Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

zpomalené pc - hd plus

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

zpomalené pc - hd plus

#1 Příspěvek od kubazzz »

Zdravím,
aktuálně mám problém s ntb - celý systém je zpomalený. Známému se povedlo s něčím
nainstalovat hdplus, od té doby je vše zasekané. HDplus mi nejde odstranit. Poprosil bych
o kontrolu logu, díky za pomoc

Logfile of random's system information tool 1.10 (written by random/random)
Run by OLPE at 2014-09-12 13:01:30
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 177 GB (74%) free of 238 GB
Total RAM: 3957 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:02:05, on 12.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17280)
Boot mode: Normal

Running processes:
C:\Users\OLPE\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\Installer\setup.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe
C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe
C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe
C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\AVAST Software\Avast\avastUi.exe
C:\Program Files\trend micro\OLPE.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.default-search.net?sid=476&a ... 88&src=hmp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: CrossriderApp0059562 - {11111111-1111-1111-1111-110511951162} - C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-bho.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Startup: Dropbox.lnk = OLPE\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Přidat do aplikace TOSHIBA Bulletin Board - res://C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Garmin Core Update Service - Garmin Ltd or its subsidiaries - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Internet Pass-Through Service (PassThru Service) - Unknown owner - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SmdmF Service (SmdmFService) - Aztec Media Inc - C:\Program Files (x86)\Settings Manager\smdmf\SmdmFService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10719 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 3797312
\??\C:\Windows\system32\conhost.exe "-495144728-1078923733-320437983-19854112212988878967435914-333583374-799538223
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
taskeng.exe {C7620A68-0D78-48C6-9D06-85F3E40623FD}
"C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe"
"C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe"
"C:\Program Files (x86)\Settings Manager\smdmf\SmdmFService.exe"
"C:\Program Files (x86)\Settings Manager\smdmf\SmdmFService.exe" -monitor 460
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2172
"taskhost.exe"
"C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe" /c
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe /Embedding
taskeng.exe {D00E8410-2914-4FA0-A171-089F131ADCD9}
"C:\Users\OLPE\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Windows\system32\RunDll32.exe" "C:\Program Files\HP\HP Officejet 6500 E710a-f\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN13C210PQ05JZ;CONNECTION=USB;MONITOR=1;
"C:\Windows\system32\RunDll32.exe" "C:\Program Files\HP\HP Officejet 7500 E910\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=MY3243110J05JB;CONNECTION=NW;MONITOR=1;
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files (x86)\Settings Manager\smdmf\smdmfu.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
C:\Windows\system32\svchost.exe -k HPService
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-2abe6dea-c35a-4f8b-a4e4-3e5d5bf42972 -SystemEventPortName:HostProcess-cacac40d-5aad-4c97-a75a-89ea0546e67c -IoCancelEventPortName:HostProcess-9839e1d5-e5fc-40b5-9e46-4611cb63681e -NonStateChangingEventPortName:HostProcess-8e0f1d31-5625-40b9-b72e-3d05a1933932 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c5265a15-ebce-49b1-88c8-a1872a6c10ab -DeviceGroupId:WpdFsGroup
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\Installer\setup.exe" --uninstall --multi-install --chrome --system-level
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" http://www.google.com/support/chrome/bi ... s=6.1.7601
"C:\Windows\SysWOW64\rundll32.exe" "C:\Program Files (x86)\Settings Manager\smdmf\sysapcrt.dll",switch_processor_mode 000000000000020C
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4372.0.1854500849\1786634729" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,44 --disable-accelerated-video-decode --gpu-vendor-id=0x10de --gpu-device-id=0x0a7a --gpu-driver-vendor=NVIDIA --gpu-driver-version=8.17.12.6669 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe"
"C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe"
"C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe"
"C:\Program Files (x86)\Plus-HD-V1.5\Uninstall.exe"
"C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-nova.exe" /Tslqtz='Plus-HD-V1.5' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /jNWHyHawn=1.34.6.10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /SqYoDeZx=http://js.datagenserv.com /MlWHEFwVW=ch /EkgeIU /VtDJGirtN='nova' /ZnpqwPR=http://js.clientdemocloud.com /lWWiCcsy='{"asw":[8, 1, 0]}' /gWZbpO='http://update.datagenserv.com/novarun/{ ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4372.29.665759643\1927111166" --ppapi-flash-args --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe10_ Global\UsGthrCtrlFltPipeMssGthrPipe10 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_07/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_09/UMA-Uniformity-Trial-50-Percent/default/ --renderer-print-preview --device-scale-factor=1 --enable-threaded-compositing --enable-delegated-renderer --disable-accelerated-video-decode --channel="4372.34.1841069179\1525324676" /prefetch:673131151
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\avastUi.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\HP\HP Officejet 7500 E910\Bin\HPNetworkCommunicatorCom.exe" -Embedding
C:\Windows\system32\wbem\wmiprvse.exe

"C:\Users\OLPE\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-1.job - C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-codedownloader.exe /WHlKt /FTjVrg=task /Tslqtz='Plus-HD-V1.5' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /jNWHyHawn=1.34.6.10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /SqYoDeZx=http://js.datagenserv.com /MlWHEFwVW=ch /ZnpqwPR=http://js.clientdemocloud.com /zTlKDOn /lWWiCcsy='{"asw":[8, 1, 0]}' /gWZbpO='http://update.datagenserv.com/ie_code_a ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-11.job - C:\Program Files (x86)\Plus-HD-V1.5\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-11.exe /XwFCMrok=ogBkyU+M+XlRpNZfaaD9aNbptqfADTIY3EL8Fx4jK20TEVqXqM9MGz6OCdidL9WgkMFzKP+oaaeBO/YEi7NTTdTawbiPC+e1Vn5SfJPsbM7Gktyqq2HYK708dGyXooFZYhUV5t9LLEsV+5DowKsj20hkdAeZdQRCW5wsbS37KNK/nM2dB/73K80vrIGvW7fEljO5lR+u8VpqxMP2/j13sUh5pa1rFIuYP0xndxB7BCTgCK722WluUXdN8YmzoE19UZZJxt2fZ8ooGIhXRk+Q3VUJk89BNcfS0ZzoJLBEnVGuz7sMWvTs6qSCxZHGcaqCCT++8nDM0xBCaXleumEGYljVjJn9FUCizZwMvRFUm/qcBPujU3/4LPQ/kQlF10sUc/mtxuNreI0w9oNyO0/6WIQ8mpr2ZYOOaBKFathauDXQIqCA00SCUvs8/WGqEXRF8EKXjbOPIPPNW1gURB1PuENFr5xO2aUPqt95e9r/ndb7foyUyknnk7ItSNYroyNrkaEJwiKEhnkD76+jZ9/Pq7x/dGvSawlrfXm2eg/InnIVsSHM0K6Y2miWQsPShXwy/waWRVrLkfUAQvniYobEUR3HK3lZp8w/z85EPle/ARjtRyAMvPbeBr/bMqwoXddLmBKo0fbxeTXSnUq30BCpLCd6CuHl8GRU8lsuKNvJfuKoNKOMRoC5c0Smn2JfSZXx1EAg5sbxLJMkao3ZSlPp6WKBe59qFzxbq6RrwSCtUv+TFfUlTwsvG598+4B265kwm6v4gjYu3w68I/z0Tn0c3X8ATkOyfuPCBXhBz2EsjP18AOE4Pxh7/3q+QEw0USAQbecrm2f4PEnfyOs1TqjURB18p2IgaDtF6RZdlXQXPcv26tRM7DNX7IFhP/GIhkJ4NlzvJUh+xSYktuKv8v/LedaNQLYOFz8Ad1uXdxvL2fLRHMr1iTF9D8HjJfskwH3uJk9ja9e7428na6/tMqm3UC1B68BwWdL9kCxoGexIZwcJ34RCBDv6U2i/OxQQIqJ7sx/AOdzjUdDp1ZHQuc2TfkSXlIUsiqkeLGMn0iWpZvYKytcdh05Zpix737gwvWKYqXZTscSfe6oZ+j4y/dfL/dktoKyfwqW0KJ3ashx2eHMO+9xEILRbOokcKHu8dhLCB4GV2zIqd2Ua9useDidaaE5oADKNsEosDMRzq/u5apuJGqy4oK9f6YQdVi8STozr+DRjXNBxFnxj6D538XGnQ1T0t01X/3eIeVsXIBcvkTFMa5SiVeQS48UonVx6KltqbO4kWYWku8+6YEuDL9H8mkEtLebOjlMgkz65Kd2LvjTEaqMVTpHBAA5gWrZDdqDAvO3vfwcy9H0nZSwroOsEH1vqomdrWAyEJQU+mG9RUYXlau126kCjcJO0INt/nOXqYT7KA5WfaWiNrH+5EIsPOjNnnfxBMeMhRzeTFuJQfsNk6b1VdTPLro4r+DTwjdR5E2YILnePl/l7yREBd5fi+phDzCff7NLalE+8vuudJfT41zG0S9TPtXC+oTvrM1teHmj8uRbGQauqI5T9bXQq1CV67jcodcnuHr68TUPjE0EhgrAM+K7o8QL0yKKKwl1paGBVMDCRoX0WIPj7l9rpGD0B6R09dJTtUWww1FW+Fj8Wd139vamAGlYZIeTgJM0b5Wvjt2/jFrZytBzSYcmxDdM5PgvF5FuRHG/5iXWovFk=
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-2.job - C:\Program Files (x86)\Plus-HD-V1.5\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-2.exe /bRXuUn /Tslqtz='Plus-HD-V1.5' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /wNQhIi=11111111-1111-1111-1111-110511951162 /MlWHEFwVW=ch /eeiRG /zTlKDOn /gWZbpO='http://update.datagenserv.com/ie_enable ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-3.job - C:\Program Files (x86)\Plus-HD-V1.5\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-3.exe /XwFCMrok=C4Qn9QuGh7v8546ZM/jb1j2PajW2VR5bDrcTCTMLIFnUZvwtwtuMEXXSdb7oAfgzo9J86Hls8btt0cGm9CiZW2znLiuWb+0qTxMk+MS8DsuzMv5kb+4GCHU3Z05fgMTZDCUxd3xZ2hGcHRuQVUz2G3NW7IDjOvh8cDeSKF6BNgZ3SK5EyFpIndDbrrGiYnHrjnST0MVrBMdy8RzreKa87gBHQ5FgiPYgp4i3Ffc52hvvNm8rHwSXeyizchikeeDQ0Y2Y3z3IJHLQJmFb8M26zh+qEzpnUu+30KaScLVVqK0WdMg7yrqT8k/GIAAom0SgvPRnZLJrr/LpBsDm7QMzUkmCwm2juYwMYcSqhaO090jCL/XHSujdXJ4YahzZ8zQrbLAI4ZcApiQoVPvK7TqSBhFUD9X9LToA2+J+9nYsVC/4131sVaYRqeXZn+ROA/OCrnVxucwfVEl2nG50YuhPR5DiCptYrQmtT8g6AB28MOntPZXF54MFzrk08fBm9jXgB8M1VEdTcHc4UuACYe4Y8+7mBfSER6TR6U4zFvHQwVW4PdheMrJ8ldVC7Prf4RcYtWLAseywFm5DsjAwJUQ+EB41O50gekO8vAiiEvjci2gZyWuCRag/Tdd/7hj3CJCn2bMQqLeoeAyTr8oyK6rZup0M0fpm9TkgbU+oh9Q63j4ISv2BhUirNXjQHvKfKNd7/0cgF93YqIPcqZXzLrpHIl1eQ++VFzPYU0zrFW+stzYL8rVR4sbmT6ddaYyuvrQwmycbL/F+YZzYcVmir/Vv2bKGY+zM3sgYfkpWrmpXFRlF+AWw0VwQu9g1/3VVbr4TAesvuPUcqJyWJcbQp6xfP6+6Th3anLqWQpRuxWU/YExAO7F60TACIAbNtnSTabXlG950HDAjsc/MrH2ftiju9SWMqjp/sL7p02XShSH3FupqrrJgJEETrX9YcqyYbWypfGG6XGteF5u46V1u+boHL1k9XQd6zpzRUFhmrJTl8RYpYeSCg3mz+QRNfWaGolNd
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-4.job - C:\Program Files (x86)\Plus-HD-V1.5\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-4.exe /nnpqzAL /Tslqtz='Plus-HD-V1.5' /psCFJxWE='C:\Program Files (x86)\Plus-HD-V1.5\59562.xpi' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /jNWHyHawn=1.34.6.10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /KHILDCqN=300 /XQgyEst=809710cc-b432-49dc-9140-7828943a0e27@84b67896-5412-4e3f-a6d3-fa7dc6e439e3.com /aiFjXgPBF=0.94 /XlPlpbW=a809710ccb43249dc91407828943a0e2784b6789654124e3fa6d3fa7dc6e439e3com59562 /hAEaKYUOo=https://w9u6a2p6.ssl.hwcdn.net/plugin/f ... /59562.rdf /HASuxAmKm='Plus-HD-V1.5' /XfoJF='Turn YouTube videos to High Definition by default' /BEgWi='Plus-HD-V1.5' /MlWHEFwVW=ch /lWWiCcsy='{"asw":[8, 1, 0]}' /zTlKDOn /ABIwhz /nzuCxSnaK /gWZbpO='http://update.datagenserv.com/ff_agent_ ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-5.job - C:\Program Files (x86)\Plus-HD-V1.5\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-5.exe /qEVKuN /Tslqtz='Plus-HD-V1.5' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /MMAHfXhXJ=http://ipgeoapi.com/ /Lqpjr=http://update.datagenserv.com /qPTtcuuqI=2 /QCpKW=http://logs.datagenserv.com /gWZbpO='http://update.datagenserv.com/updater_a ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-6.job - C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-novainstaller.exe /lsApTW /Tslqtz='Plus-HD-V1.5' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /jNWHyHawn=1.34.6.10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /SqYoDeZx=http://js.datagenserv.com /MlWHEFwVW=ch /EkgeIU /VtDJGirtN='nova' /ZnpqwPR=http://js.clientdemocloud.com /lWWiCcsy='{"asw":[8, 1, 0]}' /FTjVrg=task /gWZbpO='http://update.datagenserv.com/novacode/ ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
C:\Windows\tasks\1a865e51-8d7f-47ac-a7cc-49d250e98ec8-7.job - C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-nova.exe /Tslqtz='Plus-HD-V1.5' /sXvLS=59562 /sXpxq='001690' /jAErLa='0' /RsOnpaMiX='0' /gZLMO=AE112C908069494398FD9E12B40478E9IE /eHTOvF=00cb61805dc479ac02baae9469321219 /UvyZbFWfj=1_34_06_10 /jNWHyHawn=1.34.6.10 /yFIPXHM=1403630725 /QGQNPkKYM=http://stats.datagenserv.com /gxkGk=http://errors.datagenserv.com /SqYoDeZx=http://js.datagenserv.com /MlWHEFwVW=ch /EkgeIU /VtDJGirtN='nova' /ZnpqwPR=http://js.clientdemocloud.com /lWWiCcsy='{"asw":[8, 1, 0]}' /gWZbpO='http://update.datagenserv.com/novarun/{ ... pdate.json' /FTjVrg='task' /pVTnMrrL=''
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\globalUpdateUpdateTaskMachineCore.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /c
C:\Windows\tasks\globalUpdateUpdateTaskMachineUA.job - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951162}]
Plus-HD-V1.5 - C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-bho64.dll [2014-06-24 828400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-09-12 612248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951162}]
Plus-HD-V1.5 - C:\Program Files (x86)\Plus-HD-V1.5\Plus-HD-V1.5-bho.dll [2014-06-24 611312]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-09-12 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-02-28 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F3C88694-EFFA-4d78-B409-54B7B2535B14}]
TOSHIBA Media Controller Plug-in - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2010-12-05 529784]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-01-12 11775592]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2011-01-10 2186856]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CDAServer]
C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2012-03-09 462712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.autoupdate]
C:\Users\OLPE\AppData\Roaming\Seznam.cz\szninstall.exe -c []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
C:\Users\OLPE\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe -q []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
C:\Users\OLPE\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [2014-08-07 688984]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Officejet 7500 E910 (NET)]
C:\Program Files\HP\HP Officejet 7500 E910\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2011-10-28 49208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-21 1475584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^OLPE^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sledovat výstrahy inkoustu - HP Officejet 6500 E710a-f.lnk]
C:\Windows\system32\RunDll32.exe [2009-07-14 45568]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^OLPE^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Sledovat výstrahy inkoustu - HP Officejet 7500 E910 (Síť).lnk]
C:\Windows\system32\RunDll32.exe [2009-07-14 45568]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
""= []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-09-12 4086432]

