
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola PC
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Kontrola PC
Zdravim, prosím o kontrolu, jestli je všechno v cajku..
Nevím,jestli má něco vliv, ale poslední dobou mi skoro denně hodí BSOD :/
LOG :
Logfile of random's system information tool 1.10 (written by random/random)
Run by xxxxxx at 2014-12-26 10:28:16
Microsoft Windows 7 Professional
System drive C: has 292 GB (76%) free of 381 GB
Total RAM: 7931 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:07, on 26.12.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\xxxxxx.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [BitTorrent] "C:\Users\xxxxxx\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7156 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\Windows\system32\WLANExt.exe 30570144
\??\C:\Windows\system32\conhost.exe
atieclxx
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://go.microsoft.com/fwlink/?linkid= ... cid=0x0405"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3996.0.1489699108\395364892" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.861.1.2000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/Unused_3/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_91/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3996.2.865834314\603476382" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/Unused_3/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_91/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3996.5.231641472\1390177511" /prefetch:673131151
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/Unused_3/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_91/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3996.34.1214746065\2061877252" /prefetch:673131151
"C:\Users\xxxxxx\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-06 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-06 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2011-09-15 7466600]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-08-20 2821416]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11 30877280]
"BitTorrent"=C:\Users\xxxxxx\AppData\Roaming\BitTorrent\BitTorrent.exe [2014-12-01 1692248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Users\xxxxxx\AppData\Roaming\BitTorrent\BitTorrent.exe [2014-12-01 1692248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GSplay.exe]
C:\Users\xxxxxx\AppData\Local\Temp\Rar$EXa0.113\GSplay.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDD Regenerator]
C:\Program Files (x86)\HDD Regenerator\Shell.exe /1 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPFanControl]
C:\Program Files\HPFanControl\HPFanControl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-08-10 343168]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-12-26 10:28:17 ----D---- C:\Program Files\trend micro
2014-12-26 10:28:16 ----D---- C:\rsit
2014-12-23 01:14:24 ----D---- C:\Program Files (x86)\CountDown ShutDown PC
2014-12-20 04:14:44 ----D---- C:\Users\xxxxxx\AppData\Roaming\hpqLog
2014-12-20 04:05:04 ----D---- C:\Program Files (x86)\globalUpdate
2014-12-20 04:00:50 ----D---- C:\ProgramData\IePluginServices
2014-12-20 04:00:42 ----D---- C:\ProgramData\WindowsMangerProtect
2014-12-18 16:13:27 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\system32\d3dcsx_43.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\xactengine3_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-12-18 11:09:19 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-12-18 11:09:19 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-12-18 11:09:18 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-12-18 11:09:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-12-18 11:09:18 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-12-18 11:09:18 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-12-18 11:09:15 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-12-18 11:09:15 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-12-18 11:09:14 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-12-18 11:09:11 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-12-18 11:09:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-12-18 11:09:11 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-12-18 11:09:11 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-12-18 11:09:10 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-12-18 11:09:10 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-12-18 11:09:10 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-12-18 11:09:10 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-12-18 11:09:10 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-12-18 11:09:10 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-12-18 11:09:09 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-12-18 11:09:09 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-12-18 11:09:08 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-12-18 11:09:08 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-12-18 11:09:07 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-12-18 11:09:07 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-12-18 11:09:06 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-12-18 11:09:02 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-12-18 11:09:02 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-12-18 11:09:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-12-18 11:09:01 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-12-18 11:09:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-12-18 11:09:01 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-12-18 11:09:01 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-12-18 11:09:01 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-12-18 11:09:00 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-12-18 11:09:00 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-12-18 11:09:00 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-12-18 11:09:00 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-12-18 11:08:59 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-12-18 11:08:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-12-18 11:08:59 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-12-18 11:08:59 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-12-18 11:08:57 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-12-18 11:08:57 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-12-18 11:08:55 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-12-18 11:08:55 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-12-18 11:08:55 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-12-18 11:08:55 ----A---- C:\Windows\system32\xinput1_3.dll
2014-12-18 11:08:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-12-18 11:08:55 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-12-18 11:08:54 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-12-18 11:08:53 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-12-18 11:08:53 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-12-18 11:08:53 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-12-18 11:08:53 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-12-18 11:08:53 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-12-18 11:08:53 ----A---- C:\Windows\system32\d3dx10.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-12-18 11:08:51 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-12-18 11:08:51 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-12-18 11:08:51 ----A---- C:\Windows\system32\xinput1_2.dll
2014-12-18 11:08:51 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-12-18 11:08:50 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-12-18 11:08:50 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-12-18 11:08:50 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-12-18 11:08:50 ----A---- C:\Windows\system32\xinput1_1.dll
2014-12-18 11:08:50 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-12-18 11:08:50 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-12-18 11:08:45 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-12-18 11:08:45 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-12-18 11:08:44 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-12-18 11:08:44 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-12-18 11:08:44 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-12-18 11:08:44 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-12-18 11:08:42 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-12-18 11:08:42 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-12-18 11:08:41 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-12-18 11:08:41 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-12-18 11:08:40 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-12-18 11:08:40 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-12-18 11:08:40 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-12-18 11:08:40 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-12-18 10:52:56 ----D---- C:\Program Files (x86)\2K Games
2014-12-18 10:49:36 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2014-12-18 10:49:32 ----D---- C:\Users\xxxxxx\AppData\Roaming\DAEMON Tools Lite
2014-12-18 10:49:29 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2014-12-18 10:48:50 ----D---- C:\ProgramData\DAEMON Tools Lite
2014-12-16 13:44:50 ----D---- C:\Users\xxxxxx\AppData\Roaming\TS3Client
2014-12-16 13:44:06 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2014-12-15 02:05:13 ----D---- C:\Users\xxxxxx\AppData\Roaming\IsolatedStorage
2014-12-15 02:05:13 ----D---- C:\ProgramData\IsolatedStorage
2014-12-14 01:22:38 ----D---- C:\Program Files (x86)\SpeedFan
2014-12-13 18:12:34 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-12-13 18:11:06 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\PresentationHost.exe
2014-12-13 18:09:30 ----A---- C:\Windows\system32\netfxperf.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\mscoree.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\dfshim.dll
2014-12-13 18:08:35 ----A---- C:\Windows\SYSWOW64\vp6vfw.dll
2014-12-13 18:08:07 ----D---- C:\ProgramData\Package Cache
2014-12-13 17:14:08 ----D---- C:\Hry
2014-12-10 18:47:42 ----D---- C:\Program Files (x86)\Polda 5
2014-12-08 00:55:41 ----D---- C:\Windows\Minidump
2014-12-07 23:58:05 ----D---- C:\Users\xxxxxx\AppData\Roaming\.mono
2014-12-07 23:58:05 ----D---- C:\ProgramData\.mono
2014-12-07 23:57:57 ----D---- C:\Users\xxxxxx\AppData\Roaming\Unity
2014-12-07 00:21:22 ----AH---- C:\Windows\system32\hamachi.sys
2014-12-07 00:21:20 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2014-12-07 00:20:55 ----D---- C:\ProgramData\LogMeIn
2014-12-06 23:39:40 ----D---- C:\ProgramData\Sun
2014-12-06 23:39:37 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-12-06 23:39:19 ----D---- C:\ProgramData\Oracle
2014-12-06 23:39:11 ----D---- C:\Program Files (x86)\Java
2014-12-05 18:37:39 ----D---- C:\Users\xxxxxx\AppData\Roaming\Vodafone
2014-12-05 18:37:01 ----D---- C:\ProgramData\Vodafone
2014-12-05 18:36:50 ----D---- C:\ProgramData\Macrovision
2014-12-05 18:36:50 ----D---- C:\ProgramData\FLEXnet
2014-12-03 22:18:21 ----D---- C:\Users\xxxxxx\AppData\Roaming\vlc
2014-12-03 22:18:09 ----D---- C:\Program Files (x86)\VideoLAN
2014-12-03 17:33:33 ----D---- C:\Fraps
2014-12-03 15:13:53 ----D---- C:\Program Files\Windows Sidebar
2014-12-03 15:13:53 ----D---- C:\Program Files (x86)\Windows Media Player
2014-12-03 15:13:52 ----D---- C:\Windows\ehome
2014-12-02 20:43:57 ----D---- C:\Program Files (x86)\TeamViewer
2014-12-02 13:43:59 ----A---- C:\Windows\system32\RTNUninst64.dll
2014-12-02 13:43:59 ----A---- C:\Windows\system32\RtNicProp64.dll
2014-12-02 13:43:59 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2014-12-01 23:48:54 ----D---- C:\Program Files (x86)\HDD Regenerator
2014-12-01 23:46:14 ----D---- C:\ProgramData\APN
2014-12-01 23:45:52 ----D---- C:\Users\xxxxxx\AppData\Roaming\BitTorrent
2014-12-01 05:49:59 ----D---- C:\Users\xxxxxx\AppData\Roaming\WinRAR
2014-12-01 05:49:35 ----D---- C:\Program Files\WinRAR
2014-11-30 20:07:49 ----D---- C:\ProgramData\Riot Games
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-11-30 20:06:42 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-11-30 20:06:17 ----D---- C:\Riot Games
2014-11-30 20:04:53 ----D---- C:\Users\xxxxxx\AppData\Roaming\Riot Games
2014-11-30 18:35:37 ----D---- C:\Users\xxxxxx\AppData\Roaming\ATI
2014-11-30 18:35:37 ----D---- C:\ProgramData\ATI
2014-11-30 18:34:15 ----D---- C:\Users\xxxxxx\AppData\Roaming\Synaptics
2014-11-30 18:34:15 ----D---- C:\ProgramData\Synaptics
2014-11-30 18:28:13 ----D---- C:\Users\xxxxxx\AppData\Roaming\Skype
2014-11-30 18:28:06 ----RD---- C:\Program Files (x86)\Skype
2014-11-30 18:28:02 ----D---- C:\ProgramData\Skype
2014-11-30 18:27:51 ----D---- C:\Program Files\Synaptics
2014-11-30 18:26:39 ----D---- C:\Windows\SYSWOW64\RTCOM
2014-11-30 18:26:39 ----D---- C:\Program Files\Realtek
2014-11-30 18:26:23 ----A---- C:\Windows\system32\drivers\RTHDAEQ0.dat
2014-11-30 18:26:23 ----A---- C:\Windows\system32\drivers\RTEQEX0.dat
2014-11-30 18:26:18 ----A---- C:\Windows\system32\SRSWOW64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\SRSTSX64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtPgEx64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtkCfg64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtkAPO64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtkApi64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEEP64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEEL64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEEG64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEED64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTCOM64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RP3DHT64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RP3DAA64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RCoInst64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2014-11-30 18:26:16 ----D---- C:\Program Files (x86)\Realtek
2014-11-30 18:26:16 ----A---- C:\Windows\system32\AERTAR64.dll
2014-11-30 18:26:16 ----A---- C:\Windows\system32\AERTAC64.dll
2014-11-30 18:26:14 ----HD---- C:\Program Files (x86)\Temp
2014-11-30 18:26:14 ----A---- C:\Windows\RtlExUpd.dll
2014-11-30 17:56:48 ----D---- C:\Program Files (x86)\AMD APP
2014-11-30 17:56:46 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-11-30 17:56:41 ----DC---- C:\Windows\system32\DRVSTORE
2014-11-30 17:56:41 ----A---- C:\Windows\system32\drivers\usbfilter.sys
2014-11-30 17:55:59 ----D---- C:\ProgramData\AMD
2014-11-30 17:55:59 ----A---- C:\Windows\system32\drivers\amdiox64.sys
2014-11-30 17:55:14 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-30 17:54:17 ----N---- C:\Windows\system32\MpSigStub.exe
2014-11-30 17:54:16 ----D---- C:\Program Files\ATI Technologies
2014-11-30 17:54:13 ----D---- C:\Program Files\ATI
2014-11-30 17:53:46 ----D---- C:\Program Files (x86)\AMD High-Definition Graphics Driver
2014-11-30 17:51:07 ----D---- C:\Program Files (x86)\Google
2014-11-30 17:49:10 ----D---- C:\Windows\system32\nn-NO
2014-11-30 17:49:10 ----D---- C:\Windows\Options
2014-11-30 17:49:10 ----A---- C:\Windows\system32\drivers\athrx.sys
2014-11-30 17:49:10 ----A---- C:\Windows\system32\athihvui.dll
2014-11-30 17:49:10 ----A---- C:\Windows\system32\athihvs.dll
2014-11-30 17:49:02 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-11-30 17:49:02 ----D---- C:\Program Files (x86)\Cisco
2014-11-30 17:49:02 ----D---- C:\Program Files (x86)\Atheros
2014-11-30 17:47:50 ----D---- C:\ProgramData\Atheros
2014-11-30 17:47:46 ----D---- C:\SWSetup
2014-11-30 17:40:21 ----D---- C:\Windows\pss
2014-11-30 17:38:02 ----D---- C:\Windows\system32\appmgmt
2014-11-30 13:27:16 ----SHD---- C:\Windows\Installer
2014-11-30 13:26:16 ----AD---- C:\ProgramData\TEMP
2014-11-30 13:09:32 ----D---- C:\Users\xxxxxx\AppData\Roaming\Identities
2014-11-30 13:09:07 ----SD---- C:\Users\xxxxxx\AppData\Roaming\Microsoft
2014-11-30 13:09:07 ----D---- C:\Users\xxxxxx\AppData\Roaming\Media Center Programs
2014-11-30 13:07:23 ----SHD---- C:\Recovery
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Šablony
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Plocha
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Oblíbené položky
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Nabídka Start
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Dokumenty
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Data aplikací
2014-11-30 13:04:15 ----D---- C:\Windows\SoftwareDistribution
2014-11-30 13:01:31 ----D---- C:\Windows\Prefetch
2014-11-30 13:01:10 ----SHD---- C:\System Volume Information
2014-11-30 13:01:10 ----ASH---- C:\pagefile.sys
2014-11-30 13:01:10 ----ASH---- C:\hiberfil.sys
2014-11-30 13:00:31 ----D---- C:\Windows\Panther
======List of files/folders modified in the last 1 month======
2014-12-26 10:28:18 ----D---- C:\Windows\Temp
2014-12-26 10:28:17 ----RD---- C:\Program Files
2014-12-26 10:19:12 ----D---- C:\Windows\System32
2014-12-26 10:19:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-26 10:19:11 ----D---- C:\Windows\inf
2014-12-26 10:13:47 ----D---- C:\Windows
2014-12-25 17:32:56 ----D---- C:\Windows\system32\config
2014-12-23 01:14:24 ----RD---- C:\Program Files (x86)
2014-12-20 10:10:10 ----D---- C:\Windows\system32\Tasks
2014-12-20 10:10:09 ----D---- C:\Windows\Tasks
2014-12-20 06:04:23 ----D---- C:\Windows\system32\drivers
2014-12-20 06:04:23 ----D---- C:\Windows\system
2014-12-20 04:22:37 ----D---- C:\Windows\system32\wdi
2014-12-20 04:14:58 ----D---- C:\Windows\SysWOW64
2014-12-20 04:01:54 ----SD---- C:\ProgramData\Microsoft
2014-12-20 04:00:50 ----HD---- C:\ProgramData
2014-12-19 23:02:13 ----D---- C:\Windows\system32\catroot2
2014-12-18 11:08:50 ----RSD---- C:\Windows\assembly
2014-12-18 11:08:47 ----D---- C:\Windows\Microsoft.NET
2014-12-18 11:07:49 ----D---- C:\Windows\Logs
2014-12-18 10:50:41 ----D---- C:\Windows\system32\catroot
2014-12-18 10:50:40 ----D---- C:\Windows\system32\DriverStore
2014-12-16 13:44:25 ----D---- C:\Windows\winsxs
2014-12-13 18:13:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-12-13 18:13:16 ----D---- C:\Windows\system32\cs-CZ
2014-12-13 18:11:07 ----D---- C:\Windows\SYSWOW64\en-US
2014-12-13 18:11:07 ----D---- C:\Windows\system32\en-US
2014-12-13 18:08:35 ----D---- C:\Program Files (x86)\Common Files
2014-12-13 18:07:30 ----RSD---- C:\Windows\Fonts
2014-12-05 02:21:19 ----D---- C:\Windows\rescache
2014-12-03 18:01:43 ----D---- C:\Windows\LiveKernelReports
2014-12-03 15:13:53 ----D---- C:\Program Files\Windows Media Player
2014-12-03 15:13:53 ----D---- C:\Program Files\DVD Maker
2014-12-03 15:13:52 ----D---- C:\Windows\SYSWOW64\wbem
2014-12-03 15:13:52 ----D---- C:\Windows\SYSWOW64\migration
2014-12-03 15:13:52 ----D---- C:\Windows\system32\wbem
2014-12-03 15:13:52 ----D---- C:\Windows\PolicyDefinitions
2014-12-02 13:43:42 ----RD---- C:\Users
2014-11-30 18:30:54 ----D---- C:\Windows\system32\LogFiles
2014-11-30 17:56:46 ----D---- C:\Program Files\Common Files
2014-11-30 17:55:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-11-30 17:49:10 ----D---- C:\Windows\system32\zh-TW
2014-11-30 17:49:10 ----D---- C:\Windows\system32\zh-CN
2014-11-30 17:49:10 ----D---- C:\Windows\system32\tr-TR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\sv-SE
2014-11-30 17:49:10 ----D---- C:\Windows\system32\ru-RU
2014-11-30 17:49:10 ----D---- C:\Windows\system32\pt-PT
2014-11-30 17:49:10 ----D---- C:\Windows\system32\pl-PL
2014-11-30 17:49:10 ----D---- C:\Windows\system32\nl-NL
2014-11-30 17:49:10 ----D---- C:\Windows\system32\ko-KR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\ja-JP
2014-11-30 17:49:10 ----D---- C:\Windows\system32\it-IT
2014-11-30 17:49:10 ----D---- C:\Windows\system32\hu-HU
2014-11-30 17:49:10 ----D---- C:\Windows\system32\fr-FR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\fi-FI
2014-11-30 17:49:10 ----D---- C:\Windows\system32\es-ES
2014-11-30 17:49:10 ----D---- C:\Windows\system32\el-GR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\de-DE
2014-11-30 17:49:10 ----D---- C:\Windows\system32\da-DK
2014-11-30 13:27:21 ----D---- C:\Windows\system32\restore
2014-11-30 13:18:38 ----D---- C:\Windows\system32\CodeIntegrity
2014-11-30 13:09:27 ----SHD---- C:\$Recycle.Bin
2014-11-30 13:07:23 ----D---- C:\Program Files\Windows NT
2014-11-30 13:07:06 ----D---- C:\Windows\debug
2014-11-30 13:05:01 ----D---- C:\Windows\system32\sysprep
2014-11-30 13:03:51 ----D---- C:\Windows\system32\drivers\UMDF
2014-11-30 13:02:02 ----D---- C:\Windows\CSC
2014-11-30 13:00:09 ----D---- C:\Windows\Setup
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2011-04-16 79488]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2011-04-16 40064]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-06-17 16440]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-18 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-05 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-05 309760]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-04-21 2727424]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2011-07-14 114704]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-09-17 3073256]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-03-05 436840]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-08-20 391728]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-12-16 47232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-05 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-05 365568]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-12-20 715656]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2014-11-28 5419792]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2014-12-20 485888]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-30 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-30 107912]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
-----------------EOF-----------------
...
Nevím,jestli má něco vliv, ale poslední dobou mi skoro denně hodí BSOD :/
LOG :
Logfile of random's system information tool 1.10 (written by random/random)
Run by xxxxxx at 2014-12-26 10:28:16
Microsoft Windows 7 Professional
System drive C: has 292 GB (76%) free of 381 GB
Total RAM: 7931 MB (78% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:07, on 26.12.2014
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\xxxxxx.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... XY8OEF13GS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [BitTorrent] "C:\Users\xxxxxx\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - Fuyu LIMITED - C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 7156 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\Windows\system32\WLANExt.exe 30570144
\??\C:\Windows\system32\conhost.exe
atieclxx
C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://go.microsoft.com/fwlink/?linkid= ... cid=0x0405"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3996.0.1489699108\395364892" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --disable-accelerated-video-decode --gpu-vendor-id=0x1002 --gpu-device-id=0x68e4 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.861.1.2000 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/Unused_3/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_91/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3996.2.865834314\603476382" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/Unused_3/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_91/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3996.5.231641472\1390177511" /prefetch:673131151
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/EnhancedBookmarks/Default/ExtensionContentVerification/Bootstrap/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/Unused_3/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_17/UMA-Uniformity-Trial-1-Percent/group_91/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_07/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3996.34.1214746065\2061877252" /prefetch:673131151
"C:\Users\xxxxxx\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-06 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-06 172968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2011-09-15 7466600]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-08-20 2821416]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-12-11 30877280]
"BitTorrent"=C:\Users\xxxxxx\AppData\Roaming\BitTorrent\BitTorrent.exe [2014-12-01 1692248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Users\xxxxxx\AppData\Roaming\BitTorrent\BitTorrent.exe [2014-12-01 1692248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GSplay.exe]
C:\Users\xxxxxx\AppData\Local\Temp\Rar$EXa0.113\GSplay.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDD Regenerator]
C:\Program Files (x86)\HDD Regenerator\Shell.exe /1 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPFanControl]
C:\Program Files\HPFanControl\HPFanControl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07 507776]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-08-10 343168]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-12-26 10:28:17 ----D---- C:\Program Files\trend micro
2014-12-26 10:28:16 ----D---- C:\rsit
2014-12-23 01:14:24 ----D---- C:\Program Files (x86)\CountDown ShutDown PC
2014-12-20 04:14:44 ----D---- C:\Users\xxxxxx\AppData\Roaming\hpqLog
2014-12-20 04:05:04 ----D---- C:\Program Files (x86)\globalUpdate
2014-12-20 04:00:50 ----D---- C:\ProgramData\IePluginServices
2014-12-20 04:00:42 ----D---- C:\ProgramData\WindowsMangerProtect
2014-12-18 16:13:27 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-12-18 11:09:22 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-12-18 11:09:21 ----A---- C:\Windows\system32\d3dcsx_43.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2014-12-18 11:09:20 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\XAudio2_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\xactengine3_6.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2014-12-18 11:09:20 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-12-18 11:09:19 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2014-12-18 11:09:19 ----A---- C:\Windows\system32\XAudio2_5.dll
2014-12-18 11:09:18 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2014-12-18 11:09:18 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2014-12-18 11:09:18 ----A---- C:\Windows\system32\xactengine3_5.dll
2014-12-18 11:09:18 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\system32\d3dx11_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\system32\d3dx10_42.dll
2014-12-18 11:09:16 ----A---- C:\Windows\system32\d3dcsx_42.dll
2014-12-18 11:09:15 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2014-12-18 11:09:15 ----A---- C:\Windows\system32\D3DX9_42.dll
2014-12-18 11:09:14 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\system32\D3DX9_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\system32\d3dx10_41.dll
2014-12-18 11:09:14 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\XAudio2_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\xactengine3_4.dll
2014-12-18 11:09:12 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2014-12-18 11:09:11 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2014-12-18 11:09:11 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2014-12-18 11:09:11 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-12-18 11:09:11 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2014-12-18 11:09:10 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2014-12-18 11:09:10 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2014-12-18 11:09:10 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2014-12-18 11:09:10 ----A---- C:\Windows\system32\XAudio2_3.dll
2014-12-18 11:09:10 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2014-12-18 11:09:10 ----A---- C:\Windows\system32\D3DX9_40.dll
2014-12-18 11:09:09 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2014-12-18 11:09:09 ----A---- C:\Windows\system32\xactengine3_3.dll
2014-12-18 11:09:08 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2014-12-18 11:09:08 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\XAudio2_2.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\xactengine3_2.dll
2014-12-18 11:09:08 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2014-12-18 11:09:07 ----A---- C:\Windows\system32\d3dx10_39.dll
2014-12-18 11:09:07 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2014-12-18 11:09:06 ----A---- C:\Windows\system32\D3DX9_39.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2014-12-18 11:09:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\XAudio2_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\xactengine3_1.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\d3dx10_38.dll
2014-12-18 11:09:04 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2014-12-18 11:09:02 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2014-12-18 11:09:02 ----A---- C:\Windows\system32\XAudio2_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\system32\xactengine3_0.dll
2014-12-18 11:09:02 ----A---- C:\Windows\system32\D3DX9_38.dll
2014-12-18 11:09:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2014-12-18 11:09:01 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2014-12-18 11:09:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2014-12-18 11:09:01 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2014-12-18 11:09:01 ----A---- C:\Windows\system32\d3dx10_37.dll
2014-12-18 11:09:01 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2014-12-18 11:09:00 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2014-12-18 11:09:00 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2014-12-18 11:09:00 ----A---- C:\Windows\system32\xactengine2_10.dll
2014-12-18 11:09:00 ----A---- C:\Windows\system32\D3DX9_37.dll
2014-12-18 11:08:59 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2014-12-18 11:08:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2014-12-18 11:08:59 ----A---- C:\Windows\system32\d3dx10_36.dll
2014-12-18 11:08:59 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2014-12-18 11:08:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\xactengine2_9.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\d3dx9_36.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\d3dx10_35.dll
2014-12-18 11:08:58 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2014-12-18 11:08:57 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2014-12-18 11:08:57 ----A---- C:\Windows\system32\d3dx9_35.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2014-12-18 11:08:56 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\xactengine2_8.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\d3dx10_34.dll
2014-12-18 11:08:56 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2014-12-18 11:08:55 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2014-12-18 11:08:55 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2014-12-18 11:08:55 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2014-12-18 11:08:55 ----A---- C:\Windows\system32\xinput1_3.dll
2014-12-18 11:08:55 ----A---- C:\Windows\system32\xactengine2_7.dll
2014-12-18 11:08:55 ----A---- C:\Windows\system32\d3dx9_34.dll
2014-12-18 11:08:54 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\system32\d3dx9_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\system32\d3dx10_33.dll
2014-12-18 11:08:54 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2014-12-18 11:08:53 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2014-12-18 11:08:53 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2014-12-18 11:08:53 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2014-12-18 11:08:53 ----A---- C:\Windows\system32\xactengine2_6.dll
2014-12-18 11:08:53 ----A---- C:\Windows\system32\xactengine2_5.dll
2014-12-18 11:08:53 ----A---- C:\Windows\system32\d3dx10.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2014-12-18 11:08:52 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\xactengine2_4.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\x3daudio1_1.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\d3dx9_32.dll
2014-12-18 11:08:52 ----A---- C:\Windows\system32\d3dx9_31.dll
2014-12-18 11:08:51 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2014-12-18 11:08:51 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2014-12-18 11:08:51 ----A---- C:\Windows\system32\xinput1_2.dll
2014-12-18 11:08:51 ----A---- C:\Windows\system32\xactengine2_3.dll
2014-12-18 11:08:50 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2014-12-18 11:08:50 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2014-12-18 11:08:50 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2014-12-18 11:08:50 ----A---- C:\Windows\system32\xinput1_1.dll
2014-12-18 11:08:50 ----A---- C:\Windows\system32\xactengine2_2.dll
2014-12-18 11:08:50 ----A---- C:\Windows\system32\xactengine2_1.dll
2014-12-18 11:08:45 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2014-12-18 11:08:45 ----A---- C:\Windows\system32\xactengine2_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\system32\x3daudio1_0.dll
2014-12-18 11:08:45 ----A---- C:\Windows\system32\d3dx9_30.dll
2014-12-18 11:08:44 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2014-12-18 11:08:44 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2014-12-18 11:08:44 ----A---- C:\Windows\system32\d3dx9_29.dll
2014-12-18 11:08:44 ----A---- C:\Windows\system32\d3dx9_28.dll
2014-12-18 11:08:42 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2014-12-18 11:08:42 ----A---- C:\Windows\system32\d3dx9_27.dll
2014-12-18 11:08:41 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2014-12-18 11:08:41 ----A---- C:\Windows\system32\d3dx9_26.dll
2014-12-18 11:08:40 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2014-12-18 11:08:40 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2014-12-18 11:08:40 ----A---- C:\Windows\system32\d3dx9_25.dll
2014-12-18 11:08:40 ----A---- C:\Windows\system32\d3dx9_24.dll
2014-12-18 10:52:56 ----D---- C:\Program Files (x86)\2K Games
2014-12-18 10:49:36 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2014-12-18 10:49:32 ----D---- C:\Users\xxxxxx\AppData\Roaming\DAEMON Tools Lite
2014-12-18 10:49:29 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2014-12-18 10:48:50 ----D---- C:\ProgramData\DAEMON Tools Lite
2014-12-16 13:44:50 ----D---- C:\Users\xxxxxx\AppData\Roaming\TS3Client
2014-12-16 13:44:06 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2014-12-15 02:05:13 ----D---- C:\Users\xxxxxx\AppData\Roaming\IsolatedStorage
2014-12-15 02:05:13 ----D---- C:\ProgramData\IsolatedStorage
2014-12-14 01:22:38 ----D---- C:\Program Files (x86)\SpeedFan
2014-12-13 18:12:34 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-12-13 18:11:06 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\PresentationHostProxy.dll
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\PresentationHost.exe
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\netfxperf.dll
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\mscoree.dll
2014-12-13 18:09:30 ----A---- C:\Windows\SYSWOW64\dfshim.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\PresentationHost.exe
2014-12-13 18:09:30 ----A---- C:\Windows\system32\netfxperf.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\mscoree.dll
2014-12-13 18:09:30 ----A---- C:\Windows\system32\dfshim.dll
2014-12-13 18:08:35 ----A---- C:\Windows\SYSWOW64\vp6vfw.dll
2014-12-13 18:08:07 ----D---- C:\ProgramData\Package Cache
2014-12-13 17:14:08 ----D---- C:\Hry
2014-12-10 18:47:42 ----D---- C:\Program Files (x86)\Polda 5
2014-12-08 00:55:41 ----D---- C:\Windows\Minidump
2014-12-07 23:58:05 ----D---- C:\Users\xxxxxx\AppData\Roaming\.mono
2014-12-07 23:58:05 ----D---- C:\ProgramData\.mono
2014-12-07 23:57:57 ----D---- C:\Users\xxxxxx\AppData\Roaming\Unity
2014-12-07 00:21:22 ----AH---- C:\Windows\system32\hamachi.sys
2014-12-07 00:21:20 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2014-12-07 00:20:55 ----D---- C:\ProgramData\LogMeIn
2014-12-06 23:39:40 ----D---- C:\ProgramData\Sun
2014-12-06 23:39:37 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2014-12-06 23:39:19 ----D---- C:\ProgramData\Oracle
2014-12-06 23:39:11 ----D---- C:\Program Files (x86)\Java
2014-12-05 18:37:39 ----D---- C:\Users\xxxxxx\AppData\Roaming\Vodafone
2014-12-05 18:37:01 ----D---- C:\ProgramData\Vodafone
2014-12-05 18:36:50 ----D---- C:\ProgramData\Macrovision
2014-12-05 18:36:50 ----D---- C:\ProgramData\FLEXnet
2014-12-03 22:18:21 ----D---- C:\Users\xxxxxx\AppData\Roaming\vlc
2014-12-03 22:18:09 ----D---- C:\Program Files (x86)\VideoLAN
2014-12-03 17:33:33 ----D---- C:\Fraps
2014-12-03 15:13:53 ----D---- C:\Program Files\Windows Sidebar
2014-12-03 15:13:53 ----D---- C:\Program Files (x86)\Windows Media Player
2014-12-03 15:13:52 ----D---- C:\Windows\ehome
2014-12-02 20:43:57 ----D---- C:\Program Files (x86)\TeamViewer
2014-12-02 13:43:59 ----A---- C:\Windows\system32\RTNUninst64.dll
2014-12-02 13:43:59 ----A---- C:\Windows\system32\RtNicProp64.dll
2014-12-02 13:43:59 ----A---- C:\Windows\system32\drivers\Rt64win7.sys
2014-12-01 23:48:54 ----D---- C:\Program Files (x86)\HDD Regenerator
2014-12-01 23:46:14 ----D---- C:\ProgramData\APN
2014-12-01 23:45:52 ----D---- C:\Users\xxxxxx\AppData\Roaming\BitTorrent
2014-12-01 05:49:59 ----D---- C:\Users\xxxxxx\AppData\Roaming\WinRAR
2014-12-01 05:49:35 ----D---- C:\Program Files\WinRAR
2014-11-30 20:07:49 ----D---- C:\ProgramData\Riot Games
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2014-11-30 20:06:43 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2014-11-30 20:06:42 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2014-11-30 20:06:17 ----D---- C:\Riot Games
2014-11-30 20:04:53 ----D---- C:\Users\xxxxxx\AppData\Roaming\Riot Games
2014-11-30 18:35:37 ----D---- C:\Users\xxxxxx\AppData\Roaming\ATI
2014-11-30 18:35:37 ----D---- C:\ProgramData\ATI
2014-11-30 18:34:15 ----D---- C:\Users\xxxxxx\AppData\Roaming\Synaptics
2014-11-30 18:34:15 ----D---- C:\ProgramData\Synaptics
2014-11-30 18:28:13 ----D---- C:\Users\xxxxxx\AppData\Roaming\Skype
2014-11-30 18:28:06 ----RD---- C:\Program Files (x86)\Skype
2014-11-30 18:28:02 ----D---- C:\ProgramData\Skype
2014-11-30 18:27:51 ----D---- C:\Program Files\Synaptics
2014-11-30 18:26:39 ----D---- C:\Windows\SYSWOW64\RTCOM
2014-11-30 18:26:39 ----D---- C:\Program Files\Realtek
2014-11-30 18:26:23 ----A---- C:\Windows\system32\drivers\RTHDAEQ0.dat
2014-11-30 18:26:23 ----A---- C:\Windows\system32\drivers\RTEQEX0.dat
2014-11-30 18:26:18 ----A---- C:\Windows\system32\SRSWOW64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\SRSTSX64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtPgEx64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtkCfg64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtkAPO64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RtkApi64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEEP64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEEL64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEEG64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTEED64A.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RTCOM64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RP3DHT64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RP3DAA64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\RCoInst64.dll
2014-11-30 18:26:18 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2014-11-30 18:26:16 ----D---- C:\Program Files (x86)\Realtek
2014-11-30 18:26:16 ----A---- C:\Windows\system32\AERTAR64.dll
2014-11-30 18:26:16 ----A---- C:\Windows\system32\AERTAC64.dll
2014-11-30 18:26:14 ----HD---- C:\Program Files (x86)\Temp
2014-11-30 18:26:14 ----A---- C:\Windows\RtlExUpd.dll
2014-11-30 17:56:48 ----D---- C:\Program Files (x86)\AMD APP
2014-11-30 17:56:46 ----D---- C:\Program Files\Common Files\ATI Technologies
2014-11-30 17:56:41 ----DC---- C:\Windows\system32\DRVSTORE
2014-11-30 17:56:41 ----A---- C:\Windows\system32\drivers\usbfilter.sys
2014-11-30 17:55:59 ----D---- C:\ProgramData\AMD
2014-11-30 17:55:59 ----A---- C:\Windows\system32\drivers\amdiox64.sys
2014-11-30 17:55:14 ----D---- C:\Program Files (x86)\ATI Technologies
2014-11-30 17:54:17 ----N---- C:\Windows\system32\MpSigStub.exe
2014-11-30 17:54:16 ----D---- C:\Program Files\ATI Technologies
2014-11-30 17:54:13 ----D---- C:\Program Files\ATI
2014-11-30 17:53:46 ----D---- C:\Program Files (x86)\AMD High-Definition Graphics Driver
2014-11-30 17:51:07 ----D---- C:\Program Files (x86)\Google
2014-11-30 17:49:10 ----D---- C:\Windows\system32\nn-NO
2014-11-30 17:49:10 ----D---- C:\Windows\Options
2014-11-30 17:49:10 ----A---- C:\Windows\system32\drivers\athrx.sys
2014-11-30 17:49:10 ----A---- C:\Windows\system32\athihvui.dll
2014-11-30 17:49:10 ----A---- C:\Windows\system32\athihvs.dll
2014-11-30 17:49:02 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-11-30 17:49:02 ----D---- C:\Program Files (x86)\Cisco
2014-11-30 17:49:02 ----D---- C:\Program Files (x86)\Atheros
2014-11-30 17:47:50 ----D---- C:\ProgramData\Atheros
2014-11-30 17:47:46 ----D---- C:\SWSetup
2014-11-30 17:40:21 ----D---- C:\Windows\pss
2014-11-30 17:38:02 ----D---- C:\Windows\system32\appmgmt
2014-11-30 13:27:16 ----SHD---- C:\Windows\Installer
2014-11-30 13:26:16 ----AD---- C:\ProgramData\TEMP
2014-11-30 13:09:32 ----D---- C:\Users\xxxxxx\AppData\Roaming\Identities
2014-11-30 13:09:07 ----SD---- C:\Users\xxxxxx\AppData\Roaming\Microsoft
2014-11-30 13:09:07 ----D---- C:\Users\xxxxxx\AppData\Roaming\Media Center Programs
2014-11-30 13:07:23 ----SHD---- C:\Recovery
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Šablony
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Plocha
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Oblíbené položky
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Nabídka Start
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Dokumenty
2014-11-30 13:07:23 ----SHD---- C:\ProgramData\Data aplikací
2014-11-30 13:04:15 ----D---- C:\Windows\SoftwareDistribution
2014-11-30 13:01:31 ----D---- C:\Windows\Prefetch
2014-11-30 13:01:10 ----SHD---- C:\System Volume Information
2014-11-30 13:01:10 ----ASH---- C:\pagefile.sys
2014-11-30 13:01:10 ----ASH---- C:\hiberfil.sys
2014-11-30 13:00:31 ----D---- C:\Windows\Panther
======List of files/folders modified in the last 1 month======
2014-12-26 10:28:18 ----D---- C:\Windows\Temp
2014-12-26 10:28:17 ----RD---- C:\Program Files
2014-12-26 10:19:12 ----D---- C:\Windows\System32
2014-12-26 10:19:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-26 10:19:11 ----D---- C:\Windows\inf
2014-12-26 10:13:47 ----D---- C:\Windows
2014-12-25 17:32:56 ----D---- C:\Windows\system32\config
2014-12-23 01:14:24 ----RD---- C:\Program Files (x86)
2014-12-20 10:10:10 ----D---- C:\Windows\system32\Tasks
2014-12-20 10:10:09 ----D---- C:\Windows\Tasks
2014-12-20 06:04:23 ----D---- C:\Windows\system32\drivers
2014-12-20 06:04:23 ----D---- C:\Windows\system
2014-12-20 04:22:37 ----D---- C:\Windows\system32\wdi
2014-12-20 04:14:58 ----D---- C:\Windows\SysWOW64
2014-12-20 04:01:54 ----SD---- C:\ProgramData\Microsoft
2014-12-20 04:00:50 ----HD---- C:\ProgramData
2014-12-19 23:02:13 ----D---- C:\Windows\system32\catroot2
2014-12-18 11:08:50 ----RSD---- C:\Windows\assembly
2014-12-18 11:08:47 ----D---- C:\Windows\Microsoft.NET
2014-12-18 11:07:49 ----D---- C:\Windows\Logs
2014-12-18 10:50:41 ----D---- C:\Windows\system32\catroot
2014-12-18 10:50:40 ----D---- C:\Windows\system32\DriverStore
2014-12-16 13:44:25 ----D---- C:\Windows\winsxs
2014-12-13 18:13:16 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-12-13 18:13:16 ----D---- C:\Windows\system32\cs-CZ
2014-12-13 18:11:07 ----D---- C:\Windows\SYSWOW64\en-US
2014-12-13 18:11:07 ----D---- C:\Windows\system32\en-US
2014-12-13 18:08:35 ----D---- C:\Program Files (x86)\Common Files
2014-12-13 18:07:30 ----RSD---- C:\Windows\Fonts
2014-12-05 02:21:19 ----D---- C:\Windows\rescache
2014-12-03 18:01:43 ----D---- C:\Windows\LiveKernelReports
2014-12-03 15:13:53 ----D---- C:\Program Files\Windows Media Player
2014-12-03 15:13:53 ----D---- C:\Program Files\DVD Maker
2014-12-03 15:13:52 ----D---- C:\Windows\SYSWOW64\wbem
2014-12-03 15:13:52 ----D---- C:\Windows\SYSWOW64\migration
2014-12-03 15:13:52 ----D---- C:\Windows\system32\wbem
2014-12-03 15:13:52 ----D---- C:\Windows\PolicyDefinitions
2014-12-02 13:43:42 ----RD---- C:\Users
2014-11-30 18:30:54 ----D---- C:\Windows\system32\LogFiles
2014-11-30 17:56:46 ----D---- C:\Program Files\Common Files
2014-11-30 17:55:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-11-30 17:49:10 ----D---- C:\Windows\system32\zh-TW
2014-11-30 17:49:10 ----D---- C:\Windows\system32\zh-CN
2014-11-30 17:49:10 ----D---- C:\Windows\system32\tr-TR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\sv-SE
2014-11-30 17:49:10 ----D---- C:\Windows\system32\ru-RU
2014-11-30 17:49:10 ----D---- C:\Windows\system32\pt-PT
2014-11-30 17:49:10 ----D---- C:\Windows\system32\pl-PL
2014-11-30 17:49:10 ----D---- C:\Windows\system32\nl-NL
2014-11-30 17:49:10 ----D---- C:\Windows\system32\ko-KR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\ja-JP
2014-11-30 17:49:10 ----D---- C:\Windows\system32\it-IT
2014-11-30 17:49:10 ----D---- C:\Windows\system32\hu-HU
2014-11-30 17:49:10 ----D---- C:\Windows\system32\fr-FR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\fi-FI
2014-11-30 17:49:10 ----D---- C:\Windows\system32\es-ES
2014-11-30 17:49:10 ----D---- C:\Windows\system32\el-GR
2014-11-30 17:49:10 ----D---- C:\Windows\system32\de-DE
2014-11-30 17:49:10 ----D---- C:\Windows\system32\da-DK
2014-11-30 13:27:21 ----D---- C:\Windows\system32\restore
2014-11-30 13:18:38 ----D---- C:\Windows\system32\CodeIntegrity
2014-11-30 13:09:27 ----SHD---- C:\$Recycle.Bin
2014-11-30 13:07:23 ----D---- C:\Program Files\Windows NT
2014-11-30 13:07:06 ----D---- C:\Windows\debug
2014-11-30 13:05:01 ----D---- C:\Windows\system32\sysprep
2014-11-30 13:03:51 ----D---- C:\Windows\system32\drivers\UMDF
2014-11-30 13:02:02 ----D---- C:\Windows\CSC
2014-11-30 13:00:09 ----D---- C:\Windows\Setup
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amd_sata;amd_sata; C:\Windows\system32\DRIVERS\amd_sata.sys [2011-04-16 79488]
R0 amd_xata;amd_xata; C:\Windows\system32\DRIVERS\amd_xata.sys [2011-04-16 40064]
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie64.sys [2010-06-17 16440]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2012-12-29 28664]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 514048]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-18 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-07-05 9359872]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-07-05 309760]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-04-21 2727424]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2011-07-14 114704]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-09-17 3073256]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-03-05 436840]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-08-20 391728]
R3 usbfilter;AMD USB Filter Driver; C:\Windows\system32\DRIVERS\usbfilter.sys [2010-12-16 47232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 165376]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 6656]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 34896]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-07-14 19968]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 200272]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 21760]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-07-05 204288]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-07-05 365568]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-12-20 715656]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2014-11-28 5419792]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [2014-12-20 485888]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-30 107912]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-30 107912]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
-----------------EOF-----------------
...
Re: Kontrola PC
Zdrvim 
Mate tam havet
Pouzivate nejaky antivir? Nevidim ho
Kouknete do slozky C:\Windows\Minidump . Pokud tam budou nejake soubory, uplodnete je treba na leteckou postu http://leteckaposta.cz/ a sem dejte odkaz na stazeni.
Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.

Mate tam havet





Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Kontrola PC
Antivir nemám, mám pár dnů po instalaci windowsu.. Měl jsem nějaký problémy s diskem,to vyřešil HDD regen, ale BSOD háže pořád
Přepastování, vyčištění nepomohlo... Potřebuji aby byl ještě cca 3 měsíce v klidu, pak budu kupovat novej NTB..
Jinak jsem dnes stahoval eset online scaner a ten našel 8 věcí co šlo hned pryč.. + co jsem prohlížel fora tak ještě malwarebytes a ten zase našel 52 věcí ..
______
Letecká pošta minidump -> http://leteckaposta.cz/182289231
LOG po restartu
# AdwCleaner v4.106 - Report created 26/12/2014 at 12:08:09
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Professional (64 bits)
# Username : Slipman - SLIPMAN-PC
# Running from : C:\Users\Slipman\Desktop\adwcleaner_4.106.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
[!] Folder Deleted : C:\Users\Slipman\AppData\Local\globalUpdate
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7600.16385
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R0].txt - [1721 octets] - [26/12/2014 12:06:24]
AdwCleaner[S0].txt - [1618 octets] - [26/12/2014 12:08:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1678 octets] ##########
Přepastování, vyčištění nepomohlo... Potřebuji aby byl ještě cca 3 měsíce v klidu, pak budu kupovat novej NTB..
Jinak jsem dnes stahoval eset online scaner a ten našel 8 věcí co šlo hned pryč.. + co jsem prohlížel fora tak ještě malwarebytes a ten zase našel 52 věcí ..
______
Letecká pošta minidump -> http://leteckaposta.cz/182289231
LOG po restartu
# AdwCleaner v4.106 - Report created 26/12/2014 at 12:08:09
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Professional (64 bits)
# Username : Slipman - SLIPMAN-PC
# Running from : C:\Users\Slipman\Desktop\adwcleaner_4.106.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
[!] Folder Deleted : C:\Users\Slipman\AppData\Local\globalUpdate
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.7600.16385
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R0].txt - [1721 octets] - [26/12/2014 12:06:24]
AdwCleaner[S0].txt - [1618 octets] - [26/12/2014 12:08:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1678 octets] ##########
Re: Kontrola PC

Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Kontrola PC
Jinak ty modre smrti zpusobuje atikmdag.sys . Mrknete do spravce zarizeni, jestli neni u grafiky vykricnik, nebo otaznik.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Kontrola PC
Uff,tak sken dokončen - http://leteckaposta.cz/992884480
Správce zařízení - grafika v pohodě.. http://ctrlv.cz/shots/2014/12/26/xlOV.png
Je ale pravda, že mi občas vyskočí, že grafický adaptér přestal odpovídat a byl obnoven či tak něco
Správce zařízení - grafika v pohodě.. http://ctrlv.cz/shots/2014/12/26/xlOV.png
Je ale pravda, že mi občas vyskočí, že grafický adaptér přestal odpovídat a byl obnoven či tak něco
Re: Kontrola PC
Ty nalezy jste mohl dat sem
Zkuste ovladac grafiky preinstalovat, pripadne aktualizovat.
Takova kontrolni otazka. Jak je to s legalitou systemu?
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 26.12.2014
Čas skenování: 12:19:37
Protokol: mbam.txt
Správce: Ano
Verze: 2.00.4.1028
Databáze malwaru: v2014.12.26.06
Databáze rootkitů: v2014.12.23.02
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7
CPU: x64
Souborový systém: NTFS
Uživatel: Slipman
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 371947
Uplynulý čas: 1 hod, 31 min, 50 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 0
(Žádné zákerné zjištěny položek)
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 2
PUP.Optional.SkyTech.A, C:\Users\Slipman\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7H7UY6OU\1[1].zip, , [bbb33b2c4d2fcb6bb2edb341b54c44bc],
Trojan.Agent.W, C:\Windows\Setup\SCRIPTS\Windows7Loader.exe, , [a3cb3334adcf0e2851fa5ed158ad0bf5],
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)
Zkuste ovladac grafiky preinstalovat, pripadne aktualizovat.
Takova kontrolni otazka. Jak je to s legalitou systemu?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Kontrola PC
Momentálně mam sosnutý Win 7 na test..
Měl jsem win 8 a tam mi přes utilitku házelo bsod na instalaci ovladačů grafiky.. ( Win 8 na HP nejsou )
Jinak mam momentálně ovladače ze stránek výrobce..
Měl jsem win 8 a tam mi přes utilitku házelo bsod na instalaci ovladačů grafiky.. ( Win 8 na HP nejsou )
Jinak mam momentálně ovladače ze stránek výrobce..
Re: Kontrola PC
Pak je mi lito, ale pravidla fora mi nedovoluji pokracovat.Cheaty píše:Momentálně mam sosnutý Win 7 na test..
Hovori jasne http://forum.viry.cz/viewtopic.php?f=12&t=115512
Pomáhat NELZE:
2) Pokud stroj uživatele prokazatelně obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.), je nutné navést uživatele k nápravě, např. skrze neplacený software,
a začít řešit, až v době kdy je PC "v pořádku". V případě že uživatel nechce na pravidla přistoupit,
je nutné jej vyzvat ať fórum opustí, a vrátí se až je splní.

Pokud jste si jisty, ze mate ten spravny ovladac, tak ho preinstalujte.
Jinak je to asi vse, bohuzel.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Re: Kontrola PC
Jasné, chápu.. Pohoda..
I tak ale díky za pomoc!
Posílam kilečko SMSkou alespoň za tuhle pomoc..
Čauko a ještě jednou díky!
I tak ale díky za pomoc!
Posílam kilečko SMSkou alespoň za tuhle pomoc..
Čauko a ještě jednou díky!
Re: Kontrola PC
Neni bohuzel zac
Za pripadny prispevek dekujeme
Mejte se a treba zase nekdy, snad s lepsim vysledkem


Za pripadny prispevek dekujeme

Mejte se a treba zase nekdy, snad s lepsim vysledkem


Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).
Možnost podpořit naše fórum https://platba.viry.cz/payment/
Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).