/06/25&hid=7972956568429594366&lg=EN&cc=CZ&unqvl=56" ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejiggndngefnfnkpnbhbpkdebnkclkc => Moved successfully.
C:\Users\Uživatel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lomllnbmgafglogpdgikmklkgndelhgn => Moved successfully.
'HKLM\SOFTWARE\Policies\Google' => Key deleted successfully.
catchme => Service deleted successfully.
C:\Users\Uživatel\Desktop\Rkill.txt => Moved successfully.
C:\Users\Uživatel\Desktop\rkill.com => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Uživatel\Desktop\adwcleaner_3.214.exe => Moved successfully.
C:\Users\Uživatel\Downloads\adwcleaner_3.214.exe => Moved successfully.
C:\Users\Uživatel\Desktop\RSITx64.exe => Moved successfully.
C:\Users\Uživatel\Downloads\RSITx64.exe => Moved successfully.
C:\Users\Uživatel\Desktop\FRST – kopie.rar => Moved successfully.
C:\Users\Uživatel\Desktop\FRST – kopie.txt => Moved successfully.
C:\awh55AD.tmp => Moved successfully.
"C:\Users\Uživatel\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Users\Uživatel\Downloads\FRST64(2).exe => Moved successfully.
C:\Users\Uživatel\Downloads\FRSTLauncher.exe => Moved successfully.
C:\awh1312.tmp => Moved successfully.
C:\awh3E95.tmp => Moved successfully.
C:\awh3DDA.tmp => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Users\Public\Desktop\AVG 2013+licence key.lnk => Moved successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2013+licence key => Moved successfully.
C:\Windows\SysWOW64\msstp.vbe => Moved successfully.
C:\Windows\SysWOW64\bitstreams => Moved successfully.
C:\Windows\SysWOW64\mncevdfbt.vbe => Moved successfully.
C:\Windows\SysWOW64\acumncevdfbt.exe => Moved successfully.
C:\Windows\SysWOW64\dcgmncevdfbt.exe => Moved successfully.
C:\Users\Uživatel\Downloads\Spyware-terminator-2012-licence-key-cz.exe => Moved successfully.
C:\Users\Uživatel\Downloads\SpywareTerminatorSetup.exe => Moved successfully.
C:\Users\Uživatel\Downloads\Windows-KB890830-x64-V5.13.exe => Moved successfully.
C:\Windows\wininit.ini => Moved successfully.
C:\Users\Uživatel\AppData\Local\6651 => Moved successfully.
C:\Users\Uživatel\Downloads\SpyHunter4Crack__4869_il50297.exe => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Users\Uživatel\Downloads\spybot-2.3.exe => Moved successfully.
C:\awh3BF6.tmp => Moved successfully.
C:\awhADEA.tmp => Moved successfully.
C:\Users\Uživatel\Downloads\SpyHunter 4.17.6.4336 Full version With Patch.exe => Moved successfully.
C:\Users\Uživatel\Downloads\SpyHunter-installer.exe => Moved successfully.
C:\Users\Uživatel\Downloads\Addition.txt => Moved successfully.
C:\Users\Uživatel\Downloads\FRST.txt => Moved successfully.
C:\Users\Uživatel\Downloads\FRST64(1).exe => Moved successfully.
C:\awh46BF.tmp => Moved successfully.
C:\awhB441.tmp => Moved successfully.
C:\awh1515.tmp => Moved successfully.
C:\awh2F78.tmp => Moved successfully.
C:\awhAFB2.tmp => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncevdfbtSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncrnysdSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\inf\ntvdm.vbe => Moved successfully.
"C:\Windows\system32\msstp.vbe" => File/Directory not found.
C:\Windows\inf\mncrnysd.vbe => Moved successfully.
"C:\Windows\system32\mncevdfbt.vbe" => File/Directory not found.
"C:\Program Files (x86)\Spyware Terminator" => File/Directory not found.
========= del /f /s /q C:\awh*.tmp =========
Nelze naj�t C:\awh*.tmp.
========= End of CMD: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
The system needed a reboot.
==== End of Fixlog ====