C:\Users\OLPE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\OLPE\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro]
"Debugger="tasklist.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera]
"Debugger="tasklist.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2014-09-12 12:49:22 ----D---- C:\Users\OLPE\AppData\Roaming\AVAST Software
2014-09-12 12:48:51 ----SD---- C:\Windows\SYSWOW64\Microsoft
2014-09-12 12:47:36 ----A---- C:\Windows\system32\drivers\aswStm.sys
2014-09-12 12:47:35 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2014-09-12 12:47:34 ----A---- C:\Windows\system32\drivers\aswsp.sys
2014-09-12 12:47:34 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2014-09-12 12:47:34 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2014-09-12 12:47:34 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2014-09-12 12:46:59 ----A---- C:\Windows\avastSS.scr
2014-09-12 12:43:47 ----D---- C:\Program Files\trend micro
2014-09-12 12:43:43 ----D---- C:\rsit
2014-09-11 09:18:16 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2014-09-11 06:12:54 ----A---- C:\Windows\system32\ieui.dll
2014-09-11 06:12:53 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-09-11 06:12:51 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-09-11 06:12:51 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-09-11 06:12:51 ----A---- C:\Windows\system32\jscript9diag.dll
2014-09-11 06:12:51 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 06:12:51 ----A---- C:\Windows\system32\iernonce.dll
2014-09-11 06:12:51 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 06:12:50 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-09-11 06:12:50 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-09-11 06:12:50 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-09-11 06:12:50 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-09-11 06:12:50 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-09-11 06:12:50 ----A---- C:\Windows\system32\vbscript.dll
2014-09-11 06:12:50 ----A---- C:\Windows\system32\msrating.dll
2014-09-11 06:12:50 ----A---- C:\Windows\system32\ieUnatt.exe
2014-09-11 06:12:50 ----A---- C:\Windows\system32\dxtrans.dll
2014-09-11 06:12:50 ----A---- C:\Windows\system32\dxtmsft.dll
2014-09-11 06:12:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-09-11 06:12:49 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-09-11 06:12:49 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-09-11 06:12:49 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-09-11 06:12:49 ----A---- C:\Windows\system32\mshtmled.dll
2014-09-11 06:12:49 ----A---- C:\Windows\system32\msfeeds.dll
2014-09-11 06:12:49 ----A---- C:\Windows\system32\jsproxy.dll
2014-09-11 06:12:48 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-09-11 06:12:48 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-09-11 06:12:48 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-09-11 06:12:48 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-09-11 06:12:48 ----A---- C:\Windows\system32\iesetup.dll
2014-09-11 06:12:48 ----A---- C:\Windows\system32\iedkcs32.dll
2014-09-11 06:12:48 ----A---- C:\Windows\system32\ie4uinit.exe
2014-09-11 06:12:47 ----A---- C:\Windows\system32\mshtml.dll
2014-09-11 06:12:46 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-09-11 06:12:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-09-11 06:12:46 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-09-11 06:12:46 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-09-11 06:12:46 ----A---- C:\Windows\system32\ieapfltr.dll
2014-09-11 06:12:45 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-09-11 06:12:45 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 06:12:45 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-09-11 06:12:43 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-09-11 06:12:43 ----A---- C:\Windows\system32\iertutil.dll
2014-09-11 06:12:42 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-09-11 06:12:42 ----A---- C:\Windows\system32\wininet.dll
2014-09-11 06:12:42 ----A---- C:\Windows\system32\jscript9.dll
2014-09-11 06:12:41 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-09-11 06:12:41 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-09-11 06:12:41 ----A---- C:\Windows\system32\urlmon.dll
2014-09-11 06:12:39 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-09-11 06:12:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-09-11 06:12:38 ----A---- C:\Windows\system32\ieframe.dll
2014-09-11 06:04:21 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2014-09-11 06:04:21 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-09-10 13:51:19 ----A---- C:\Windows\system32\d3d10warp.dll
2014-09-10 13:51:18 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2014-09-10 13:51:03 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-09-10 13:51:03 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-09-10 13:51:03 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-09-10 13:51:03 ----A---- C:\Windows\system32\lsasrv.dll
2014-09-10 13:51:03 ----A---- C:\Windows\system32\kerberos.dll
2014-09-10 13:50:52 ----A---- C:\Windows\system32\aepdu.dll
2014-09-10 13:50:51 ----A---- C:\Windows\system32\aeinv.dll
2014-09-10 13:50:50 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2014-09-10 13:50:50 ----A---- C:\Windows\system32\TSWorkspace.dll
2014-09-04 14:22:20 ----D---- C:\ProgramData\smdmf
2014-09-04 14:22:18 ----D---- C:\ProgramData\systemk
2014-08-28 09:23:23 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-08-28 09:23:23 ----A---- C:\Windows\system32\win32k.sys
2014-08-28 09:23:23 ----A---- C:\Windows\system32\gdi32.dll
2014-08-14 03:01:51 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-08-14 03:01:51 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-08-14 03:01:51 ----A---- C:\Windows\system32\infocardapi.dll
2014-08-14 03:01:51 ----A---- C:\Windows\system32\icardagt.exe
2014-08-14 03:01:49 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-08-14 03:01:49 ----A---- C:\Windows\system32\icardres.dll
2014-08-14 03:01:25 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-08-14 03:01:25 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-08-13 23:36:26 ----A---- C:\Windows\SYSWOW64\KBDYAK.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\SYSWOW64\KBDTAT.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\SYSWOW64\KBDRU1.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\SYSWOW64\KBDRU.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\SYSWOW64\KBDBASH.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\system32\KBDYAK.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\system32\KBDTAT.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\system32\KBDRU1.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\system32\KBDRU.DLL
2014-08-13 23:36:26 ----A---- C:\Windows\system32\KBDBASH.DLL
2014-08-13 23:36:24 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-08-13 23:36:24 ----A---- C:\Windows\system32\tzres.dll
2014-08-13 23:36:18 ----A---- C:\Windows\system32\msi.dll
2014-08-13 23:36:17 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-08-13 23:36:16 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-08-13 23:36:16 ----A---- C:\Windows\system32\authui.dll
2014-08-13 23:36:15 ----A---- C:\Windows\system32\msihnd.dll
2014-08-13 23:36:15 ----A---- C:\Windows\system32\consent.exe
2014-08-13 23:36:14 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-08-13 23:36:09 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-08-13 23:36:07 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-08-13 23:36:07 ----A---- C:\Windows\system32\shell32.dll
2014-08-13 23:35:13 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-08-13 23:35:13 ----A---- C:\Windows\system32\rpcrt4.dll

======List of files/folders modified in the last 1 month======

2014-09-12 12:57:24 ----D---- C:\Windows\Temp
2014-09-12 12:48:51 ----D---- C:\Windows\SysWOW64
2014-09-12 12:48:25 ----D---- C:\Windows\system32\drivers
2014-09-12 12:48:06 ----D---- C:\Windows\system32\Tasks
2014-09-12 12:47:31 ----D---- C:\Windows\winsxs
2014-09-12 12:47:21 ----D---- C:\Windows
2014-09-12 12:47:06 ----A---- C:\Windows\system32\aswBoot.exe
2014-09-12 12:43:47 ----RD---- C:\Program Files
2014-09-12 12:41:33 ----D---- C:\ProgramData\AVAST Software
2014-09-12 12:40:48 ----SHD---- C:\System Volume Information
2014-09-12 12:09:01 ----D---- C:\Windows\pss
2014-09-12 12:07:06 ----D---- C:\Users\OLPE\AppData\Roaming\Seznam.cz
2014-09-12 12:07:02 ----D---- C:\Program Files (x86)\Seznam.cz
2014-09-12 12:03:03 ----D---- C:\Windows\inf
2014-09-12 12:03:02 ----D---- C:\Windows\Minidump
2014-09-12 12:03:02 ----D---- C:\Windows\debug
2014-09-12 11:21:56 ----D---- C:\Windows\tracing
2014-09-12 09:53:33 ----D---- C:\Windows\system32\config
2014-09-12 09:44:16 ----D---- C:\Windows\System32
2014-09-12 09:44:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-09-12 09:41:29 ----A---- C:\Windows\SYSWOW64\log.txt
2014-09-12 09:40:36 ----D---- C:\Users\OLPE\AppData\Roaming\Dropbox
2014-09-12 06:39:13 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-09-12 06:39:13 ----D---- C:\Windows\system32\cs-CZ
2014-09-11 09:18:32 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-09-11 07:30:30 ----D---- C:\Windows\Microsoft.NET
2014-09-11 07:25:55 ----RSD---- C:\Windows\assembly
2014-09-11 06:36:38 ----D---- C:\Windows\Prefetch
2014-09-11 06:33:52 ----D---- C:\Windows\system32\catroot
2014-09-11 06:33:15 ----D---- C:\Program Files\Internet Explorer
2014-09-11 06:33:13 ----D---- C:\Windows\SYSWOW64\en-US
2014-09-11 06:33:10 ----D---- C:\Windows\system32\en-US
2014-09-11 06:33:07 ----D---- C:\Program Files (x86)\Internet Explorer
2014-09-11 06:17:44 ----SHD---- C:\Windows\Installer
2014-09-11 06:17:41 ----HD---- C:\Config.Msi
2014-09-11 06:17:41 ----D---- C:\ProgramData\Microsoft Help
2014-09-11 06:13:26 ----D---- C:\Windows\system32\catroot2
2014-09-11 06:11:03 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-09-11 06:09:30 ----D---- C:\Program Files\Microsoft Security Client
2014-09-11 06:09:29 ----D---- C:\Program Files (x86)\Microsoft Security Client
2014-09-11 06:09:10 ----D---- C:\Windows\system32\MRT
2014-09-11 06:05:28 ----A---- C:\Windows\system32\MRT.exe
2014-09-11 06:04:11 ----SD---- C:\Windows\system32\CompatTel
2014-09-04 14:22:20 ----HD---- C:\ProgramData
2014-09-04 14:22:05 ----D---- C:\Program Files (x86)\Settings Manager
2014-08-31 11:23:07 ----D---- C:\Program Files (x86)\The KMPlayer
2014-08-19 10:08:57 ----D---- C:\Program Files\CCleaner
2014-08-14 07:15:30 ----D---- C:\Windows\rescache
2014-08-14 03:36:46 ----D---- C:\Program Files\Microsoft Silverlight
2014-08-14 03:36:43 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2014-08-14 03:34:25 ----D---- C:\Windows\ehome
2014-08-14 03:34:22 ----RSD---- C:\Windows\Fonts
2014-08-14 03:33:30 ----D---- C:\Windows\PolicyDefinitions

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-09-12 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-09-12 224896]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-04-27 540696]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-09-12 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-09-12 1041168]
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622;F06DEFF2-5B9C-490D-910F-35D3A9119622; \??\C:\Program Files (x86)\Settings Manager\smdmf\x64\smdmfmgrc2.cfg [2014-08-14 41872]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2010-11-29 82224]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-09-12 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-09-12 79184]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-09-12 92008]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2009-03-02 11576]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-12-17 2675712]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver; C:\Windows\system32\DRIVERS\btfilter.sys [2010-10-18 42096]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-01-13 2712680]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2011-02-08 38096]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\drivers\serscan.sys [2009-07-14 12288]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-02-03 1413680]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2011-01-20 291120]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2010-06-18 18872]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2010-08-30 94528]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2011-01-27 67384]
R3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-09-12 427360]
S2 DgiVecp;DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [2009-03-02 53816]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2011-05-13 36328]
S3 HTCAND64;HTC Device Driver; C:\Windows\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
S3 htcnprot;HTC NDIS Protocol Driver; C:\Windows\system32\DRIVERS\htcnprot.sys [2012-12-07 36928]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 29696]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2009-12-15 117248]
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 114304]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-10-29 250984]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2010-11-11 50864]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2010-04-26 63488]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 WinUsb;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-09-12 50344]
R2 Garmin Core Update Service;Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [2014-08-07 438616]
R2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-24 136176]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-05-06 325656]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 PassThru Service;Internet Pass-Through Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
R2 SmdmFService;SmdmF Service; C:\Program Files (x86)\Settings Manager\smdmf\SmdmFService.exe [2014-08-14 3572240]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-05-06 2533400]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-06-24 68608]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-11 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-06-24 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-24 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-08-19 111616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-12-08 137632]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2012-02-21 1255736]
S4 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
S4 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
S4 GFNEXSrv;GFNEX Service; C:\Windows\System32\GFNEXSrv.exe [2010-09-09 162824]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NVSvc;NVIDIA Driver Helper Service; C:\Windows\system32\nvvsvc.exe [2011-01-16 993896]
S4 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2010-04-12 196976]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zpomalené pc - hd plus

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

Re: zpomalené pc - hd plus

#3 Příspěvek od kubazzz »

posílám zatím log z adw... jrt se spustí, ale nic se neděje (čekal jsem cca 30 min)

# AdwCleaner v3.309 - Report created 12/09/2014 at 14:38:57
# Updated 02/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : OLPE - PRUNEROV
# Running from : C:\Users\OLPE\Desktop\adwcleaner_3.309.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : F06DEFF2-5B9C-490D-910F-35D3A9119622
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : SmdmFService

***** [ Files / Folders ] *****

[!] Folder Deleted : C:\ProgramData\smdmf
Folder Deleted : C:\ProgramData\systemk
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
[!] Folder Deleted : C:\Program Files (x86)\Settings Manager
[!] Folder Deleted : C:\Program Files (x86)\Plus-HD-V1.5
Folder Deleted : C:\Users\OLPE\AppData\Local\globalUpdate
Folder Deleted : C:\Users\OLPE\AppData\LocalLow\DataMngr
Folder Deleted : C:\Users\OLPE\AppData\Roaming\OpenCandy

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : 1a865e51-8d7f-47ac-a7cc-49d250e98ec8-11
Task Deleted : 1a865e51-8d7f-47ac-a7cc-49d250e98ec8-2
Task Deleted : 1a865e51-8d7f-47ac-a7cc-49d250e98ec8-3
Task Deleted : 1a865e51-8d7f-47ac-a7cc-49d250e98ec8-7

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0059562.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0059562.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0059562.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0059562.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522952262}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555955562}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566956662}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544954462}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522952262}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555955562}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566956662}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Linkey
Key Deleted : HKCU\Software\SmdmF
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\SystemK
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Plus-HD-V1.5
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\SmdmF
Key Deleted : HKLM\SOFTWARE\SystemK
Key Deleted : HKLM\SOFTWARE\Plus-HD-V1.5
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v37.0.2062.120

[ File : C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [12120 octets] - [12/09/2014 14:16:56]
AdwCleaner[S0].txt - [11242 octets] - [12/09/2014 14:38:57]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11303 octets] ##########

kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

Re: zpomalené pc - hd plus

#4 Příspěvek od kubazzz »

tak už se zadařilo i jrt:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by OLPE on p  12.09.2014 at 15:02:37,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511951162}



~~~ Files

Successfully deleted: [File] C:\Windows\syswow64\sho6B2D.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho943.tmp



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{03065534-3D25-45C5-AF0B-964D2A5D1B6F}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{0AAD2417-123D-4456-B78D-95936726836F}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{1069A162-FC03-4572-9E7F-3FB234FB3356}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{10BDBEB3-277B-450D-BEBC-A07E19150616}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{179EEA9E-A2C4-41C8-883F-11FABFBE1D4E}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{18EAF461-87F2-427A-9D04-20FC76FEFD45}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{1A8B22A0-E5E3-427A-BB82-B675846591AE}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{1D8FCC52-2A87-4F3F-8956-A02E39D56943}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{25C81E4F-5B68-4007-9B67-547AABC3559A}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{2CC0B7CE-DCE5-4CD2-8BB2-D418002EB665}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{2DF09391-D530-4BA0-993E-4BAFB7D4BFB9}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{2E0B029D-7652-48D8-8008-2401D8A80BA7}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{348E3DBD-0CCD-4AB8-AA8C-163CB031F343}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{34F97870-FEC8-4DD0-BFA9-C781B6BF3ACA}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{3948E987-EC2D-41AC-8EAA-3402E3738885}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{3AF2EBB8-60A9-43A6-AC6A-EAB0E69D467B}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{3B958594-A294-4AA5-A5BC-A1A39738FA31}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{3EBADB04-E168-4CA1-BAB2-042D55F7FB58}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{3F8C4E65-4657-428F-BC8C-9DAAB7963B4D}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{42AF65D7-9925-478B-8788-4727DD56D45D}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{4411B2CD-0F8C-4213-8ECC-F95B5D516795}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{494ABF05-1159-4B83-8DE0-01FCC405A847}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{51B8DD13-95B2-4B1C-B88E-B27FA2B9D9BF}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{552C1CCC-DED7-4A14-ABEB-7ED198517F7F}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{59DB4E2A-8FFB-41D7-A1D8-0FB66C862E28}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{5CE4BC5F-57DB-4C51-B43A-A5C731B2AA22}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{5D43AD74-4D06-42C7-8730-F104F27DB05A}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{5E7B7CE3-A882-421E-BE56-DE2124271F15}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{6231DF05-74F3-46E3-975C-77F64FCE18E1}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{62577260-E38F-478E-A084-729CDD826C32}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{636D4D74-5241-4550-A35B-9FF985A17B62}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{653BC2E8-D965-4ECD-87A6-F59E3469687A}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{66352B20-372E-45FF-8169-C3BD1C9B44A3}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{674818B4-6D15-4760-929E-3EE47F50F6DF}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{68C1E243-5A1C-4EF4-970E-43E29701DCA4}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{6A1770E1-EB7C-4F11-A5AB-6E4334C251C0}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{6C0072E6-8905-4CA3-AF28-B6BB18AF21C8}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{708D9573-9198-4C41-9840-EED53C58FEDB}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{72B642DE-9939-4AC5-B6D0-36F101A941FC}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{76951CA0-973A-4EC7-93BC-8FAFED6C26E7}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{77BB239B-6DD4-41AE-AF9A-AF4B6BD391B7}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{7828AA5D-28BC-4445-B9E1-6288B5298991}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{7A5812EA-7571-4647-9E5E-6C07DC3E494E}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{7C2CE5C1-B289-49E0-90BF-962E12527535}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{8116C5A3-D40D-4E6A-BC02-6579A5151164}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{81417397-5EC1-4B23-B1F0-DFEACF4E9833}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{84AC2346-6047-4844-A75C-A207F473AB76}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{852308EF-3A88-45F6-A2A6-FD5C2C1D2D99}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{87D8D1AE-4128-4901-983F-C9E555C65AD4}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{89FBF52B-AC48-4702-942F-74E5428E2E36}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{9057FD4E-64D4-4465-A4F1-11E5DE6C80C2}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{97472144-471B-4058-9FC0-200DC38777F2}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{9A2F900C-7200-42F4-B947-57853E4AF8D9}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{9C69E7CC-6328-4349-A6AD-0BCEEB2E128E}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{9D324EDB-18A1-4D51-905E-3D2724EFC51A}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{9FDB889F-5DCF-462D-B4B6-E815C3AFFB0F}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{A34D6816-90B8-4210-8F32-1216E04B0EDB}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{A9F10AE7-B0B6-49EC-86FC-F05E2E401E72}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{AD747A0F-386B-4499-AD4E-1579A36B39D2}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{B208572E-EFC5-41B6-A8AC-DEFF35440B6D}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{B391839C-A248-430F-B091-72844B41037F}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{B75EF402-1618-417F-AE3C-B5DB89C21F93}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{B791815A-047C-4474-B643-EB1EE7761662}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{B80DE53D-CC34-46B3-A322-C9DAC444E08F}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{B822DBF7-D0E1-477B-A909-0C59DCBACAFC}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{BCB95FE1-C724-4CB8-BD73-240E6AE8C1D4}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{BDA4C36E-B9F8-4200-B193-91F41055BF05}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{C8A68B28-6AA5-4956-9F75-C1043DDEC4DF}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{C8C8A4FB-0C78-4736-935B-5077513FB967}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{CEA3A55C-1161-4FEF-8DE8-C88FB587A4A1}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{CEB4AF2B-249E-4051-A131-DFC711CFF5F7}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{D4E79C16-940A-499F-A4D6-8311A080986C}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{D5328B74-EFC1-41E4-BF5F-0811FD66E11D}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{D7C7EBAC-7A4C-4768-B1F8-9F13603E0B07}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{D8BCB7AA-F78F-4C8D-B79A-F0FB13262C22}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{DDC030C5-DD49-4352-9597-0381DB8C67D4}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{E0A8FCDA-9F13-4201-894C-713A19C19F3E}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{E56FECD7-A8C9-4828-90C6-0C38D21975D0}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{E6DBD1A8-0F79-448D-B318-A5A28D4F4699}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{E6F44565-6940-46CE-8DE8-8D46EB859B80}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{E7CD7000-3FB5-4B4D-A0C7-B099860B00ED}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{E8845BD4-D1A3-4C34-A22F-722D633A402E}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{EB0F55F2-D311-4474-AC42-4B3D7067E8B4}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{ECEA098A-26B5-41C4-8A98-89E9D00D9C04}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{ED6A866E-FDD6-4BF9-B725-649949BAE91C}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{EEC39274-9F97-4E36-B109-AE697052BCB3}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{F1B74962-3259-4E27-87BB-9A5F5C2C56A8}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{F3501F02-41E0-43A7-AD7A-87AA23CDCFD9}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{F41D039E-00CD-4C59-93BB-C39A4B71B2DB}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{F5C36920-C112-4239-84F8-1A9BE5B39C97}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{FAE2A713-7DFC-4D63-9200-4FF05B4B8C72}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{FB5CE62F-9174-4A10-BF15-A16A308E3CBD}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{FB8EA9F2-BF18-4434-BAB0-B622023A97D0}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{FD6B8624-CF1A-4691-A87E-8701CA045A9B}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{FE5D1308-FA4F-4DC9-866B-F042514E9FF5}
Successfully deleted: [Empty Folder] C:\Users\OLPE\appdata\local\{FF7A4FDD-94B3-43CB-939D-3C51DC33AE73}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  12.09.2014 at 15:11:45,59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zpomalené pc - hd plus

#5 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

Re: zpomalené pc - hd plus

#6 Příspěvek od kubazzz »

posílám log ze zoeku, jinak ntb se zdá mnohem lepší...

Zoek.exe v5.0.0.0 Updated 10-September-2014
Tool run by OLPE on so 13.09.2014 at 8:24:44,56.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\OLPE\Desktop\zoek.com [Scan all users] [Script inserted]

===== Runcheck 8:25:18,67 =====

--- Create Environment Variables 8:25:20,71
--- Create System Restore Point 8:25:32,36
--- Checking Input 8:26:05,44
--- Reset Hosts File 8:26:13,45
--- AU AppData Check 8:26:15,26
--- Remove From Windows Installer 8:26:21,97
--- IE Startpage Check 8:29:03,14
--- Program Files DB Check 8:30:07,27
--- C:\Users\Default\AppData\Roaming DB Check 8:31:07,97
--- C:\Users\Default User\AppData\Roaming DB Check 8:31:07,97
--- C:\Users\OLPE\AppData\Roaming DB Check 8:31:07,97
--- C:\Windows\SysNative\config\systemprofile\AppData\Roaming DB Check 8:31:07,97
--- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming DB Check 8:31:07,97
--- C:\Windows\serviceprofiles\networkservice\AppData\Roaming DB Check 8:31:07,97
--- C:\Windows\serviceprofiles\Localservice\AppData\Roaming DB Check 8:31:07,97
--- C:\Users\OLPE DB Check 8:33:47,96

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zpomalené pc - hd plus

#7 Příspěvek od vyosek »

Dejte sem procim log c:\zoek-result.log
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

Re: zpomalené pc - hd plus

#8 Příspěvek od kubazzz »

zdravím,
bohužel se mi se zoekem nedaří - vždy se zasekne (cca 2-3 hod se nic neděje) a k dokončení a restartu nedojde, zkoušel
jsem to vícekrát. Objevil se mi pouze tento log:

Zoek.exe v5.0.0.0 Updated 10-September-2014
Tool run by OLPE on so 13.09.2014 at 8:24:44,56.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\OLPE\Desktop\zoek.com [Scan all users] [Script inserted]

==== System Restore Info ======================

13.9.2014 8:26:02 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zpomalené pc - hd plus

#9 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

Re: zpomalené pc - hd plus

#10 Příspěvek od kubazzz »

zdravím,
byl jsem teď pracovně mimo, takže posílám log až dnes... (FRST launcher mi bohužel ale nejde stáhnout)

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by OLPE (administrator) on PRUNEROV on 18-09-2014 08:49:40
Running from C:\Users\OLPE\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Dropbox, Inc.) C:\Users\OLPE\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11775592 2011-01-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2011-01-10] (Realtek Semiconductor)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-09-12] (AVAST Software)
HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {759f3089-0753-11e4-8054-e06995931cec} - F:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {bead7ac8-dbcf-11e3-a802-e06995931cec} - F:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A02B07 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {d0285d56-56cd-11e1-b38e-e06995931cec} - G:\AutoRun.exe
HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {e79f4dcf-ac0f-11e2-8bab-e06995931cec} - F:\AutoRun.exe
Startup: C:\Users\OLPE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\OLPE\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: AutoCAD Digital Signatures Icon Overlay Handler -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {24ADBF89-54FD-4510-A1A0-B1E9B3D0B97C} URL =
SearchScopes: HKCU - {C9880D70-8886-4F99-8F3D-5A8D49754366} URL = http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
SearchScopes: HKCU - {D95F30F5-4885-4ACD-88F6-8AC063F169DE} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKCU - {EAF42603-B3B7-4081-8FF5-6F10FD791E3D} URL = http://rover.ebay.com/rover/1/710-71511 ... earchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Toolbar: HKCU - No Name - {34AB3C4C-DA1A-4067-96F4-31452C7CFE65} - No File
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-12]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR DefaultSearchKeyword: Default -> F8E7BD9328E3F267E05B8CB1E599DF6E535C0A9F02637294BFCFE1686F52B9D1
CHR DefaultSearchProvider: Default -> E29C2C402B81B7DB05848CC79570E6E4A9AF9816F660D90C27B24D8BAD91808B
CHR DefaultSearchURL: Default -> ABDBB19C7A2520999449BB4AD648E7B86F97F67DC9B46A505087E672A6FE9F0F
CHR Profile: C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Disk Google) - C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-12]
CHR Extension: (YouTube) - C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-12]
CHR Extension: (Vyhledávání Google) - C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-12]
CHR Extension: (avast! Online Security) - C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-12]
CHR Extension: (Peněženka Google) - C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12]
CHR Extension: (Gmail) - C:\Users\OLPE\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-12]
CHR HKLM-x32\...\Chrome\Extension: [adldappccjhelkmbkpiibilgnnjakieg] - C:\Program Files (x86)\VideoDownloadConverter_4z Chrome Extension\bar\VideoDownloadConvert@mindspark.com.gen1 [2013-12-14]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-09-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-09-12] (AVAST Software)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [438616 2014-08-07] (Garmin Ltd or its subsidiaries)
S4 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-09] ()
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-09-12] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-09-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-09-12] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-09-12] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-09-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-09-12] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-09-12] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-09-12] ()
S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [243200 2009-12-15] (Huawei Technologies Co., Ltd.)
S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed]
S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [29696 2009-12-15] (Huawei Tech. Co., Ltd.)
S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114304 2009-12-15] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-18 08:49 - 2014-09-18 08:50 - 00013692 _____ () C:\Users\OLPE\Desktop\FRST.txt
2014-09-18 08:49 - 2014-09-18 08:49 - 00000000 ____D () C:\FRST
2014-09-17 07:45 - 2014-09-17 07:46 - 00027648 ___SH () C:\Users\OLPE\Desktop\Thumbs.db
2014-09-15 14:45 - 2014-09-15 14:45 - 02105856 _____ (Farbar) C:\Users\OLPE\Desktop\FRST64.exe
2014-09-15 08:28 - 2014-09-15 08:28 - 00000000 ____D () C:\zoek
2014-09-15 08:17 - 2014-09-15 08:17 - 00001302 _____ () C:\zoek-results.log
2014-09-15 08:16 - 2014-09-15 08:16 - 01290240 _____ () C:\Users\OLPE\Desktop\zoek.exe
2014-09-13 08:39 - 2014-09-15 08:28 - 00000063 _____ () C:\folders.log
2014-09-13 08:24 - 2014-09-15 08:28 - 00002703 _____ () C:\runcheck.txt
2014-09-13 08:24 - 2014-09-13 08:24 - 00000000 ____D () C:\zoek_backup
2014-09-13 08:24 - 2014-09-13 08:24 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\WinRAR
2014-09-13 08:17 - 2014-09-13 08:17 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-09-13 08:17 - 2014-09-13 08:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-09-13 08:17 - 2014-09-13 08:17 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2014-09-12 14:56 - 2014-09-16 13:18 - 00000336 _____ () C:\Windows\setupact.log
2014-09-12 14:56 - 2014-09-15 09:04 - 00001310 _____ () C:\Windows\PFRO.log
2014-09-12 14:56 - 2014-09-12 14:56 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-12 14:36 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-12 14:16 - 2014-09-12 14:39 - 00000000 ____D () C:\AdwCleaner
2014-09-12 13:31 - 2014-09-12 13:31 - 01370467 _____ () C:\Users\OLPE\Desktop\adwcleaner_3.309.exe
2014-09-12 13:24 - 2014-09-12 13:24 - 00000000 ____D () C:\Windows\ERUNT
2014-09-12 13:22 - 2014-09-12 13:23 - 01016261 _____ (Thisisu) C:\Users\OLPE\Desktop\JRT.exe
2014-09-12 12:49 - 2014-09-12 12:49 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\AVAST Software
2014-09-12 12:49 - 2014-09-12 12:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-09-12 12:48 - 2014-09-12 14:58 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-12 12:47 - 2014-09-12 12:48 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-09-12 12:46 - 2014-09-12 12:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-09-12 12:43 - 2014-09-12 13:01 - 00000000 ____D () C:\Program Files\trend micro
2014-09-12 12:43 - 2014-09-12 12:45 - 00000000 ____D () C:\rsit
2014-09-12 12:43 - 2014-09-12 12:43 - 01222144 _____ () C:\Users\OLPE\Desktop\RSITx64.exe
2014-09-12 12:12 - 2014-09-12 13:36 - 00002250 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-12 12:12 - 2014-09-12 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-11 09:18 - 2014-09-11 09:18 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-09-11 06:12 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 06:12 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 06:12 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 06:12 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 06:12 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 06:12 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 06:12 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 06:12 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 06:12 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 06:12 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 06:12 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 06:12 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 06:12 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 06:12 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 06:12 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 06:12 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 06:12 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 06:12 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 06:12 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 06:12 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 06:12 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 06:12 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 06:12 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 06:12 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 06:12 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 06:12 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 06:12 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 06:12 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 06:12 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 06:12 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 06:12 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 06:12 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 06:12 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 06:12 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 06:12 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 06:12 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 06:12 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 06:12 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 06:12 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 06:12 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 06:12 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 06:12 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 06:12 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 06:12 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 06:12 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 06:12 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 06:12 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 06:12 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 06:12 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 06:12 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 06:12 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 06:12 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 06:12 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 06:12 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 06:12 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 06:12 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 06:04 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 06:04 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-10 13:51 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 13:51 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-10 13:51 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-10 13:51 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-10 13:51 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-10 13:51 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-10 13:51 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-10 13:50 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-10 13:50 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-10 13:50 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-10 13:50 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-04 14:22 - 2014-09-12 14:39 - 00000000 ____D () C:\ProgramData\smdmf
2014-08-29 05:48 - 2014-05-04 15:19 - 2138658816 _____ () C:\Users\OLPE\Desktop\47.Ronin.2013.480p.BDRip.AC3.XViD.CZ.4play.avi
2014-08-28 09:23 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 09:23 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 09:23 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-21 10:21 - 2014-08-21 10:21 - 00000000 ____D () C:\Users\OLPE\Desktop\Nová složka (3)
2014-08-20 09:31 - 2014-08-20 09:31 - 00001600 _____ () C:\Users\OLPE\Desktop\9866-005 – zástupce.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-18 08:50 - 2014-09-18 08:49 - 00013692 _____ () C:\Users\OLPE\Desktop\FRST.txt
2014-09-18 08:49 - 2014-09-18 08:49 - 00000000 ____D () C:\FRST
2014-09-18 08:47 - 2011-04-27 08:47 - 01712336 _____ () C:\Windows\WindowsUpdate.log
2014-09-18 08:27 - 2012-04-20 16:39 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-18 08:04 - 2013-05-18 10:17 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-18 07:31 - 2009-07-14 06:45 - 00025120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-18 07:31 - 2009-07-14 06:45 - 00025120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-18 07:25 - 2013-05-18 10:17 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-18 07:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-09-17 14:06 - 2014-01-12 15:30 - 00003966 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{CA964286-32E7-4072-AD72-4AC137609696}
2014-09-17 13:43 - 2013-07-31 11:00 - 00000000 ___RD () C:\Users\OLPE\Dropbox
2014-09-17 08:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-17 07:46 - 2014-09-17 07:45 - 00027648 ___SH () C:\Users\OLPE\Desktop\Thumbs.db
2014-09-16 13:18 - 2014-09-12 14:56 - 00000336 _____ () C:\Windows\setupact.log
2014-09-15 14:45 - 2014-09-15 14:45 - 02105856 _____ (Farbar) C:\Users\OLPE\Desktop\FRST64.exe
2014-09-15 09:08 - 2011-02-14 10:37 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-09-15 09:08 - 2011-02-14 10:37 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-09-15 09:08 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-15 09:05 - 2013-07-31 10:58 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\Dropbox
2014-09-15 09:04 - 2014-09-12 14:56 - 00001310 _____ () C:\Windows\PFRO.log
2014-09-15 09:04 - 2012-06-15 12:20 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-09-15 09:04 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-15 08:28 - 2014-09-15 08:28 - 00000000 ____D () C:\zoek
2014-09-15 08:28 - 2014-09-13 08:39 - 00000063 _____ () C:\folders.log
2014-09-15 08:28 - 2014-09-13 08:24 - 00002703 _____ () C:\runcheck.txt
2014-09-15 08:17 - 2014-09-15 08:17 - 00001302 _____ () C:\zoek-results.log
2014-09-15 08:16 - 2014-09-15 08:16 - 01290240 _____ () C:\Users\OLPE\Desktop\zoek.exe
2014-09-13 08:24 - 2014-09-13 08:24 - 00000000 ____D () C:\zoek_backup
2014-09-13 08:24 - 2014-09-13 08:24 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\WinRAR
2014-09-13 08:17 - 2014-09-13 08:17 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-09-13 08:17 - 2014-09-13 08:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-09-13 08:17 - 2014-09-13 08:17 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2014-09-12 14:58 - 2014-09-12 12:48 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-12 14:56 - 2014-09-12 14:56 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-12 14:39 - 2014-09-12 14:16 - 00000000 ____D () C:\AdwCleaner
2014-09-12 14:39 - 2014-09-04 14:22 - 00000000 ____D () C:\ProgramData\smdmf
2014-09-12 14:39 - 2014-06-24 19:25 - 00000000 ____D () C:\Program Files (x86)\Plus-HD-V1.5
2014-09-12 14:38 - 2014-06-24 19:25 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-09-12 13:36 - 2014-09-12 12:12 - 00002250 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-12 13:31 - 2014-09-12 13:31 - 01370467 _____ () C:\Users\OLPE\Desktop\adwcleaner_3.309.exe
2014-09-12 13:24 - 2014-09-12 13:24 - 00000000 ____D () C:\Windows\ERUNT
2014-09-12 13:23 - 2014-09-12 13:22 - 01016261 _____ (Thisisu) C:\Users\OLPE\Desktop\JRT.exe
2014-09-12 13:01 - 2014-09-12 12:43 - 00000000 ____D () C:\Program Files\trend micro
2014-09-12 12:49 - 2014-09-12 12:49 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\AVAST Software
2014-09-12 12:49 - 2014-09-12 12:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-09-12 12:48 - 2014-09-12 12:47 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-09-12 12:47 - 2014-09-12 12:47 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-09-12 12:47 - 2013-03-19 11:35 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-09-12 12:47 - 2013-03-19 11:35 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-09-12 12:47 - 2011-10-24 13:13 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-09-12 12:46 - 2014-09-12 12:46 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-09-12 12:45 - 2014-09-12 12:43 - 00000000 ____D () C:\rsit
2014-09-12 12:43 - 2014-09-12 12:43 - 01222144 _____ () C:\Users\OLPE\Desktop\RSITx64.exe
2014-09-12 12:41 - 2011-10-24 13:13 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-09-12 12:12 - 2014-09-12 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-09-12 12:09 - 2013-02-12 12:48 - 00000000 ____D () C:\Windows\pss
2014-09-12 12:07 - 2013-11-05 01:25 - 00000000 ____D () C:\Users\OLPE\AppData\Roaming\Seznam.cz
2014-09-12 12:07 - 2012-03-01 16:01 - 00000000 ____D () C:\Program Files (x86)\Seznam.cz
2014-09-12 12:03 - 2012-06-21 06:46 - 00000000 ____D () C:\Windows\Minidump
2014-09-11 09:18 - 2014-09-11 09:18 - 17903792 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-09-11 09:18 - 2012-04-20 16:39 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-11 09:18 - 2012-04-20 16:39 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-11 09:18 - 2012-04-20 16:39 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-11 06:17 - 2011-11-02 17:15 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 06:11 - 2011-10-24 12:27 - 01560276 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 06:09 - 2013-08-01 03:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 06:09 - 2013-04-19 16:28 - 00002124 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-09-11 06:09 - 2013-04-19 16:28 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-09-11 06:09 - 2013-04-19 16:28 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-09-11 06:09 - 2013-04-19 16:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-09-11 06:05 - 2012-02-20 08:10 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-11 06:04 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-05 09:52 - 2013-08-13 09:06 - 00000000 ____D () C:\Users\OLPE\Desktop\plechy D
2014-09-05 04:10 - 2014-09-10 13:50 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-05 04:05 - 2014-09-10 13:50 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-04 14:22 - 2014-06-24 19:26 - 00000000 ____D () C:\Program Files (x86)\Settings Manager
2014-08-31 11:23 - 2013-11-04 23:25 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer
2014-08-29 03:18 - 2009-07-14 06:45 - 00409672 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-23 04:07 - 2014-08-28 09:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 09:23 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 09:23 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 16:59 - 2013-11-20 22:47 - 00000000 ____D () C:\Users\OLPE\Desktop\pomocné konstrukce
2014-08-21 10:21 - 2014-08-21 10:21 - 00000000 ____D () C:\Users\OLPE\Desktop\Nová složka (3)
2014-08-20 09:31 - 2014-08-20 09:31 - 00001600 _____ () C:\Users\OLPE\Desktop\9866-005 – zástupce.lnk
2014-08-19 20:05 - 2014-09-11 06:12 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-19 19:39 - 2014-09-11 06:12 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-19 10:14 - 2013-04-23 07:23 - 00000873 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-08-19 10:09 - 2013-08-10 13:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-19 10:08 - 2012-11-12 16:00 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-19 01:01 - 2014-09-11 06:12 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-19 00:29 - 2014-09-11 06:12 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-19 00:29 - 2014-09-11 06:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-19 00:26 - 2014-09-11 06:12 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-19 00:20 - 2014-09-11 06:12 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-19 00:19 - 2014-09-11 06:12 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-19 00:15 - 2014-09-11 06:12 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-19 00:15 - 2014-09-11 06:12 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-19 00:14 - 2014-09-11 06:12 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-19 00:14 - 2014-09-11 06:12 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-19 00:08 - 2014-09-11 06:12 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-19 00:08 - 2014-09-11 06:12 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-19 00:08 - 2014-09-11 06:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-19 00:05 - 2014-09-11 06:12 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-19 00:03 - 2014-09-11 06:12 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-19 00:03 - 2014-09-11 06:12 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-19 00:03 - 2014-09-11 06:12 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe

Some content of TEMP:
====================
C:\Users\OLPE\AppData\Local\Temp\7za.exe
C:\Users\OLPE\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcqxsul.dll
C:\Users\OLPE\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpxlqprd.dll
C:\Users\OLPE\AppData\Local\Temp\hijackthis.exe
C:\Users\OLPE\AppData\Local\Temp\NirCmd.exe
C:\Users\OLPE\AppData\Local\Temp\PEVZ.EXE
C:\Users\OLPE\AppData\Local\Temp\Quarantine.exe
C:\Users\OLPE\AppData\Local\Temp\remove.exe
C:\Users\OLPE\AppData\Local\Temp\sed.exe
C:\Users\OLPE\AppData\Local\Temp\shortcut.exe
C:\Users\OLPE\AppData\Local\Temp\SHSetup.exe
C:\Users\OLPE\AppData\Local\Temp\swreg.exe
C:\Users\OLPE\AppData\Local\Temp\swxcacls.exe
C:\Users\OLPE\AppData\Local\Temp\wget.exe
C:\Users\OLPE\AppData\Local\Temp\zoek-delete.exe
C:\Users\OLPE\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-17 07:37

==================== End Of Log ============================
Přílohy
Addition.rar
(9.06 KiB) Staženo 18 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zpomalené pc - hd plus

#11 Příspěvek od vyosek »

:arrow: Mate tam dva antiviry - MSE a Avast, jeden z nich musi pryc, jinak budou kolidovat. Takze ktery???
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kubazzz
Návštěvník
Návštěvník
Příspěvky: 54
Registrován: 21 zář 2010 20:01

Re: zpomalené pc - hd plus

#12 Příspěvek od kubazzz »

tak jsem odinstaloval mse....

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zpomalené pc - hd plus

#13 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    
    HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
    HKLM-x32\...\Run: [] => [X]
    HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-08-07] (Garmin Ltd or its subsidiaries)
    HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {759f3089-0753-11e4-8054-e06995931cec} - F:\HTC_Sync_Manager_PC.exe
    HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {bead7ac8-dbcf-11e3-a802-e06995931cec} - F:\AutoRun.exe {D2D77DC2-8299-11D1-8949-444553540000} 5.2088.1.A02B07 PID_0083 {01D42BF0-ED08-463f-8A28-99EB6FEE962B}
    HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {d0285d56-56cd-11e1-b38e-e06995931cec} - G:\AutoRun.exe
    HKU\S-1-5-21-685113854-4160033775-173958377-1000\...\MountPoints2: {e79f4dcf-ac0f-11e2-8bab-e06995931cec} - F:\AutoRun.exe
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://toshiba.msn.com
    SearchScopes: HKCU - {24ADBF89-54FD-4510-A1A0-B1E9B3D0B97C} URL =
    SearchScopes: HKCU - {C9880D70-8886-4F99-8F3D-5A8D49754366} URL = http://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2
    SearchScopes: HKCU - {EAF42603-B3B7-4081-8FF5-6F10FD791E3D} URL = http://rover.ebay.com/rover/1/710-71511 ... 4?satitle={searchTerms}
    
    R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
    
    2014-09-18 08:49 - 2014-09-18 08:50 - 00013692 _____ () C:\Users\OLPE\Desktop\FRST.txt
    2014-09-15 08:28 - 2014-09-15 08:28 - 00000000 ____D () C:\zoek
    2014-09-15 08:17 - 2014-09-15 08:17 - 00001302 _____ () C:\zoek-results.log
    2014-09-15 08:16 - 2014-09-15 08:16 - 01290240 _____ () C:\Users\OLPE\Desktop\zoek.exe
    2014-09-13 08:39 - 2014-09-15 08:28 - 00000063 _____ () C:\folders.log
    2014-09-13 08:24 - 2014-09-15 08:28 - 00002703 _____ () C:\runcheck.txt
    2014-09-13 08:24 - 2014-09-13 08:24 - 00000000 ____D () C:\zoek_backup
    2014-09-12 14:36 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
    2014-09-12 14:16 - 2014-09-12 14:39 - 00000000 ____D () C:\AdwCleaner
    2014-09-12 13:31 - 2014-09-12 13:31 - 01370467 _____ () C:\Users\OLPE\Desktop\adwcleaner_3.309.exe
    2014-09-12 13:24 - 2014-09-12 13:24 - 00000000 ____D () C:\Windows\ERUNT
    2014-09-12 13:22 - 2014-09-12 13:23 - 01016261 _____ (Thisisu) C:\Users\OLPE\Desktop\JRT.exe
    2014-09-12 12:43 - 2014-09-12 13:01 - 00000000 ____D () C:\Program Files\trend micro
    2014-09-12 12:43 - 2014-09-12 12:45 - 00000000 ____D () C:\rsit
    2014-09-12 12:43 - 2014-09-12 12:43 - 01222144 _____ () C:\Users\OLPE\Desktop\RSITx64.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět