Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
borek
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 črc 2014 11:53

Prosím o kontrolu logu

#1 Příspěvek od borek »

Dobrý den,
prosil bych o kontrolu logu a pomoc při vyčištění od havěti. Mám bohužel více problémů:
1) při zmáčknutí tlačítka pro zapnutí počítače trvá asi 5 vteřin, než se na monitoru něco zobrazí. Zhruba před 2 měsíci se PC zapínal bez té prodlevy.
2) při najetí do systému windows trvá delší dobu, než je systém schopný reagovat (teda reaguje, ale ne hned, nejspíše ho brzdí najíždění ostatních programů, ale nejsem si vědom, že bych instaloval nějaký náročný program - taky to takto nedělalo od začátku).
3) nedaří se mi zbavit programu FixMyRegistry - při odinstalaci se místo něj objeví druhý program a neustále se střídají


Zde je log.txt

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Hukvaldy at 2014-07-16 13:09:35
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 2 GB (5%) free of 45 GB
Total RAM: 8190 MB (75% free)


======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"I:\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\Explorer.EXE
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {024E2DB2-216D-4D8D-9D42-DE0B0C6632C8}
C:\Windows\SysWOW64\Rundll32.exe "C:\Users\Hukvaldy\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
"C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe"
"I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe" -autorun
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"I:\SamsungKies\Kies\Kies.exe" /preload
"C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe"
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"I:\QIP 2005 (portable)\qip.exe" 
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"I:\Avast\avastui.exe" /nogui
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"I:\SamsungKies\Kies\KiesTrayAgent.exe" 
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --channel="4032.1.1437229729\1695688651" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --channel="4032.2.163084785\1050249380" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --channel="4032.3.1942358636\849774457" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Hukvaldy\AppData\Local\Google\Chrome\User Data\Default\Extensions\heildphpnddilhkemkielfhnkaagiabh\3.2_0\plugin/npBrowserSwitcher.dll" --lang=cs --channel="4032.8.1812678368\299974459" /prefetch:-390060480
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4032.18.713513009\386829849" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\Hukvaldy\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=1,15 --gpu-vendor-id=0x1002 --gpu-device-id=0x68f9 --gpu-driver-vendor=Microsoft --gpu-driver-version=6.1.7600.16385 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4032.35.1295323976\1118071793" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.42.1917622468\1810771503" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.78.1629647610\1697119379" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.84.2069965989\1488937254" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.89.344958202\282632349" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.91.962406471\792789987" /prefetch:673131151
C:\Windows\system32\wbem\wmiprvse.exe

"C:\Program Files\trend micro\Hukvaldy.exe" /silentautolog
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.93.366581135\1210705943" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="4032.97.808668481\1853742842" /prefetch:673131151
"I:\MSOffice\Office12\EXCEL.EXE" /e
C:\Windows\System32\svchost.exe -k WerSvcGroup
"C:\Users\Hukvaldy\Downloads\RSITx64.exe" 
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - I:\Avast\aswWebRepIE64.dll [2013-11-02 1567016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-06-03 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-06-03 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - I:\Avast\aswWebRepIE.dll [2013-11-02 606544]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-29 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - E:\VisualStudio\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player ControlBar Toolbar - C:\Users\Hukvaldy\AppData\LocalLow\BS_Player_ControlBar\prxtbBS_1.dll [2014-04-10 423744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - I:\Avast\aswWebRepIE64.dll [2013-11-02 1567016]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - I:\Avast\aswWebRepIE.dll [2013-11-02 606544]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player ControlBar Toolbar - C:\Users\Hukvaldy\AppData\LocalLow\BS_Player_ControlBar\prxtbBS_1.dll [2014-04-10 423744]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"KiesPreload"=I:\SamsungKies\Kies\Kies.exe [2014-02-14 1564992]
"KiesAirMessage"=I:\SamsungKies\Kies\KiesAirMessage.exe -startup []
"SpeedUpMyComputer"=C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss []
"FixMyRegistry"=C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [2014-05-26 1886840]
"QIP2005"=I:\QIP 2005 (portable)\qip.exe [2009-08-13 3276288]
"Raptr"=C:\PROGRA~2\Raptr\raptrstub.exe [2014-06-24 55360]
"BackgroundContainerV2"=C:\Windows\SysWOW64\Rundll32.exe [2009-07-14 44544]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=I:\Avast\AvastUI.exe [2013-11-02 3567800]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"KiesTrayAgent"=I:\SamsungKies\Kies\KiesTrayAgent.exe [2014-02-14 311616]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KNet]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-16 12:55:47 ----D---- C:\rsit
2014-07-16 12:55:47 ----D---- C:\Program Files\trend micro
2014-07-14 23:06:40 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-07-14 23:06:36 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-07-14 23:06:36 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-07-14 23:06:34 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-07-14 23:06:34 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-07-14 23:06:32 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-07-14 23:06:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-07-14 23:06:32 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-07-14 23:06:32 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-07-14 23:06:30 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-07-14 23:06:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-07-14 23:06:30 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-07-14 23:06:30 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-07-14 23:06:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-07-14 23:06:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-07-14 23:06:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-07-14 23:06:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-07-14 23:06:26 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-07-14 23:06:24 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-07-14 23:06:24 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-07-14 23:06:20 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-07-14 23:06:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-07-14 23:06:20 ----A---- C:\Windows\system32\xinput1_3.dll
2014-07-14 23:06:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-07-14 23:06:18 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-07-14 23:06:18 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-07-14 23:06:18 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-07-14 23:06:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-07-14 23:06:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-07-14 23:06:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-07-14 23:06:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-07-14 23:06:17 ----A---- C:\Windows\system32\d3dx10.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-07-14 23:06:15 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-07-14 23:06:15 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-07-14 23:06:15 ----A---- C:\Windows\system32\xinput1_2.dll
2014-07-14 23:06:15 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-07-14 23:06:14 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-07-14 23:06:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-07-14 23:06:14 ----A---- C:\Windows\system32\xinput1_1.dll
2014-07-14 23:06:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-07-14 23:06:13 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-07-14 23:06:13 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-07-14 23:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-07-14 23:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-07-14 23:06:09 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-07-14 23:06:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-07-14 23:06:08 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-07-14 23:06:08 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-07-14 23:06:08 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-07-14 23:06:08 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-07-14 23:06:07 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-07-14 23:06:07 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-07-14 23:06:06 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-07-14 23:06:06 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-07-14 23:02:49 ----SHD---- C:\Config.Msi
2014-07-14 23:02:39 ----D---- C:\Users\Hukvaldy\AppData\Roaming\ATI
2014-07-14 22:53:32 ----D---- C:\Users\Hukvaldy\AppData\Roaming\library_dir
2014-07-14 22:52:50 ----D---- C:\Users\Hukvaldy\AppData\Roaming\Raptr
2014-07-14 22:52:50 ----D---- C:\Program Files (x86)\Raptr
2014-07-14 22:51:45 ----D---- C:\ProgramData\AMD
2014-07-14 22:50:29 ----D---- C:\Program Files\AMD
2014-07-14 22:49:57 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-07-14 22:49:40 ----D---- C:\ProgramData\Package Cache
2014-07-12 12:00:36 ----N---- C:\Windows\unvise32.exe
2014-06-29 22:26:24 ----D---- C:\ProgramData\Oracle
2014-06-29 22:26:21 ----D---- C:\ProgramData\Sun
2014-06-29 22:26:12 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\java.exe
2014-06-29 22:26:01 ----D---- C:\Program Files (x86)\Java
2014-06-18 20:34:37 ----D---- C:\Users\Hukvaldy\AppData\Roaming\Microsoft FxCop

======List of files/folders modified in the last 1 month======

2014-07-16 13:09:32 ----D---- C:\Windows\Temp
2014-07-16 12:55:47 ----RD---- C:\Program Files
2014-07-15 21:05:37 ----SHD---- C:\System Volume Information
2014-07-14 23:33:15 ----D---- C:\Windows\system32\catroot
2014-07-14 23:32:28 ----SHD---- C:\Windows\Installer
2014-07-14 23:07:38 ----D---- C:\Windows\system32\config
2014-07-14 23:06:41 ----D---- C:\Windows\SysWOW64
2014-07-14 23:06:41 ----D---- C:\Windows\System32
2014-07-14 23:06:13 ----RSD---- C:\Windows\assembly
2014-07-14 23:06:11 ----D---- C:\Windows\Microsoft.NET
2014-07-14 23:06:07 ----D---- C:\Windows
2014-07-14 23:05:25 ----D---- C:\Windows\Logs
2014-07-14 23:03:38 ----RD---- C:\Program Files (x86)
2014-07-14 23:03:38 ----D---- C:\Program Files (x86)\Common Files
2014-07-14 23:03:07 ----HD---- C:\ProgramData
2014-07-14 23:02:44 ----D---- C:\Windows\system32\DriverStore
2014-07-14 23:02:44 ----D---- C:\Windows\system32\catroot2
2014-07-14 23:02:44 ----D---- C:\Windows\inf
2014-07-14 22:54:04 ----D---- C:\Windows\winsxs
2014-07-14 22:50:46 ----D---- C:\Windows\Prefetch
2014-07-14 22:50:41 ----D---- C:\Windows\system32\drivers
2014-07-14 22:49:57 ----D---- C:\Program Files\Common Files
2014-07-14 22:49:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-06-18 16:35:01 ----A---- C:\Windows\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-11-02 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-11-02 205320]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-11-01 871408]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-11-02 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-11-02 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-08 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-11-02 65264]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-11-02 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-11-02 84328]
R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [2008-07-11 145448]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S3 ali1uu3x;ali1uu3x; C:\Windows\system32\drivers\ali1uu3x.sys []
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-23 108800]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Users\Hukvaldy\AppData\Local\Temp\EverestDriver.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-23 206080]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\E:\VisualStudio\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aaLogger;ArchestrA Logger; C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe [2009-06-03 229446]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 avast! Antivirus;avast! Antivirus; I:\Avast\AvastSvc.exe [2013-11-02 50344]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CwIPCSvc;Control Web IPC; C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe [2013-08-29 64512]
R2 FS Service Control;FS Service Control; C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe [2009-07-03 32845]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 slssvc;Wonderware SuiteLink; C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe [2009-06-25 49152]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-01 116648]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-01 116648]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 svcprocess;SVCProcess; C:\Windows\svcproxy\svcprocess.exe []
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-01 1255736]
S3 WWNetDDE;Wonderware NetDDE Helper; C:\Program Files (x86)\Common Files\ArchestrA\wwnetdde.exe [2009-07-15 80688]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119543
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://www.stahuj.centrum.cz/utility_a_ ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve >Scan< a potom na >Clean< (smazat)
Proběhne skenováni a pak se objeví log, který sem vložte.
borek píše:při zmáčknutí tlačítka pro zapnutí počítače trvá asi 5 vteřin, než se na monitoru něco zobrazí.
Tohle spíše vypadá na nějaký hw problém (potíže s detekcí hardwaru biosem)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

borek
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 črc 2014 11:53

Re: Prosím o kontrolu logu

#3 Příspěvek od borek »

Tohle spíše vypadá na nějaký hw problém (potíže s detekcí hardwaru biosem)
Aha, tak na HW se pak podívám...

Zde je log z AdwCleaneru

Kód: Vybrat vše

# AdwCleaner v3.215 - Report created 16/07/2014 at 14:45:49
# Updated 09/07/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Hukvaldy - HUKVALDY-PC
# Running from : C:\Users\Hukvaldy\Desktop\adwcleaner_3.215.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Conduit
Folder Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\ProgramData\RegClean
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\DAEMON Tools Toolbar
Folder Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Program Files (x86)\SmartTweak
Folder Deleted : C:\Program Files (x86)\BS_Player_ControlBar
Folder Deleted : C:\Users\Hukvaldy\AppData\Local\Conduit
Folder Deleted : C:\Users\Hukvaldy\AppData\Local\Temp\BS_Player_ControlBar
Folder Deleted : C:\Users\Hukvaldy\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Hukvaldy\AppData\LocalLow\BS_Player_ControlBar
Folder Deleted : C:\Users\Hukvaldy\AppData\Roaming\NCH Software
Folder Deleted : C:\Users\Hukvaldy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
File Deleted : C:\END
File Deleted : C:\Users\Hukvaldy\Desktop\FixMyRegistry.lnk
File Deleted : C:\Windows\System32\Tasks\BackgroundContainer Startup Task

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [BackgroundContainerV2]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SpeedUpMyComputer]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT1750559
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1750559
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{055DD326-956C-4827-9467-A172509E81B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA3D2339-E172-4538-856A-3C0DE17435E2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{886401FD-7291-4324-ADD4-ABFE4A4F66FD}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\smarttweak
Key Deleted : HKCU\Software\Tbccint_HKLM
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\BackgroundContainer
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Software\BS_Player_ControlBar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\dt soft\daemon tools toolbar
Key Deleted : HKLM\Software\BS_Player_ControlBar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FixMyRegistry

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16720


-\\ Google Chrome v35.0.1916.153

[ File : C:\Users\Hukvaldy\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://www.traplice.cz/?page=websearch&srchtext={searchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}

*************************

AdwCleaner[R0].txt - [5536 octets] - [16/07/2014 14:44:32]
AdwCleaner[S0].txt - [5440 octets] - [16/07/2014 14:45:49]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5500 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119543
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

borek
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 črc 2014 11:53

Re: Prosím o kontrolu logu

#5 Příspěvek od borek »

log RSIT:

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Hukvaldy at 2014-07-16 22:37:19
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 2 GB (5%) free of 45 GB
Total RAM: 8190 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:37:21, on 16.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal

Running processes:
I:\SamsungKies\Kies\Kies.exe
I:\Avast\avastui.exe
I:\SamsungKies\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Hukvaldy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - I:\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - E:\VisualStudio\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - I:\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "I:\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] I:\SamsungKies\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [KiesPreload] I:\SamsungKies\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [KiesAirMessage] I:\SamsungKies\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [QIP2005] I:\QIP 2005 (portable)\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://I:\MSOffice\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\MSOffice\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: ArchestrA Logger (aaLogger) - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - I:\Avast\AvastSvc.exe
O23 - Service: Control Web IPC (CwIPCSvc) - Moravian Instruments® - C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FS Service Control - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Wonderware SuiteLink (slssvc) - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SVCProcess (svcprocess) - Unknown owner - C:\Windows\svcproxy\svcprocess.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wonderware NetDDE Helper (WWNetDDE) - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\wwnetdde.exe

--
End of file - 8239 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"I:\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe"
"I:\SamsungKies\Kies\Kies.exe" /preload
"I:\Avast\avastui.exe" /nogui
"I:\SamsungKies\Kies\KiesTrayAgent.exe" 
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --channel="1240.1.613476441\519237230" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --channel="1240.2.721648987\985523866" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-compositing --disable-accelerated-video-decode --disable-webrtc-hw-encoding --enable-software-compositing --disable-gpu-compositing --channel="1240.3.1397359154\811374295" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\Hukvaldy\AppData\Local\Google\Chrome\User Data\Default\Extensions\heildphpnddilhkemkielfhnkaagiabh\3.2_0\plugin/npBrowserSwitcher.dll" --lang=cs --channel="1240.6.659808739\117658594" /prefetch:-390060480
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1240.8.1142567022\1522086779" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1240.15.113464990\952530335" --use-gl=swiftshader --supports-dual-gpus=false --swiftshader-path="C:\Users\Hukvaldy\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159" --gpu-driver-bug-workarounds=1,15 --gpu-vendor-id=0x1002 --gpu-device-id=0x68f9 --gpu-driver-vendor=Microsoft --gpu-driver-version=6.1.7600.16385 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="1240.41.254871339\147972254" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --disable-databases --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group7 pct:10g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/FlashHardwareVideoDecode/HwVideo/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_93/UMA-Uniformity-Trial-10-Percent/group_09/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --disable-gpu-compositing --channel="1240.42.1943264816\2084740562" /prefetch:673131151

C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Hukvaldy\Downloads\RSITx64.exe" 

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - I:\Avast\aswWebRepIE64.dll [2013-11-02 1567016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-06-03 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-06-03 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - I:\Avast\aswWebRepIE.dll [2013-11-02 606544]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-29 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - E:\VisualStudio\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - I:\Avast\aswWebRepIE64.dll [2013-11-02 1567016]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - I:\Avast\aswWebRepIE.dll [2013-11-02 606544]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"KiesPreload"=I:\SamsungKies\Kies\Kies.exe [2014-02-14 1564992]
"KiesAirMessage"=I:\SamsungKies\Kies\KiesAirMessage.exe -startup []
"QIP2005"=I:\QIP 2005 (portable)\qip.exe [2009-08-13 3276288]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=I:\Avast\AvastUI.exe [2013-11-02 3567800]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"KiesTrayAgent"=I:\SamsungKies\Kies\KiesTrayAgent.exe [2014-02-14 311616]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KNet]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-16 14:44:54 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-07-16 14:44:29 ----D---- C:\AdwCleaner
2014-07-16 12:55:47 ----D---- C:\rsit
2014-07-16 12:55:47 ----D---- C:\Program Files\trend micro
2014-07-14 23:06:40 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-07-14 23:06:36 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-07-14 23:06:36 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-07-14 23:06:34 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-07-14 23:06:34 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-07-14 23:06:32 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-07-14 23:06:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-07-14 23:06:32 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-07-14 23:06:32 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-07-14 23:06:30 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-07-14 23:06:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-07-14 23:06:30 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-07-14 23:06:30 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-07-14 23:06:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-07-14 23:06:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-07-14 23:06:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-07-14 23:06:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-07-14 23:06:26 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-07-14 23:06:24 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-07-14 23:06:24 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-07-14 23:06:20 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-07-14 23:06:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-07-14 23:06:20 ----A---- C:\Windows\system32\xinput1_3.dll
2014-07-14 23:06:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-07-14 23:06:18 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-07-14 23:06:18 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-07-14 23:06:18 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-07-14 23:06:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-07-14 23:06:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-07-14 23:06:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-07-14 23:06:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-07-14 23:06:17 ----A---- C:\Windows\system32\d3dx10.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-07-14 23:06:15 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-07-14 23:06:15 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-07-14 23:06:15 ----A---- C:\Windows\system32\xinput1_2.dll
2014-07-14 23:06:15 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-07-14 23:06:14 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-07-14 23:06:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-07-14 23:06:14 ----A---- C:\Windows\system32\xinput1_1.dll
2014-07-14 23:06:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-07-14 23:06:13 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-07-14 23:06:13 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-07-14 23:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-07-14 23:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-07-14 23:06:09 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-07-14 23:06:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-07-14 23:06:08 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-07-14 23:06:08 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-07-14 23:06:08 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-07-14 23:06:08 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-07-14 23:06:07 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-07-14 23:06:07 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-07-14 23:06:06 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-07-14 23:06:06 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-07-14 23:02:49 ----SHD---- C:\Config.Msi
2014-07-14 23:02:39 ----D---- C:\Users\Hukvaldy\AppData\Roaming\ATI
2014-07-14 22:53:32 ----D---- C:\Users\Hukvaldy\AppData\Roaming\library_dir
2014-07-14 22:51:45 ----D---- C:\ProgramData\AMD
2014-07-14 22:50:29 ----D---- C:\Program Files\AMD
2014-07-14 22:49:57 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-07-14 22:49:40 ----D---- C:\ProgramData\Package Cache
2014-06-29 22:26:24 ----D---- C:\ProgramData\Oracle
2014-06-29 22:26:21 ----D---- C:\ProgramData\Sun
2014-06-29 22:26:12 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\java.exe
2014-06-29 22:26:01 ----D---- C:\Program Files (x86)\Java
2014-06-18 20:34:37 ----D---- C:\Users\Hukvaldy\AppData\Roaming\Microsoft FxCop

======List of files/folders modified in the last 1 month======

2014-07-16 22:37:20 ----D---- C:\Windows\Temp
2014-07-16 22:37:09 ----D---- C:\Windows\Prefetch
2014-07-16 21:40:32 ----D---- C:\Windows\system32\config
2014-07-16 21:28:56 ----SHD---- C:\System Volume Information
2014-07-16 14:47:12 ----D---- C:\Windows
2014-07-16 14:45:51 ----D---- C:\Windows\system32\Tasks
2014-07-16 14:45:50 ----RD---- C:\Program Files (x86)
2014-07-16 14:45:50 ----HD---- C:\ProgramData
2014-07-16 14:44:54 ----D---- C:\Windows\SysWOW64
2014-07-16 12:55:47 ----RD---- C:\Program Files
2014-07-14 23:33:15 ----D---- C:\Windows\system32\catroot
2014-07-14 23:32:28 ----SHD---- C:\Windows\Installer
2014-07-14 23:06:41 ----D---- C:\Windows\System32
2014-07-14 23:06:13 ----RSD---- C:\Windows\assembly
2014-07-14 23:06:11 ----D---- C:\Windows\Microsoft.NET
2014-07-14 23:05:25 ----D---- C:\Windows\Logs
2014-07-14 23:03:38 ----D---- C:\Program Files (x86)\Common Files
2014-07-14 23:02:44 ----D---- C:\Windows\system32\DriverStore
2014-07-14 23:02:44 ----D---- C:\Windows\system32\catroot2
2014-07-14 23:02:44 ----D---- C:\Windows\inf
2014-07-14 22:54:04 ----D---- C:\Windows\winsxs
2014-07-14 22:50:41 ----D---- C:\Windows\system32\drivers
2014-07-14 22:49:57 ----D---- C:\Program Files\Common Files
2014-07-14 22:49:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-06-18 16:35:01 ----A---- C:\Windows\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-11-02 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-11-02 205320]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-11-01 871408]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-11-02 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-11-02 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-08 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-11-02 65264]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-11-02 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-11-02 84328]
R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [2008-07-11 145448]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
S3 at6pbuv5;at6pbuv5; C:\Windows\system32\drivers\at6pbuv5.sys []
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-23 108800]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Users\Hukvaldy\AppData\Local\Temp\EverestDriver.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-23 206080]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\E:\VisualStudio\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aaLogger;ArchestrA Logger; C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe [2009-06-03 229446]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 avast! Antivirus;avast! Antivirus; I:\Avast\AvastSvc.exe [2013-11-02 50344]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CwIPCSvc;Control Web IPC; C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe [2013-08-29 64512]
R2 FS Service Control;FS Service Control; C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe [2009-07-03 32845]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 slssvc;Wonderware SuiteLink; C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe [2009-06-25 49152]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-01 116648]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-01 116648]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 svcprocess;SVCProcess; C:\Windows\svcproxy\svcprocess.exe []
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-01 1255736]
S3 WWNetDDE;Wonderware NetDDE Helper; C:\Program Files (x86)\Common Files\ArchestrA\wwnetdde.exe [2009-07-15 80688]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119543
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

:reg
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:services
AppMgmt

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

borek
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 črc 2014 11:53

Re: Prosím o kontrolu logu

#7 Příspěvek od borek »

Nový log RSIT:

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Hukvaldy at 2014-07-17 11:51:11
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 4 GB (10%) free of 45 GB
Total RAM: 8190 MB (84% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:51:14, on 17.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal

Running processes:
I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe
I:\SamsungKies\Kies\Kies.exe
I:\QIP 2005 (portable)\qip.exe
I:\Avast\avastui.exe
I:\SamsungKies\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Hukvaldy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - I:\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - E:\VisualStudio\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - I:\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "I:\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] I:\SamsungKies\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [OTM] "C:\Users\Hukvaldy\Desktop\OTM.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [KiesPreload] I:\SamsungKies\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [KiesAirMessage] I:\SamsungKies\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [QIP2005] I:\QIP 2005 (portable)\qip.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://I:\MSOffice\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\MSOffice\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: ArchestrA Logger (aaLogger) - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - I:\Avast\AvastSvc.exe
O23 - Service: Control Web IPC (CwIPCSvc) - Moravian Instruments® - C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FS Service Control - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Wonderware SuiteLink (slssvc) - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SVCProcess (svcprocess) - Unknown owner - C:\Windows\svcproxy\svcprocess.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wonderware NetDDE Helper (WWNetDDE) - Invensys Systems, Inc. - C:\Program Files (x86)\Common Files\ArchestrA\wwnetdde.exe

--
End of file - 7847 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k NetworkService
"I:\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
"C:\Windows\system32\Dwm.exe"
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
taskeng.exe {23BF17FF-946B-47B4-9EEC-BF4A17949B84}
taskeng.exe {984E3EE6-5EBC-41CA-BB97-BD27E23836A5}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe"
C:\Windows\system32\msiexec.exe /V
"C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
"C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
C:\Windows\system32\SearchIndexer.exe /Embedding
"I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe" -autorun
"I:\SamsungKies\Kies\Kies.exe" /preload
"I:\QIP 2005 (portable)\qip.exe" 
"I:\Avast\avastui.exe" /nogui
"I:\SamsungKies\Kies\KiesTrayAgent.exe" 
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Hukvaldy\Downloads\RSITx64.exe" 
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - I:\Avast\aswWebRepIE64.dll [2013-11-02 1567016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-06-03 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-06-03 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-06-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - I:\Avast\aswWebRepIE.dll [2013-11-02 606544]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-06-29 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDA57003-0068-4ed2-9D32-4D1EC707D94D}]
Microsoft Web Test Recorder 10.0 Helper - E:\VisualStudio\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2010-03-19 61360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - I:\Avast\aswWebRepIE64.dll [2013-11-02 1567016]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - I:\Avast\aswWebRepIE.dll [2013-11-02 606544]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=I:\Daemon Tools\nainstalovane\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"KiesPreload"=I:\SamsungKies\Kies\Kies.exe [2014-02-14 1564992]
"KiesAirMessage"=I:\SamsungKies\Kies\KiesAirMessage.exe -startup []
"QIP2005"=I:\QIP 2005 (portable)\qip.exe [2009-08-13 3276288]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=I:\Avast\AvastUI.exe [2013-11-02 3567800]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"KiesTrayAgent"=I:\SamsungKies\Kies\KiesTrayAgent.exe [2014-02-14 311616]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-05-07 256896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"OTM"=C:\Users\Hukvaldy\Desktop\OTM.exe [2014-07-17 522240]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KNet]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-07-17 11:42:15 ----D---- C:\_OTM
2014-07-16 14:44:54 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-07-16 14:44:29 ----D---- C:\AdwCleaner
2014-07-16 12:55:47 ----D---- C:\rsit
2014-07-16 12:55:47 ----D---- C:\Program Files\trend micro
2014-07-14 23:06:40 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-07-14 23:06:40 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-07-14 23:06:39 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-07-14 23:06:38 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-07-14 23:06:37 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-07-14 23:06:36 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-07-14 23:06:36 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-07-14 23:06:35 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-07-14 23:06:34 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-07-14 23:06:34 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-07-14 23:06:33 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-07-14 23:06:32 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-07-14 23:06:32 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-07-14 23:06:32 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-07-14 23:06:32 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-07-14 23:06:31 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-07-14 23:06:30 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-07-14 23:06:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-07-14 23:06:30 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-07-14 23:06:30 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-07-14 23:06:29 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-07-14 23:06:28 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-07-14 23:06:28 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-07-14 23:06:27 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-07-14 23:06:27 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-07-14 23:06:26 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-07-14 23:06:26 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-07-14 23:06:25 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-07-14 23:06:24 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-07-14 23:06:24 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-07-14 23:06:23 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-07-14 23:06:22 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-07-14 23:06:21 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-07-14 23:06:20 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-07-14 23:06:20 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-07-14 23:06:20 ----A---- C:\Windows\system32\xinput1_3.dll
2014-07-14 23:06:20 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-07-14 23:06:19 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-07-14 23:06:18 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-07-14 23:06:18 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-07-14 23:06:18 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-07-14 23:06:18 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-07-14 23:06:17 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-07-14 23:06:17 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-07-14 23:06:17 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-07-14 23:06:17 ----A---- C:\Windows\system32\d3dx10.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-07-14 23:06:16 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-07-14 23:06:16 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-07-14 23:06:15 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-07-14 23:06:15 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-07-14 23:06:15 ----A---- C:\Windows\system32\xinput1_2.dll
2014-07-14 23:06:15 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-07-14 23:06:14 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-07-14 23:06:14 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-07-14 23:06:14 ----A---- C:\Windows\system32\xinput1_1.dll
2014-07-14 23:06:14 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-07-14 23:06:13 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-07-14 23:06:13 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-07-14 23:06:10 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-07-14 23:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-07-14 23:06:09 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-07-14 23:06:09 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-07-14 23:06:09 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-07-14 23:06:08 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-07-14 23:06:08 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-07-14 23:06:08 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-07-14 23:06:08 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-07-14 23:06:07 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-07-14 23:06:07 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-07-14 23:06:06 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-07-14 23:06:06 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-07-14 23:02:49 ----SHD---- C:\Config.Msi
2014-07-14 23:02:39 ----D---- C:\Users\Hukvaldy\AppData\Roaming\ATI
2014-07-14 22:53:32 ----D---- C:\Users\Hukvaldy\AppData\Roaming\library_dir
2014-07-14 22:51:45 ----D---- C:\ProgramData\AMD
2014-07-14 22:50:29 ----D---- C:\Program Files\AMD
2014-07-14 22:49:57 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-07-14 22:49:40 ----D---- C:\ProgramData\Package Cache
2014-06-29 22:26:24 ----D---- C:\ProgramData\Oracle
2014-06-29 22:26:21 ----D---- C:\ProgramData\Sun
2014-06-29 22:26:12 ----A---- C:\Windows\SYSWOW64\javaws.exe
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\javaw.exe
2014-06-29 22:26:07 ----A---- C:\Windows\SYSWOW64\java.exe
2014-06-29 22:26:01 ----D---- C:\Program Files (x86)\Java
2014-06-18 20:34:37 ----D---- C:\Users\Hukvaldy\AppData\Roaming\Microsoft FxCop

======List of files/folders modified in the last 1 month======

2014-07-17 11:51:13 ----D---- C:\Windows\Temp
2014-07-17 11:49:49 ----D---- C:\Windows\Prefetch
2014-07-17 11:42:15 ----D---- C:\Windows\Tasks
2014-07-16 23:33:31 ----SHD---- C:\System Volume Information
2014-07-16 21:40:32 ----D---- C:\Windows\system32\config
2014-07-16 14:47:12 ----D---- C:\Windows
2014-07-16 14:45:51 ----D---- C:\Windows\system32\Tasks
2014-07-16 14:45:50 ----RD---- C:\Program Files (x86)
2014-07-16 14:45:50 ----HD---- C:\ProgramData
2014-07-16 14:44:54 ----D---- C:\Windows\SysWOW64
2014-07-16 12:55:47 ----RD---- C:\Program Files
2014-07-14 23:33:15 ----D---- C:\Windows\system32\catroot
2014-07-14 23:32:28 ----SHD---- C:\Windows\Installer
2014-07-14 23:06:41 ----D---- C:\Windows\System32
2014-07-14 23:06:13 ----RSD---- C:\Windows\assembly
2014-07-14 23:06:11 ----D---- C:\Windows\Microsoft.NET
2014-07-14 23:05:25 ----D---- C:\Windows\Logs
2014-07-14 23:03:38 ----D---- C:\Program Files (x86)\Common Files
2014-07-14 23:02:44 ----D---- C:\Windows\system32\DriverStore
2014-07-14 23:02:44 ----D---- C:\Windows\system32\catroot2
2014-07-14 23:02:44 ----D---- C:\Windows\inf
2014-07-14 22:54:04 ----D---- C:\Windows\winsxs
2014-07-14 22:50:41 ----D---- C:\Windows\system32\drivers
2014-07-14 22:49:57 ----D---- C:\Program Files\Common Files
2014-07-14 22:49:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-06-18 16:35:01 ----A---- C:\Windows\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-11-02 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-11-02 205320]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-11-01 871408]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-11-02 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-11-02 1032416]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-11-08 409832]
R1 aswTdi;aswTdi; \??\C:\Windows\system32\drivers\aswTdi.sys [2013-11-02 65264]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2010-11-20 59392]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2010-11-20 360832]
R2 aswFsBlk;aswFsBlk; \??\C:\Windows\system32\drivers\aswFsBlk.sys [2013-11-02 38984]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-11-02 84328]
R2 Sentinel64;Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [2008-07-11 145448]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2010-11-20 194944]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2010-11-20 95232]
S3 a87d4i55;a87d4i55; C:\Windows\system32\drivers\a87d4i55.sys []
S3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
S3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-23 108800]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Users\Hukvaldy\AppData\Local\Temp\EverestDriver.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-23 206080]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VSPerfDrv100;Performance Tools Driver 10.0; \??\E:\VisualStudio\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2011-01-18 68440]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aaLogger;ArchestrA Logger; C:\Program Files (x86)\Common Files\ArchestrA\aaLogger.exe [2009-06-03 229446]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-21 65432]
R2 avast! Antivirus;avast! Antivirus; I:\Avast\AvastSvc.exe [2013-11-02 50344]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CwIPCSvc;Control Web IPC; C:\Program Files (x86)\Moravian Instruments\Shared\cwsvc.exe [2013-08-29 64512]
R2 FS Service Control;FS Service Control; C:\Program Files (x86)\Common Files\ArchestrA\NTServApp.exe [2009-07-03 32845]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 slssvc;Wonderware SuiteLink; C:\Program Files (x86)\Common Files\ArchestrA\slssvc.exe [2009-06-25 49152]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-01 116648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-11-01 116648]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 svcprocess;SVCProcess; C:\Windows\svcproxy\svcprocess.exe []
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-11-01 1255736]
S3 WWNetDDE;Wonderware NetDDE Helper; C:\Program Files (x86)\Common Files\ArchestrA\wwnetdde.exe [2009-07-15 80688]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S4 SQLBrowser;SQL Server Browser; C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119543
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#8 Příspěvek od Rudy »

Smazáno. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Ještě doporučím přesun některých vyšich dat na jiné úložiště, příp. odinstalaci nepoužívaných programů. Volné místo na disku je teď 4GB, a to je dost málo. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

borek
Návštěvník
Návštěvník
Příspěvky: 5
Registrován: 16 črc 2014 11:53

Re: Prosím o kontrolu logu

#9 Příspěvek od borek »

Děkuju, start systému už je rychlejší, nechtěné programy zmizely.
Větší místo na systémovém disku asi bohužel udělat nezvládnu (max. na 5 GB po vyčištění plochy) - mám tam jen Windows a soubory Visual Studia, které se tam nahrály automaticky bez možnosti volby (samotná instalace VS je na jiném disku). Ale po vaší pomoci vzniklo něco přes 2 GB dalšího místa.

Ještě jednou děkuji a přeji pěkný den.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119543
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu

#10 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno