Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pravidelné odpojení od internetu - po restartu problém zmizí

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Pravidelné odpojení od internetu - po restartu problém zmizí

#1 Příspěvek od Nark »

Dobrý den mám problém s WIN 7 - poměrně nová instalace cca 2 měsíce - vždy po nějakém čase většinou přes noc se stane že se PC odpojí od internetu na stejném routeru je wifi a ta jede stabilně bez problému. Mohl bych poprosit o radu? díky

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#2 Příspěvek od Rudy »

Zdravím!
Jste si zcela jist, že wifi jede normálně, když v noci u PC nejste?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#3 Příspěvek od Nark »

Dobrý den jsem rano když příjdu k PC hlásí mi že sítový kabel byl odpojen když to na wifi se normálně připojím respektive neregistruji jakýkoli problém. Další problém je i pří samotném restartu kdy počítač není možné restartovat klasicky ale pouze tvrdým restartem. Díky za radu.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#4 Příspěvek od Rudy »

Takže PC spíš zatuhne, ne? Pokud je to možné, udělejte obnovu systému k datu, kdy korketně fungoval. Nen-li to možné, dejte log RSIT: http://forum.viry.cz/viewtopic.php?f=13&t=130786 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#5 Příspěvek od Nark »

Posílám RSIT Log - obnova již není možná.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Nark at 2014-09-13 09:04:46
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 47 GB (41%) free of 114 GB
Total RAM: 6135 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:04:51, on 13.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avpui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\klwtblfs.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Nark.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: CrossriderApp0061792 - {11111111-1111-1111-1111-110611171192} - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll (file missing)
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O2 - BHO: YTAHelperBHO - {FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} - C:\ProgramData\YTAHelper\YTAHelper.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [GoobzoYouTubeAccelerator] "C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Dropbox.lnk = Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 15.0.0 (AVP15.0.0) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: YouTubeAcceleratorService - Unknown owner - C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe (file missing)

--
End of file - 8832 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
atieclxx
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe" -r
C:\Windows\SysWOW64\srvany.exe
C:\Windows\KMService.exe
\??\C:\Windows\system32\conhost.exe "-115643996720671305451920197651-1020477790-1742177672-355903979-547468126953100752
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {6896D208-9E2D-4C81-BEF2-86C53300D09A}
C:\Windows\Explorer.EXE
taskeng.exe {E446ABA1-BEA2-45BA-8473-5EEAEB67E58A}
"C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe"
"C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avpui.exe" -hidden /prefetch:1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-3373383961-3809780321-2737733167-10001_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-3373383961-3809780321-2737733167-10001 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4804.0.127960648\1658220527" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x6798 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.200.1004.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="4804.2.1649195610\2083833974" /prefetch:673131151
C:\Windows\system32\cmd.exe /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe" --parent-window=0 chrome-extension://dbhjdbfgekjfcfkkfjjmlmojhbllhbho/ < \\.\pipe\chrome.nativeMessaging.in.baa76f54f3cbb09f > \\.\pipe\chrome.nativeMessaging.out.baa76f54f3cbb09f
\??\C:\Windows\system32\conhost.exe "-831563961-2097453307-763032473211262942951292706384545732811256061321791695010
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe" --parent-window=0 chrome-extension://dbhjdbfgekjfcfkkfjjmlmojhbllhbho/
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\klwtblfs.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="4804.8.957567639\512762114" /prefetch:673131151
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\Nark\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524

======Scheduled tasks folder======

C:\Windows\tasks\FBZ.job - C:\Users\Nark\AppData\Roaming\FBZ.exe /infocmdline=M5aUbG6VT9IqShZG0GNgRq5a4p2711w5/0mRi9BrL+2FQpegWAQJL9PqLzKg/vemPv29aRuyWvprMK8EQpDoz2RWJvouSkorrUJqhtkkiVyFkWGgwz+xAHy5iJDlJ49k4YBxpUejff+8Fz9Z8Xu0ytB5PNIYIDEJUyy5qpiixpiIbKBStUVLOdN4KNkWN0+fbG33ZYsd4Ig43AUjFDB6Q80sYGiO/g4zLyQLAjvFpi93MQ2sbzRKlWwaj1kbqIVZDUI8YZPDOiXbTKv6FT3yr/3UGlXKeF+NC96F/egZ4HrIMXag8vb20BBLkHCQYip9wrx2QNNqoNSRlOerCqDEmAh+ajw3NmyGabU/IdUv9+RuwMU/gl1hbNSb9lY/4YQFNAddZTFa8Ena1uf05Jd0ybDO+vDw8dko/Ga4elFaz2N0Kv6sRMINngY4ziEPEL5w5SrMjrZRk2Iv+gGTeKUhmHocxRdGu0kxvpn+QTEzumnhkbf1FPXjwfra7iJHp73B
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\JG.job - C:\Users\Nark\AppData\Roaming\JG.exe /infocmdline=gEMnc7Y18p3cndSWKQjXD0l+JlQrpSrldKEmp49w4TFFlx01zjOXm5i2aT4t6T+AG0hEwWr561twrPcNRFvld0vVnB+2ZyjrcPnoWk+Uw5ceflBxbXH7WH7rwfRdKM4PIznfio7mMN2jMTeXlhc2XOCLHjXc73w27j/MSDqo6mc19cW0TZs3agTWwKO6EId3wNuaAyjNuDmY47r1rffevS2ccPrxN8LoWY4rVaq8HDnsm0RoeGUmg6eYAQGl5h8t0YWf1PBZHkF1dGFxMCw4l7D9wayQ7bZq15jw1MJEQdC9lXhnRrlfpxsZoSlg34KJTodwuzRSXO1VVU5eaUgAdzdO2bJWf+cULEElZEqUZNfd5v11i1QtxZj1zBwjv1QmEBVBPx+x1RUEmzZINtooUqQB8LiPRCEpAXE+5MaafDbkO2QIPPvf1qMdjLPXDkgWavCNwYhWPVKrfXlI2u68mzBDRKVX7XAo+i3oE2uAvJmKXYKi3M6ukY/m2KJx3HVc
C:\Windows\tasks\RFMZOHQS.job - C:\Users\Nark\AppData\Roaming\RFMZOHQS.exe /infocmdline=diI9PvNhr1LaAIdlOeIiDmn7qsMhhl5BnI1A/D7k3/qiS2uZP7ENhJDXpiFMQJrPAkyvAgLSpRzEjXLBtGfiu3Wy7lymkEH0axHxxZslV5VwpLGOl6Vot0Brl3jiocXpkSUAPu4iTCrx7Hen/s19DqS64ynysXqUsaOxTo1L2DGhj+qXpXG6aH4JgPrhefJlmRUhiOQsfnCoosweQod5Z1JbuB9rDmRDLIoODDEsY389yAO64ZSOOIZDGQpwhhLdQ1e96G7JcQ2Gr6VbBosKPbMdqQDe/WZYqbSvA8mB4huqM+WaH/ghmA/vc2UpfSlZ8zM0vXy0PauxSnHGwVTb9bD9wUijNeYibkAqbkkqg5eQiu3gv6Gh89ExX3CoRL+u9uNkSGtnhpMw0AKkx5DDrqENTgl4GzSwzwDT+0ikf8oget6sWkW64fITO7ejf9iLtb32MiLqVMuwqJ17tL7rpbuK39MrYAzjKy8mVPdpYqsZ8Zwh37tMsRT6rkk1VmI6sZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\Windows\tasks\ZFCJW.job - C:\Users\Nark\AppData\Roaming\ZFCJW.exe /infocmdline=DD+CmloxS8+aOgzeBsP7VbWudq3QVUOeN1g4RGacyS3X+/XsKMiFDdOVgD0EigL1MKgAss3glJ1bif+TQQFPcneF8jXPcPSnu147dil9YmcmplQHmOdcqRdVnuykYhdV5aOQnUw/exAvqkv+M14h/kEhKMa5pbDvOPxPI80WcWwXl4pw9D/1H+j4n+a+jRNB9lUBvKcoMop2792fUuep3g87NoQip3Bm51bsftKcHbpIiPYxq+RjqZkq6H3FcKKnYE3g5i8xFCDtv6WN5PHASvYdIMQZEAN0FkO+G4e4tSvY5CFPOcKqzKlUxzNqJUoG7qarxXklkKwc9X+y8XK/t1F4pnX1Crc0obF3XZX9En9lcAm/ZPPHbixXX63XUQcc2t+1VlpRJqDO2imCUf0rmXakQhcdGYIjzgZucKoCROI/GbhaqjC0iHAJPHzOXbKlQnnmx1XHygz8C5Ozz3SyzGog9XSEKgPAI3lPCp74RyAOHhjhXONj+FyjFmSlrSPV

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171192}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20 878784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-25 1419936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20 1109696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper64.dll [2014-08-10 498024]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171192}]
HD-V1.9 - C:\Program Files (x86)\HD-V1.9\HD-V1.9-bho.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20 709312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-25 1176736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20 891072]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]
YTAHelper - C:\ProgramData\YTAHelper\YTAHelper.dll [2014-08-10 416616]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ACPW07EN"=C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [2014-03-18 1813832]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"=C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe /startup []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-07-09 767200]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

C:\Users\Nark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=28

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-13 09:04:46 ----D---- C:\rsit
2014-09-13 09:04:46 ----D---- C:\Program Files\trend micro
2014-09-11 22:46:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-11 22:46:44 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 22:46:43 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 22:46:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-11 22:46:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 22:46:39 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-11 22:46:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 22:46:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 22:46:38 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-11 22:46:37 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 22:46:36 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-11 22:46:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-11 22:46:36 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 22:46:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-11 22:46:34 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-11 22:46:34 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 22:42:26 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-11 22:42:26 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 15:51:18 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-11 15:51:18 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 15:50:57 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-11 15:50:57 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-11 15:50:54 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 15:50:54 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 15:50:52 ----A---- C:\Windows\system32\aepdu.dll
2014-09-11 15:50:52 ----A---- C:\Windows\system32\aeinv.dll
2014-09-04 08:04:20 ----A---- C:\Windows\system32\klfphc.dll
2014-09-04 08:04:13 ----D---- C:\Windows\ELAMBKUP
2014-09-04 08:04:12 ----D---- C:\ProgramData\Kaspersky Lab
2014-09-04 08:04:12 ----D---- C:\Program Files (x86)\Kaspersky Lab
2014-09-04 08:04:09 ----A---- C:\Windows\system32\drivers\klif.sys
2014-09-04 08:04:09 ----A---- C:\Windows\system32\drivers\klflt.sys
2014-09-04 08:04:08 ----A---- C:\Windows\system32\drivers\klhk.sys
2014-09-02 19:13:35 ----A---- C:\Windows\ntbtlog.txt
2014-09-02 19:06:13 ----D---- C:\Windows\system32\appmgmt
2014-09-02 09:38:45 ----D---- C:\ProgramData\YTAHelper
2014-09-02 09:38:43 ----AD---- C:\ProgramData\TEMP
2014-09-02 09:35:28 ----D---- C:\Program Files (x86)\globalUpdate
2014-09-02 08:27:24 ----A---- C:\Windows\SYSWOW64\srvany.exe
2014-09-02 08:27:24 ----A---- C:\Windows\KMService.exe
2014-08-29 18:56:53 ----D---- C:\Users\Nark\AppData\Roaming\Battle.net
2014-08-29 18:56:45 ----D---- C:\Program Files (x86)\Battle.net
2014-08-27 23:44:06 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-27 23:44:06 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 23:44:06 ----A---- C:\Windows\system32\gdi32.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-15 03:00:44 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-15 03:00:44 ----A---- C:\Windows\system32\icardres.dll
2014-08-15 03:00:44 ----A---- C:\Windows\system32\icardagt.exe
2014-08-15 03:00:42 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-15 03:00:42 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-14 05:10:35 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-14 05:10:35 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-14 05:10:34 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-14 05:10:34 ----A---- C:\Windows\system32\tzres.dll
2014-08-14 05:10:33 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-14 05:10:33 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-14 05:10:33 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-14 05:10:33 ----A---- C:\Windows\system32\msihnd.dll
2014-08-14 05:10:33 ----A---- C:\Windows\system32\msi.dll
2014-08-14 05:10:33 ----A---- C:\Windows\system32\consent.exe
2014-08-14 05:10:33 ----A---- C:\Windows\system32\authui.dll
2014-08-14 05:10:32 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-14 05:10:31 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-14 05:10:31 ----A---- C:\Windows\system32\shell32.dll
2014-08-14 05:10:02 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-14 05:10:02 ----A---- C:\Windows\system32\rpcrt4.dll

======List of files/folders modified in the last 1 month======

2014-09-13 09:04:49 ----D---- C:\Windows\Temp
2014-09-13 09:04:46 ----RD---- C:\Program Files
2014-09-13 09:01:53 ----D---- C:\Users\Nark\AppData\Roaming\Dropbox
2014-09-13 09:01:39 ----SHD---- C:\System Volume Information
2014-09-12 14:17:40 ----D---- C:\Windows\system32\config
2014-09-12 13:57:21 ----D---- C:\Windows\rescache
2014-09-12 13:55:21 ----D---- C:\Windows\Microsoft.NET
2014-09-12 13:47:51 ----RSD---- C:\Windows\assembly
2014-09-12 12:46:30 ----D---- C:\Windows\System32
2014-09-12 12:46:30 ----D---- C:\Windows\inf
2014-09-12 12:46:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-12 12:41:28 ----D---- C:\Windows\winsxs
2014-09-12 12:40:42 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-12 12:40:42 ----D---- C:\Windows\SysWOW64
2014-09-12 12:40:42 ----D---- C:\Windows\system32\en-US
2014-09-12 12:40:42 ----D---- C:\Program Files\Internet Explorer
2014-09-12 12:40:42 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-11 22:48:29 ----SHD---- C:\Windows\Installer
2014-09-11 22:46:54 ----D---- C:\Windows\system32\catroot2
2014-09-11 22:46:54 ----D---- C:\Windows\system32\catroot
2014-09-11 22:46:22 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 22:45:47 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-11 22:45:08 ----D---- C:\Windows\system32\MRT
2014-09-11 22:42:48 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 22:42:25 ----SD---- C:\Windows\system32\CompatTel
2014-09-10 22:37:32 ----D---- C:\Windows\system32\NDF
2014-09-10 08:20:19 ----D---- C:\Users\Nark\AppData\Roaming\uTorrent
2014-09-04 17:02:00 ----D---- C:\Windows\system32\wdi
2014-09-04 16:57:59 ----D---- C:\Windows\system32\Tasks
2014-09-04 08:11:46 ----D---- C:\ProgramData\Skype
2014-09-04 08:04:57 ----HD---- C:\ProgramData
2014-09-04 08:04:20 ----D---- C:\Windows\system32\drivers
2014-09-04 08:04:19 ----D---- C:\Windows\system32\DriverStore
2014-09-04 08:04:13 ----D---- C:\Windows
2014-09-04 08:04:12 ----RD---- C:\Program Files (x86)
2014-09-02 09:43:24 ----D---- C:\Windows\Tasks
2014-09-02 09:41:21 ----HD---- C:\Windows\system32\GroupPolicy
2014-09-02 09:41:21 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-09-02 09:36:10 ----SD---- C:\ProgramData\Microsoft
2014-09-02 09:35:10 ----D---- C:\Program Files (x86)\Common Files
2014-08-19 17:51:07 ----D---- C:\Windows\system32\drivers\UMDF
2014-08-15 03:20:54 ----RSD---- C:\Windows\Fonts
2014-08-15 03:20:54 ----D---- C:\Windows\ehome
2014-08-15 03:20:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-15 03:20:53 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 03:20:53 ----D---- C:\Windows\PolicyDefinitions

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2014-02-20 457824]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 klhk;klhk; C:\Windows\system32\DRIVERS\klhk.sys [2014-04-10 243808]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2014-07-25 792128]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2014-02-25 30304]
R1 klpd;klpd; C:\Windows\system32\DRIVERS\klpd.sys [2013-04-12 15456]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2014-03-25 55904]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2014-03-26 179296]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-07-09 15950848]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-07-09 557056]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 klflt;Kaspersky Lab Kernel DLL; C:\Windows\system32\DRIVERS\klflt.sys [2014-07-25 140352]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2014-03-28 28768]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-08-08 29280]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S2 MLPTDR_Q;MLPTDR_Q; \??\C:\Windows\system32\ []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;Ovladač WinUSB; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-07-09 239616]
R2 AVP15.0.0;Služba Kaspersky Anti-Virus 15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe [2014-04-20 233552]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2010-06-16 8192]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-02 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S2 YouTubeAcceleratorService;YouTubeAcceleratorService; C:\PROGRA~2\YOUTUB~1\YouTubeAcceleratorService.exe -start -scm []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-09-02 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-07-30 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#6 Příspěvek od Rudy »

Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#7 Příspěvek od Nark »

tady je log:

# AdwCleaner v3.310 - Report created 13/09/2014 at 20:25:09
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Nark - NARK-PC
# Running from : C:\Users\Nark\Desktop\adwcleaner_3.310.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : YouTubeAcceleratorService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\YTAHelper
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Users\Nark\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Nark\AppData\LocalLow\Goobzo
Folder Deleted : C:\Users\Public\Documents\Goobzo
Folder Deleted : C:\Users\Public\Documents\ShopperPro
Folder Deleted : C:\Users\Public\Documents\YTAHelper
File Deleted : C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [GoobzoYouTubeAccelerator]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061792.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061792.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061792.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0061792.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171192}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172292}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175592}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176692}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{03771AEF-400D-4A13-B712-25878EC4A3F5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644174492}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171192}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171192}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611171192}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611171192}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622172292}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655175592}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666176692}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611171192}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\Goobzo
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280


-\\ Google Chrome v37.0.2062.103

[ File : C:\Users\Nark\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=357&r=2013/02/24&hid=2701123189&lg=EN&cc=CZ
Deleted [Search Provider] : hxxp://www.search.ask.com/web?p2=%5EBBK%5EOSJ0 ... earchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://mystart.incredibar.com/mb201/?loc=IB_DS&search={searchTerms}&a=6R8RonOYBN&i=26
Deleted [Search Provider] : hxxp://wordpress.org/search/do-search.php?search={searchTerms}
Deleted [Search Provider] : hxxp://mystart.incredibar.com/mb203?a=6R8RonOYBN&search={searchTerms}
Deleted [Startup_urls] : hxxp://search.conduit.com/?ctid=CT2801948&SearchSource=48
Deleted [Startup_urls] : hxxp://mystart.incredibar.com/mb201?a=6R8RonOYBN&i=26
Deleted [Startup_urls] : hxxp://mystart.incredibar.com/mb203?a=6R8RonOYBN&i=26
Deleted [Startup_urls] : hxxp://websearch.the-searcheng.info/?pid=964&r=2013/09/05&hid=6652891530998143497&lg=EN&cc=CZ&unqvl=35
Deleted [Startup_urls] : hxxp://search.gboxapp.com/

*************************

AdwCleaner[R0].txt - [11111 octets] - [13/09/2014 20:24:15]
AdwCleaner[S0].txt - [10974 octets] - [13/09/2014 20:25:09]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11035 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#8 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#9 Příspěvek od Nark »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Nark at 2014-09-14 08:28:34
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 64 GB (56%) free of 114 GB
Total RAM: 6135 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:28:37, on 14.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avpui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\klwtblfs.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Nark\AppData\Roaming\uTorrent\utorrent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Nark.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Dropbox.lnk = Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 15.0.0 (AVP15.0.0) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8150 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe" -r
C:\Windows\SysWOW64\srvany.exe
C:\Windows\KMService.exe
\??\C:\Windows\system32\conhost.exe "-1618512621739053474-656647091-282448567359933600209616209-390956565-1362583859
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe"
"C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avpui.exe" -hidden /prefetch:1
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3892.2.514122733\938068085" /prefetch:673131151
C:\Windows\system32\cmd.exe /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe" --parent-window=0 chrome-extension://dbhjdbfgekjfcfkkfjjmlmojhbllhbho/ < \\.\pipe\chrome.nativeMessaging.in.3f9ed6d816c1b73 > \\.\pipe\chrome.nativeMessaging.out.3f9ed6d816c1b73
\??\C:\Windows\system32\conhost.exe "-1764250416-1664516580-2090706798-17076860101411704772301135350278405668-255674064
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe" --parent-window=0 chrome-extension://dbhjdbfgekjfcfkkfjjmlmojhbllhbho/
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\klwtblfs.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3892.5.956337163\1400071326" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="3892.7.1385719057\2046487947" /prefetch:673131151
"C:\Users\Nark\AppData\Roaming\uTorrent\utorrent.exe" "magnet:?xt=urn:btih:80d198f87dbe4bd73ac88194ad6011bcc751af66&dn=Edge.of.Tomorrow.2014.1080p.WEB-DL.DD5.1.H264-RARBG&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80&tr=udp%3A%2F%2Ftracker.publicbt.com%3A80&tr=udp%3A%2F%2Ftracker.istole.it%3A6969&tr=udp%3A%2F%2Fopen.demonii.com%3A1337"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3892.38.1465244697\965786299" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,39 --gpu-vendor-id=0x1002 --gpu-device-id=0x6798 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.200.1004.0 --ignored=" --type=renderer " /prefetch:822062411
C:\Windows\servicing\TrustedInstaller.exe

C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Nark\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\FBZ.job - C:\Users\Nark\AppData\Roaming\FBZ.exe /infocmdline=M5aUbG6VT9IqShZG0GNgRq5a4p2711w5/0mRi9BrL+2FQpegWAQJL9PqLzKg/vemPv29aRuyWvprMK8EQpDoz2RWJvouSkorrUJqhtkkiVyFkWGgwz+xAHy5iJDlJ49k4YBxpUejff+8Fz9Z8Xu0ytB5PNIYIDEJUyy5qpiixpiIbKBStUVLOdN4KNkWN0+fbG33ZYsd4Ig43AUjFDB6Q80sYGiO/g4zLyQLAjvFpi93MQ2sbzRKlWwaj1kbqIVZDUI8YZPDOiXbTKv6FT3yr/3UGlXKeF+NC96F/egZ4HrIMXag8vb20BBLkHCQYip9wrx2QNNqoNSRlOerCqDEmAh+ajw3NmyGabU/IdUv9+RuwMU/gl1hbNSb9lY/4YQFNAddZTFa8Ena1uf05Jd0ybDO+vDw8dko/Ga4elFaz2N0Kv6sRMINngY4ziEPEL5w5SrMjrZRk2Iv+gGTeKUhmHocxRdGu0kxvpn+QTEzumnhkbf1FPXjwfra7iJHp73B
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\JG.job - C:\Users\Nark\AppData\Roaming\JG.exe /infocmdline=gEMnc7Y18p3cndSWKQjXD0l+JlQrpSrldKEmp49w4TFFlx01zjOXm5i2aT4t6T+AG0hEwWr561twrPcNRFvld0vVnB+2ZyjrcPnoWk+Uw5ceflBxbXH7WH7rwfRdKM4PIznfio7mMN2jMTeXlhc2XOCLHjXc73w27j/MSDqo6mc19cW0TZs3agTWwKO6EId3wNuaAyjNuDmY47r1rffevS2ccPrxN8LoWY4rVaq8HDnsm0RoeGUmg6eYAQGl5h8t0YWf1PBZHkF1dGFxMCw4l7D9wayQ7bZq15jw1MJEQdC9lXhnRrlfpxsZoSlg34KJTodwuzRSXO1VVU5eaUgAdzdO2bJWf+cULEElZEqUZNfd5v11i1QtxZj1zBwjv1QmEBVBPx+x1RUEmzZINtooUqQB8LiPRCEpAXE+5MaafDbkO2QIPPvf1qMdjLPXDkgWavCNwYhWPVKrfXlI2u68mzBDRKVX7XAo+i3oE2uAvJmKXYKi3M6ukY/m2KJx3HVc
C:\Windows\tasks\RFMZOHQS.job - C:\Users\Nark\AppData\Roaming\RFMZOHQS.exe /infocmdline=diI9PvNhr1LaAIdlOeIiDmn7qsMhhl5BnI1A/D7k3/qiS2uZP7ENhJDXpiFMQJrPAkyvAgLSpRzEjXLBtGfiu3Wy7lymkEH0axHxxZslV5VwpLGOl6Vot0Brl3jiocXpkSUAPu4iTCrx7Hen/s19DqS64ynysXqUsaOxTo1L2DGhj+qXpXG6aH4JgPrhefJlmRUhiOQsfnCoosweQod5Z1JbuB9rDmRDLIoODDEsY389yAO64ZSOOIZDGQpwhhLdQ1e96G7JcQ2Gr6VbBosKPbMdqQDe/WZYqbSvA8mB4huqM+WaH/ghmA/vc2UpfSlZ8zM0vXy0PauxSnHGwVTb9bD9wUijNeYibkAqbkkqg5eQiu3gv6Gh89ExX3CoRL+u9uNkSGtnhpMw0AKkx5DDrqENTgl4GzSwzwDT+0ikf8oget6sWkW64fITO7ejf9iLtb32MiLqVMuwqJ17tL7rpbuK39MrYAzjKy8mVPdpYqsZ8Zwh37tMsRT6rkk1VmI6sZkLutK+wRg09MBTdV6esMVJAnVrHQ18v7KwLAnjHLQ6qygpZwcc4FRKmt288xLM80NNLghoNjL7A5LleUPNwEK91s0rHvKmd83SdnKb64/+DklNpVBvfiP1S7ufH9ZR3T06y0c1dfgiSyZsKto8dEXbr5D/fQu+D2xz3adWKyg=
C:\Windows\tasks\ZFCJW.job - C:\Users\Nark\AppData\Roaming\ZFCJW.exe /infocmdline=DD+CmloxS8+aOgzeBsP7VbWudq3QVUOeN1g4RGacyS3X+/XsKMiFDdOVgD0EigL1MKgAss3glJ1bif+TQQFPcneF8jXPcPSnu147dil9YmcmplQHmOdcqRdVnuykYhdV5aOQnUw/exAvqkv+M14h/kEhKMa5pbDvOPxPI80WcWwXl4pw9D/1H+j4n+a+jRNB9lUBvKcoMop2792fUuep3g87NoQip3Bm51bsftKcHbpIiPYxq+RjqZkq6H3FcKKnYE3g5i8xFCDtv6WN5PHASvYdIMQZEAN0FkO+G4e4tSvY5CFPOcKqzKlUxzNqJUoG7qarxXklkKwc9X+y8XK/t1F4pnX1Crc0obF3XZX9En9lcAm/ZPPHbixXX63XUQcc2t+1VlpRJqDO2imCUf0rmXakQhcdGYIjzgZucKoCROI/GbhaqjC0iHAJPHzOXbKlQnnmx1XHygz8C5Ozz3SyzGog9XSEKgPAI3lPCp74RyAOHhjhXONj+FyjFmSlrSPV

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20 878784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-25 1419936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20 1109696]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20 709312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-25 1176736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20 891072]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ACPW07EN"=C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [2014-03-18 1813832]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-07-09 767200]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

C:\Users\Nark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=28

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-13 20:24:46 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-09-13 20:24:14 ----D---- C:\AdwCleaner
2014-09-13 09:04:46 ----D---- C:\rsit
2014-09-13 09:04:46 ----D---- C:\Program Files\trend micro
2014-09-11 22:46:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-11 22:46:44 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 22:46:43 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 22:46:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-11 22:46:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 22:46:39 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-11 22:46:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 22:46:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 22:46:38 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-11 22:46:37 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 22:46:36 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-11 22:46:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-11 22:46:36 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 22:46:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-11 22:46:34 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-11 22:46:34 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 22:42:26 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-11 22:42:26 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 15:51:18 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-11 15:51:18 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 15:50:57 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-11 15:50:57 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-11 15:50:54 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 15:50:54 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 15:50:52 ----A---- C:\Windows\system32\aepdu.dll
2014-09-11 15:50:52 ----A---- C:\Windows\system32\aeinv.dll
2014-09-04 08:04:20 ----A---- C:\Windows\system32\klfphc.dll
2014-09-04 08:04:13 ----D---- C:\Windows\ELAMBKUP
2014-09-04 08:04:12 ----D---- C:\ProgramData\Kaspersky Lab
2014-09-04 08:04:12 ----D---- C:\Program Files (x86)\Kaspersky Lab
2014-09-04 08:04:09 ----A---- C:\Windows\system32\drivers\klif.sys
2014-09-04 08:04:09 ----A---- C:\Windows\system32\drivers\klflt.sys
2014-09-04 08:04:08 ----A---- C:\Windows\system32\drivers\klhk.sys
2014-09-02 19:13:35 ----A---- C:\Windows\ntbtlog.txt
2014-09-02 19:06:13 ----D---- C:\Windows\system32\appmgmt
2014-09-02 09:38:43 ----AD---- C:\ProgramData\TEMP
2014-09-02 08:27:24 ----A---- C:\Windows\SYSWOW64\srvany.exe
2014-09-02 08:27:24 ----A---- C:\Windows\KMService.exe
2014-08-29 18:56:53 ----D---- C:\Users\Nark\AppData\Roaming\Battle.net
2014-08-29 18:56:45 ----D---- C:\Program Files (x86)\Battle.net
2014-08-27 23:44:06 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-27 23:44:06 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 23:44:06 ----A---- C:\Windows\system32\gdi32.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-15 03:00:44 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-15 03:00:44 ----A---- C:\Windows\system32\icardres.dll
2014-08-15 03:00:44 ----A---- C:\Windows\system32\icardagt.exe
2014-08-15 03:00:42 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-15 03:00:42 ----A---- C:\Windows\system32\TsWpfWrp.exe

======List of files/folders modified in the last 1 month======

2014-09-14 08:28:36 ----D---- C:\Windows\Temp
2014-09-14 08:28:34 ----D---- C:\Users\Nark\AppData\Roaming\uTorrent
2014-09-14 08:18:42 ----D---- C:\Windows\system32\config
2014-09-13 20:30:55 ----D---- C:\Windows\System32
2014-09-13 20:30:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-13 20:30:54 ----D---- C:\Windows\inf
2014-09-13 20:26:43 ----D---- C:\Users\Nark\AppData\Roaming\Dropbox
2014-09-13 20:26:32 ----SHD---- C:\System Volume Information
2014-09-13 20:25:10 ----D---- C:\Windows\Tasks
2014-09-13 20:25:10 ----D---- C:\Windows\system32\Tasks
2014-09-13 20:25:09 ----RD---- C:\Program Files (x86)
2014-09-13 20:25:09 ----HD---- C:\ProgramData
2014-09-13 20:24:46 ----D---- C:\Windows\SysWOW64
2014-09-13 09:04:46 ----RD---- C:\Program Files
2014-09-12 13:57:21 ----D---- C:\Windows\rescache
2014-09-12 13:55:21 ----D---- C:\Windows\Microsoft.NET
2014-09-12 13:47:51 ----RSD---- C:\Windows\assembly
2014-09-12 12:41:28 ----D---- C:\Windows\winsxs
2014-09-12 12:40:42 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-12 12:40:42 ----D---- C:\Windows\system32\en-US
2014-09-12 12:40:42 ----D---- C:\Program Files\Internet Explorer
2014-09-12 12:40:42 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-11 22:48:29 ----SHD---- C:\Windows\Installer
2014-09-11 22:46:54 ----D---- C:\Windows\system32\catroot2
2014-09-11 22:46:54 ----D---- C:\Windows\system32\catroot
2014-09-11 22:46:22 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 22:45:47 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-11 22:45:08 ----D---- C:\Windows\system32\MRT
2014-09-11 22:42:48 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 22:42:25 ----SD---- C:\Windows\system32\CompatTel
2014-09-10 22:37:32 ----D---- C:\Windows\system32\NDF
2014-09-04 17:02:00 ----D---- C:\Windows\system32\wdi
2014-09-04 08:11:46 ----D---- C:\ProgramData\Skype
2014-09-04 08:04:20 ----D---- C:\Windows\system32\drivers
2014-09-04 08:04:19 ----D---- C:\Windows\system32\DriverStore
2014-09-04 08:04:13 ----D---- C:\Windows
2014-09-02 09:41:21 ----HD---- C:\Windows\system32\GroupPolicy
2014-09-02 09:41:21 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-09-02 09:36:10 ----SD---- C:\ProgramData\Microsoft
2014-09-02 09:35:10 ----D---- C:\Program Files (x86)\Common Files
2014-08-19 17:51:07 ----D---- C:\Windows\system32\drivers\UMDF
2014-08-15 03:20:54 ----RSD---- C:\Windows\Fonts
2014-08-15 03:20:54 ----D---- C:\Windows\ehome
2014-08-15 03:20:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-15 03:20:53 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 03:20:53 ----D---- C:\Windows\PolicyDefinitions

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2014-02-20 457824]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 klhk;klhk; C:\Windows\system32\DRIVERS\klhk.sys [2014-04-10 243808]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2014-07-25 792128]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2014-02-25 30304]
R1 klpd;klpd; C:\Windows\system32\DRIVERS\klpd.sys [2013-04-12 15456]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2014-03-25 55904]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2014-03-26 179296]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-07-09 15950848]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-07-09 557056]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 klflt;Kaspersky Lab Kernel DLL; C:\Windows\system32\DRIVERS\klflt.sys [2014-07-25 140352]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2014-03-28 28768]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-08-08 29280]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S2 MLPTDR_Q;MLPTDR_Q; \??\C:\Windows\system32\ []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;Ovladač WinUSB; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-07-09 239616]
R2 AVP15.0.0;Služba Kaspersky Anti-Virus 15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe [2014-04-20 233552]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2010-06-16 8192]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-07-30 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#10 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\FBZ.job
C:\Windows\tasks\RFMZOHQS.job

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#11 Příspěvek od Nark »

tady je:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Nark at 2014-09-14 15:48:43
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 64 GB (56%) free of 114 GB
Total RAM: 6135 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:48:45, on 14.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avpui.exe
C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Reader_sl.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\cmd.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\klwtblfs.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Nark.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: ContentBlockerBrowserHelperObject - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll
O2 - BHO: VirtualKeyboardBrowserHelperObject - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O4 - Startup: Dropbox.lnk = Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: Virtuální klávesnice - {0C4CC089-D306-440D-9772-464E226F6539} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll
O9 - Extra button: Kontrola adres URL - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 15.0.0 (AVP15.0.0) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8100 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
atieclxx
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe" -r
C:\Windows\SysWOW64\srvany.exe
C:\Windows\KMService.exe
\??\C:\Windows\system32\conhost.exe "668792306301485183900474310-1761495508-48641705-1752053273-654923672310360383
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
taskeng.exe {246AFF0E-D1D6-4A68-A1A6-68E22ADF0ADB}
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
taskeng.exe {22C22BDF-994B-4DC2-A3B0-895885CEB6DE}
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avpui.exe" -hidden /prefetch:1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe"
"C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Reader_sl.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9223
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4320.0.1837884318\1553366145" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17 --gpu-vendor-id=0x1002 --gpu-device-id=0x6798 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.200.1004.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="4320.2.247588952\938966589" /prefetch:673131151
C:\Windows\system32\cmd.exe /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe" --parent-window=0 chrome-extension://dbhjdbfgekjfcfkkfjjmlmojhbllhbho/ < \\.\pipe\chrome.nativeMessaging.in.7e3be9f4ab62362d > \\.\pipe\chrome.nativeMessaging.out.7e3be9f4ab62362d
\??\C:\Windows\system32\conhost.exe "19586868191079441929-412454847-550547790-525851362138342543-13655278551478303444
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\plugin-nm-server.exe" --parent-window=0 chrome-extension://dbhjdbfgekjfcfkkfjjmlmojhbllhbho/
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\klwtblfs.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/ChromeSuggestions/Most Likely with Kodachrome/EmbeddedSearch/Group8 pct:10h stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/GoogleNow/Enable/OmniboxBundledExperimentV1/StandardR4/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/SDCH/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/no_enforcement/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --channel="4320.5.121463610\1487825795" /prefetch:673131151
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Nark\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\JG.job - C:\Users\Nark\AppData\Roaming\JG.exe /infocmdline=gEMnc7Y18p3cndSWKQjXD0l+JlQrpSrldKEmp49w4TFFlx01zjOXm5i2aT4t6T+AG0hEwWr561twrPcNRFvld0vVnB+2ZyjrcPnoWk+Uw5ceflBxbXH7WH7rwfRdKM4PIznfio7mMN2jMTeXlhc2XOCLHjXc73w27j/MSDqo6mc19cW0TZs3agTWwKO6EId3wNuaAyjNuDmY47r1rffevS2ccPrxN8LoWY4rVaq8HDnsm0RoeGUmg6eYAQGl5h8t0YWf1PBZHkF1dGFxMCw4l7D9wayQ7bZq15jw1MJEQdC9lXhnRrlfpxsZoSlg34KJTodwuzRSXO1VVU5eaUgAdzdO2bJWf+cULEElZEqUZNfd5v11i1QtxZj1zBwjv1QmEBVBPx+x1RUEmzZINtooUqQB8LiPRCEpAXE+5MaafDbkO2QIPPvf1qMdjLPXDkgWavCNwYhWPVKrfXlI2u68mzBDRKVX7XAo+i3oE2uAvJmKXYKi3M6ukY/m2KJx3HVc
C:\Windows\tasks\ZFCJW.job - C:\Users\Nark\AppData\Roaming\ZFCJW.exe /infocmdline=DD+CmloxS8+aOgzeBsP7VbWudq3QVUOeN1g4RGacyS3X+/XsKMiFDdOVgD0EigL1MKgAss3glJ1bif+TQQFPcneF8jXPcPSnu147dil9YmcmplQHmOdcqRdVnuykYhdV5aOQnUw/exAvqkv+M14h/kEhKMa5pbDvOPxPI80WcWwXl4pw9D/1H+j4n+a+jRNB9lUBvKcoMop2792fUuep3g87NoQip3Bm51bsftKcHbpIiPYxq+RjqZkq6H3FcKKnYE3g5i8xFCDtv6WN5PHASvYdIMQZEAN0FkO+G4e4tSvY5CFPOcKqzKlUxzNqJUoG7qarxXklkKwc9X+y8XK/t1F4pnX1Crc0obF3XZX9En9lcAm/ZPPHbixXX63XUQcc2t+1VlpRJqDO2imCUf0rmXakQhcdGYIjzgZucKoCROI/GbhaqjC0iHAJPHzOXbKlQnnmx1XHygz8C5Ozz3SyzGog9XSEKgPAI3lPCp74RyAOHhjhXONj+FyjFmSlrSPV

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20 878784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-25 1419936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20 1109696]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}]
Content Blocker Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-04-20 709312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{73455575-E40C-433C-9784-C78DC7761455}]
Virtual Keyboard Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-07-25 1176736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
URL Advisor Plugin - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-04-20 891072]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ACPW07EN"=C:\Program Files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe [2014-03-18 1813832]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-07-09 767200]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

C:\Users\Nark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=28

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-09-14 15:45:00 ----D---- C:\_OTM
2014-09-13 20:24:46 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-09-13 20:24:14 ----D---- C:\AdwCleaner
2014-09-13 09:04:46 ----D---- C:\rsit
2014-09-13 09:04:46 ----D---- C:\Program Files\trend micro
2014-09-11 22:46:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-11 22:46:44 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-11 22:46:43 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 22:46:43 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 22:46:43 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-11 22:46:42 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 22:46:42 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-11 22:46:41 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 22:46:41 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 22:46:40 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-11 22:46:40 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 22:46:40 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 22:46:39 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-11 22:46:39 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 22:46:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 22:46:38 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-11 22:46:37 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 22:46:37 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 22:46:36 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-11 22:46:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-11 22:46:36 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 22:46:35 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-11 22:46:34 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-11 22:46:34 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 22:42:26 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-11 22:42:26 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 15:51:18 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-11 15:51:18 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-11 15:50:57 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-11 15:50:57 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-11 15:50:54 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-11 15:50:54 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-11 15:50:54 ----A---- C:\Windows\system32\kerberos.dll
2014-09-11 15:50:52 ----A---- C:\Windows\system32\aepdu.dll
2014-09-11 15:50:52 ----A---- C:\Windows\system32\aeinv.dll
2014-09-04 08:04:20 ----A---- C:\Windows\system32\klfphc.dll
2014-09-04 08:04:13 ----D---- C:\Windows\ELAMBKUP
2014-09-04 08:04:12 ----D---- C:\ProgramData\Kaspersky Lab
2014-09-04 08:04:12 ----D---- C:\Program Files (x86)\Kaspersky Lab
2014-09-04 08:04:09 ----A---- C:\Windows\system32\drivers\klif.sys
2014-09-04 08:04:09 ----A---- C:\Windows\system32\drivers\klflt.sys
2014-09-04 08:04:08 ----A---- C:\Windows\system32\drivers\klhk.sys
2014-09-02 19:13:35 ----A---- C:\Windows\ntbtlog.txt
2014-09-02 19:06:13 ----D---- C:\Windows\system32\appmgmt
2014-09-02 09:38:43 ----AD---- C:\ProgramData\TEMP
2014-09-02 08:27:24 ----A---- C:\Windows\SYSWOW64\srvany.exe
2014-09-02 08:27:24 ----A---- C:\Windows\KMService.exe
2014-08-29 18:56:53 ----D---- C:\Users\Nark\AppData\Roaming\Battle.net
2014-08-29 18:56:45 ----D---- C:\Program Files (x86)\Battle.net
2014-08-27 23:44:06 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-27 23:44:06 ----A---- C:\Windows\system32\win32k.sys
2014-08-27 23:44:06 ----A---- C:\Windows\system32\gdi32.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-15 03:00:44 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-15 03:00:44 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-15 03:00:44 ----A---- C:\Windows\system32\icardres.dll
2014-08-15 03:00:44 ----A---- C:\Windows\system32\icardagt.exe
2014-08-15 03:00:42 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-15 03:00:42 ----A---- C:\Windows\system32\TsWpfWrp.exe

======List of files/folders modified in the last 1 month======

2014-09-14 15:48:09 ----D---- C:\Users\Nark\AppData\Roaming\Dropbox
2014-09-14 15:47:40 ----D---- C:\Windows\Temp
2014-09-14 15:47:27 ----SHD---- C:\System Volume Information
2014-09-14 15:45:25 ----D---- C:\Windows\system32\config
2014-09-14 15:45:00 ----D---- C:\Windows\Tasks
2014-09-14 08:50:04 ----D---- C:\Users\Nark\AppData\Roaming\uTorrent
2014-09-13 20:30:55 ----D---- C:\Windows\System32
2014-09-13 20:30:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-13 20:30:54 ----D---- C:\Windows\inf
2014-09-13 20:25:10 ----D---- C:\Windows\system32\Tasks
2014-09-13 20:25:09 ----RD---- C:\Program Files (x86)
2014-09-13 20:25:09 ----HD---- C:\ProgramData
2014-09-13 20:24:46 ----D---- C:\Windows\SysWOW64
2014-09-13 09:04:46 ----RD---- C:\Program Files
2014-09-12 13:57:21 ----D---- C:\Windows\rescache
2014-09-12 13:55:21 ----D---- C:\Windows\Microsoft.NET
2014-09-12 13:47:51 ----RSD---- C:\Windows\assembly
2014-09-12 12:41:28 ----D---- C:\Windows\winsxs
2014-09-12 12:40:42 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-12 12:40:42 ----D---- C:\Windows\system32\en-US
2014-09-12 12:40:42 ----D---- C:\Program Files\Internet Explorer
2014-09-12 12:40:42 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-11 22:48:29 ----SHD---- C:\Windows\Installer
2014-09-11 22:46:54 ----D---- C:\Windows\system32\catroot2
2014-09-11 22:46:54 ----D---- C:\Windows\system32\catroot
2014-09-11 22:46:22 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 22:45:47 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-11 22:45:08 ----D---- C:\Windows\system32\MRT
2014-09-11 22:42:48 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 22:42:25 ----SD---- C:\Windows\system32\CompatTel
2014-09-10 22:37:32 ----D---- C:\Windows\system32\NDF
2014-09-04 17:02:00 ----D---- C:\Windows\system32\wdi
2014-09-04 08:11:46 ----D---- C:\ProgramData\Skype
2014-09-04 08:04:20 ----D---- C:\Windows\system32\drivers
2014-09-04 08:04:19 ----D---- C:\Windows\system32\DriverStore
2014-09-04 08:04:13 ----D---- C:\Windows
2014-09-02 09:41:21 ----HD---- C:\Windows\system32\GroupPolicy
2014-09-02 09:41:21 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2014-09-02 09:36:10 ----SD---- C:\ProgramData\Microsoft
2014-09-02 09:35:10 ----D---- C:\Program Files (x86)\Common Files
2014-08-19 17:51:07 ----D---- C:\Windows\system32\drivers\UMDF
2014-08-15 03:20:54 ----RSD---- C:\Windows\Fonts
2014-08-15 03:20:54 ----D---- C:\Windows\ehome
2014-08-15 03:20:53 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-08-15 03:20:53 ----D---- C:\Windows\system32\cs-CZ
2014-08-15 03:20:53 ----D---- C:\Windows\PolicyDefinitions

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2014-02-20 457824]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 klhk;klhk; C:\Windows\system32\DRIVERS\klhk.sys [2014-04-10 243808]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2014-07-25 792128]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2014-02-25 30304]
R1 klpd;klpd; C:\Windows\system32\DRIVERS\klpd.sys [2013-04-12 15456]
R1 kltdi;kltdi; C:\Windows\system32\DRIVERS\kltdi.sys [2014-03-25 55904]
R1 kneps;kneps; C:\Windows\system32\DRIVERS\kneps.sys [2014-03-26 179296]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-07-09 15950848]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-07-09 557056]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 klflt;Kaspersky Lab Kernel DLL; C:\Windows\system32\DRIVERS\klflt.sys [2014-07-25 140352]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\Windows\system32\DRIVERS\klkbdflt.sys [2014-03-28 28768]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\Windows\system32\DRIVERS\klmouflt.sys [2013-08-08 29280]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-04 346144]
S2 MLPTDR_Q;MLPTDR_Q; \??\C:\Windows\system32\ []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;Ovladač WinUSB; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-07-09 239616]
R2 AVP15.0.0;Služba Kaspersky Anti-Virus 15.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe [2014-04-20 233552]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 KMService;KMService; C:\Windows\syswow64\srvany.exe [2010-06-16 8192]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-07-30 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#12 Příspěvek od Rudy »

Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#13 Příspěvek od Nark »

Myslel sem si že ano ale dnes opět pc odpojené - sitový kabel odpojen a nešlo zrestartovat. Po hard resetu jede internet v pohodě. Mate ještě nějaký nápad?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119547
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravidelné odpojení od internetu - po restartu problém z

#14 Příspěvek od Rudy »

Zkuste obnovu systému k datu, kdy korektně fungoval. Pokud to není možné, dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nark
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 16 bře 2006 12:06

Re: Pravidelné odpojení od internetu - po restartu problém z

#15 Příspěvek od Nark »

Tady je log combofix:

ComboFix 14-09-16.01 - Nark 15.09.2014 21:03:14.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.6135.4202 [GMT 2:00]
Spuštěný z: c:\users\Nark\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
SP: Kaspersky Anti-Virus *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Common Files\Config\uninstinethnfd.exe
c:\program files (x86)\Common Files\Config\ver.xml
c:\users\Nark\AppData\Local\Adobe\AdbeRdr11000_cs_CZ.exe
c:\users\Nark\AppData\Local\Adobe\downloader.dll
c:\users\Nark\AppData\Local\Adobe\gccheck.exe
c:\users\Nark\AppData\Local\Adobe\gtbcheck.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-08-15 do 2014-09-15 )))))))))))))))))))))))))))))))
.
.
2014-09-15 19:06 . 2014-09-15 19:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-09-15 07:07 . 2014-09-15 07:07 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{798E5A30-CB39-4259-8241-B0607F21A16C}\offreg.dll
2014-09-14 13:45 . 2014-09-14 13:45 -------- d-----w- C:\_OTM
2014-09-13 18:24 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll
2014-09-13 18:24 . 2014-09-13 18:25 -------- d-----w- C:\AdwCleaner
2014-09-13 07:04 . 2014-09-14 13:48 -------- d-----w- c:\program files\trend micro
2014-09-13 07:04 . 2014-09-13 07:04 -------- d-----w- C:\rsit
2014-09-12 10:46 . 2014-08-21 03:43 11319192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{798E5A30-CB39-4259-8241-B0607F21A16C}\mpengine.dll
2014-09-11 20:42 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll
2014-09-11 20:42 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
2014-09-11 13:51 . 2014-08-01 11:53 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll
2014-09-11 13:51 . 2014-08-01 11:35 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll
2014-09-11 13:50 . 2014-06-24 03:29 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
2014-09-11 13:50 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll
2014-09-11 13:50 . 2014-07-07 02:06 728064 ----a-w- c:\windows\system32\kerberos.dll
2014-09-11 13:50 . 2014-07-07 02:06 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-09-11 13:50 . 2014-07-07 01:40 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-09-11 13:50 . 2014-07-07 01:40 550912 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-09-11 13:50 . 2014-07-07 01:39 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-09-11 13:50 . 2014-09-05 02:10 578048 ----a-w- c:\windows\system32\aepdu.dll
2014-09-11 13:50 . 2014-09-05 02:05 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-09-04 06:04 . 2013-05-06 07:13 110176 ----a-w- c:\windows\system32\klfphc.dll
2014-09-04 06:04 . 2014-09-04 06:04 -------- d-----w- c:\windows\ELAMBKUP
2014-09-04 06:04 . 2014-09-15 19:07 -------- d-----w- c:\programdata\Kaspersky Lab
2014-09-04 06:04 . 2014-09-04 06:04 -------- d-----w- c:\program files (x86)\Kaspersky Lab
2014-09-04 06:04 . 2014-07-25 16:23 792128 ----a-w- c:\windows\system32\drivers\klif.sys
2014-09-04 06:04 . 2014-07-25 16:23 140352 ----a-w- c:\windows\system32\drivers\klflt.sys
2014-09-04 06:04 . 2014-04-10 15:25 243808 ----a-w- c:\windows\system32\drivers\klhk.sys
2014-09-02 17:06 . 2014-09-02 17:06 -------- d-----w- c:\windows\system32\appmgmt
2014-09-02 07:38 . 2014-09-02 07:38 172032 ----a-w- c:\windows\SysWow64\AniGIF.ocx
2014-09-02 07:38 . 2014-09-02 07:38 -------- d-----w- c:\users\Nark\AppData\Local\CrashRpt
2014-09-02 07:35 . 2014-09-15 19:06 -------- d-----w- c:\program files (x86)\Common Files\Config
2014-09-02 07:32 . 2014-09-02 07:32 -------- d-sh--w- c:\users\Nark\AppData\Local\EmieUserList
2014-09-02 07:32 . 2014-09-02 07:32 -------- d-sh--w- c:\users\Nark\AppData\Local\EmieSiteList
2014-09-02 06:27 . 2013-02-14 13:44 273920 ----a-w- c:\windows\KMService.exe
2014-09-02 06:27 . 2010-06-15 23:44 8192 ----a-w- c:\windows\SysWow64\srvany.exe
2014-08-29 16:56 . 2014-09-15 07:37 -------- d-----w- c:\users\Nark\AppData\Local\Battle.net
2014-08-29 16:56 . 2014-08-29 16:57 -------- d-----w- c:\users\Nark\AppData\Roaming\Battle.net
2014-08-29 16:56 . 2014-09-14 06:50 -------- d-----w- c:\program files (x86)\Battle.net
2014-08-29 16:56 . 2014-08-29 16:56 -------- d-----w- c:\program files (x86)\Common Files\Blizzard Entertainment
2014-08-27 21:44 . 2014-08-23 02:07 404480 ----a-w- c:\windows\system32\gdi32.dll
2014-08-27 21:44 . 2014-08-23 01:45 311808 ----a-w- c:\windows\SysWow64\gdi32.dll
2014-08-27 21:44 . 2014-08-23 00:59 3163648 ----a-w- c:\windows\system32\win32k.sys
2014-08-19 15:34 . 2014-09-02 17:26 -------- d-----w- c:\users\Nark\AppData\Local\Diagnostics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-09-11 20:42 . 2014-08-03 08:20 101694776 ----a-w- c:\windows\system32\MRT.exe
2014-08-05 07:20 . 2014-07-28 14:28 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-08-01 01:29 . 2014-08-01 01:29 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-08-01 01:29 . 2014-08-01 01:29 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-08-01 01:29 . 2014-08-01 01:29 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-08-01 01:29 . 2014-08-01 01:29 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-08-01 01:29 . 2014-08-01 01:29 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-08-01 01:29 . 2014-08-01 01:29 81408 ----a-w- c:\windows\system32\icardie.dll
2014-08-01 01:29 . 2014-08-01 01:29 774144 ----a-w- c:\windows\system32\jscript.dll
2014-08-01 01:29 . 2014-08-01 01:29 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-08-01 01:29 . 2014-08-01 01:29 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-08-01 01:29 . 2014-08-01 01:29 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-08-01 01:29 . 2014-08-01 01:29 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-08-01 01:29 . 2014-08-01 01:29 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-08-01 01:29 . 2014-08-01 01:29 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-08-01 01:29 . 2014-08-01 01:29 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-08-01 01:29 . 2014-08-01 01:29 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-08-01 01:29 . 2014-08-01 01:29 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-08-01 01:29 . 2014-08-01 01:29 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-08-01 01:29 . 2014-08-01 01:29 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-08-01 01:29 . 2014-08-01 01:29 413696 ----a-w- c:\windows\system32\html.iec
2014-08-01 01:29 . 2014-08-01 01:29 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-08-01 01:29 . 2014-08-01 01:29 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-08-01 01:29 . 2014-08-01 01:29 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-08-01 01:29 . 2014-08-01 01:29 247808 ----a-w- c:\windows\system32\msls31.dll
2014-08-01 01:29 . 2014-08-01 01:29 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-08-01 01:29 . 2014-08-01 01:29 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-08-01 01:29 . 2014-08-01 01:29 235520 ----a-w- c:\windows\system32\url.dll
2014-08-01 01:29 . 2014-08-01 01:29 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-08-01 01:29 . 2014-08-01 01:29 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-08-01 01:29 . 2014-08-01 01:29 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-08-01 01:29 . 2014-08-01 01:29 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-08-01 01:29 . 2014-08-01 01:29 147968 ----a-w- c:\windows\system32\occache.dll
2014-08-01 01:29 . 2014-08-01 01:29 143872 ----a-w- c:\windows\system32\wextract.exe
2014-08-01 01:29 . 2014-08-01 01:29 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-08-01 01:29 . 2014-08-01 01:29 13824 ----a-w- c:\windows\system32\mshta.exe
2014-08-01 01:29 . 2014-08-01 01:29 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-08-01 01:29 . 2014-08-01 01:29 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-08-01 01:29 . 2014-08-01 01:29 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-08-01 01:29 . 2014-08-01 01:29 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-08-01 01:29 . 2014-08-01 01:29 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-08-01 01:29 . 2014-08-01 01:29 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-08-01 01:29 . 2014-08-01 01:29 101376 ----a-w- c:\windows\system32\inseng.dll
2014-08-01 01:28 . 2014-08-01 01:28 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 648192 ----a-w- c:\windows\system32\d3d10level9.dll
2014-08-01 01:28 . 2014-08-01 01:28 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
2014-08-01 01:28 . 2014-08-01 01:28 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2014-08-01 01:28 . 2014-08-01 01:28 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2014-08-01 01:28 . 2014-08-01 01:28 363008 ----a-w- c:\windows\system32\dxgi.dll
2014-08-01 01:28 . 2014-08-01 01:28 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
2014-08-01 01:28 . 2014-08-01 01:28 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 296960 ----a-w- c:\windows\system32\d3d10core.dll
2014-08-01 01:28 . 2014-08-01 01:28 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
2014-08-01 01:28 . 2014-08-01 01:28 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2014-08-01 01:28 . 2014-08-01 01:28 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2014-08-01 01:28 . 2014-08-01 01:28 221184 ----a-w- c:\windows\system32\UIAnimation.dll
2014-08-01 01:28 . 2014-08-01 01:28 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
2014-08-01 01:28 . 2014-08-01 01:28 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
2014-08-01 01:28 . 2014-08-01 01:28 194560 ----a-w- c:\windows\system32\d3d10_1.dll
2014-08-01 01:28 . 2014-08-01 01:28 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2014-08-01 01:28 . 2014-08-01 01:28 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
2014-08-01 01:28 . 2014-08-01 01:28 1643520 ----a-w- c:\windows\system32\DWrite.dll
2014-08-01 01:28 . 2014-08-01 01:28 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2014-08-01 01:28 . 2014-08-01 01:28 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2014-08-01 01:28 . 2014-08-01 01:28 1238528 ----a-w- c:\windows\system32\d3d10.dll
2014-08-01 01:28 . 2014-08-01 01:28 1175552 ----a-w- c:\windows\system32\FntCache.dll
2014-08-01 01:28 . 2014-08-01 01:28 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2014-08-01 01:28 . 2014-08-01 01:28 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
2014-08-01 01:28 . 2014-08-01 01:28 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-08-01 01:28 . 2014-08-01 01:28 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-07-31 01:26 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-07-31 01:26 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll
2014-07-24 21:47 . 2014-07-24 21:47 869544 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2014-07-16 03:23 . 2014-08-14 03:10 2048 ----a-w- c:\windows\system32\tzres.dll
2014-07-16 02:46 . 2014-08-14 03:10 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2014-07-14 02:02 . 2014-08-14 03:10 1216000 ----a-w- c:\windows\system32\rpcrt4.dll
2014-07-14 01:40 . 2014-08-14 03:10 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll
2014-07-09 15:52 . 2014-07-09 15:52 127872 ----a-w- c:\windows\system32\amdhcp64.dll
2014-07-09 15:52 . 2014-07-09 15:52 117560 ----a-w- c:\windows\SysWow64\amdhcp32.dll
2014-07-09 15:52 . 2014-07-09 15:52 78432 ----a-w- c:\windows\system32\atimpc64.dll
2014-07-09 15:52 . 2014-07-09 15:52 78432 ----a-w- c:\windows\system32\amdpcom64.dll
2014-07-09 15:52 . 2014-07-09 15:52 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll
2014-07-09 15:52 . 2014-07-09 15:52 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2014-07-09 15:52 . 2014-07-09 15:52 143304 ----a-w- c:\windows\system32\atiuxp64.dll
2014-07-09 15:52 . 2014-07-09 15:52 126336 ----a-w- c:\windows\SysWow64\atiuxpag.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-07-09 767200]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
c:\users\Nark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Nark\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-7-30 36414496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MLPTDR_Q;MLPTDR_Q;c:\windows\system32\;c:\windows\SYSNATIVE\ [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S1 klhk;klhk;c:\windows\system32\DRIVERS\klhk.sys;c:\windows\SYSNATIVE\DRIVERS\klhk.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AVP15.0.0;Služba Kaspersky Anti-Virus 15.0.0;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe;c:\program files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.0\avp.exe [x]
S2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
S2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 klflt;Kaspersky Lab Kernel DLL;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-09-13 23:36 1096520 ----a-w- c:\program files (x86)\Google\Chrome\Application\37.0.2062.120\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 14:15]
.
2014-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-07-28 14:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2014-06-24 22:04 164760 ----a-w- c:\users\Nark\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ACPW07EN"="c:\program files\ACD Systems\ACDSee Pro\7.0\acdIDInTouch2.exe" [2014-03-18 1813832]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-HD-V1.9 - c:\program files (x86)\HD-V1.9\Uninstall.exe
AddRemove-YouTube Accelerator - c:\program files (x86)\YouTube Accelerator\YTAUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MLPTDR_Q]
"ImagePath"="\??\c:\windows\system32\"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.032"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.abr"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.ani"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.apd"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.arw"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.bay"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.bmp"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.cr2"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.crw"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.cs1"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.cur"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.dcr"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.dcx"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.dib"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.djv"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.djvu"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.dng"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.emf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.eps"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.erf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.fff"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.gif"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.hdr"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.icl"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.icn"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.iw4"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.j2c"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.j2k"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jbr"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jfif"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jif"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jp2"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jpc"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jpe"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jpeg"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jpg"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jpk"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.jpx"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.kdc"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.mef"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.mos"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.mrw"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.nef"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.nrw"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.orf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pbr"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pct"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pcx"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pef"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pic"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pict"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.png"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.psd"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.psp"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pspbrush"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.pspimage"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.raf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.raw"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.rle"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.rw2"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.rwl"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.sr2"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.srf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.srw"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.tga"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.thm"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.tif"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.tiff"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.ttc"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.ttf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v70po\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.v70po"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v70pp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.v70pp"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v70ppf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.v70ppf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.wbm"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.wbmp"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.webp"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.wmf"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.xif"
.
[HKEY_USERS\S-1-5-21-3373383961-3809780321-2737733167-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee Pro 7.xmp"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\srvany.exe
c:\windows\KMService.exe
.
**************************************************************************
.
Celkový čas: 2014-09-15 21:10:20 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-09-15 19:10
.
Před spuštěním: Volných bajtů: 68 126 863 360
Po spuštění: Volných bajtů: 69 489 172 480
.
- - End Of File - - D8281FA3CDFFAD8E86C757A705DB3097
A36C5E4F47E84449FF07ED3517B43A31

Odpovědět