nelze spustit aplikace + iexplore.exe - chyba aplikace
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
Malwarebytes Anti-Malware
http://www.malwarebytes.org
Scan Date: 30.12.2014
Scan Time: 18:16:14
Logfile: mamt.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.30.06
Rootkit Database: v2014.12.29.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: petra
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 718609
Time Elapsed: 6 hr, 15 min, 14 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 25
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Application Updater\ApplicationUpdater.exe.vir, , [b846590ff587a096f216f2b003fe05fb],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe.vir, , [1ce22d3bdf9d82b43804cdfebe432ed2],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Spigot\Search Settings\wth187.dll.vir, , [7a84cb9ddba11b1b5fddf1da768bf10f],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Spigot\Search Settings\wthx187.dll.vir, , [9668d791bcc011253804fccf0cf5619f],
PUP.Optional.Norpalla.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Norpalla\NorpallaBHO.dll.vir, , [7d81cc9c7507999dd71b6223936eaf51],
PUP.Optional.Norpalla.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Norpalla\updateNorpalla.exe.vir, , [9e605d0bdca092a418db97eed62b21df],
PUP.Optional.Norpalla.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Norpalla\bin\utilNorpalla.exe.vir, , [798575f37a0287af12e14d3803fea35d],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\pdfforge Toolbar\WidgiHelper.exe.vir, , [cf2fc5a395e75dd98a7fb6ec56abf808],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\pdfforge Toolbar\IE\9.7\pdfforgeToolbarIE.dll.vir, , [7e80d395ff7de94d201c23a8b948a35d],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\pdfforge Toolbar\IE\9.7\pdfforgeToolbarIE64.dll.vir, , [738b1652dca0ed491b21b51618e94eb2],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir, , [fe00e187bfbdd85ec2f7495c2ad7d22e],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir, , [0df1a1c7314bb18504b54e57eb16649c],
PUP.Optional.SearchProtect, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader64.exe.vir, , [1ae42b3d07757eb8cf2115cfc33ebb45],
PUP.Optional.IEPluginService.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir, , [629c5b0da8d45bdbbdf280088b765da3],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir, , [0ef06107d2aa67cf8d2cc8dd48b9a759],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir, , [d925bdab1c602115b504abfa2cd5bc44],
PUP.Optional.IePluginService.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe.vir, , [23dbc6a24438d95dce0a87ee4db4fa06],
PUP.Optional.SupTab.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir, , [3fbf95d399e3cd69e9c9ee471de32dd3],
PUP.Optional.IePluginService.A, C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir, , [24da86e2770587af9d3bd69ff50c3cc4],
PUP.Optional.WPM.A, C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir, , [f70791d7f38989ad610109a05aa7837d],
Trojan.Zemot.ED, C:\ProgramData\Microsoft\Secure\Icons\temp\tmp54D3.exe, , [03fbc4a4bac294a24574ad510ff2ac54],
Backdoor.Bot, C:\ProgramData\Microsoft\Secure\Icons\temp\tmpC27C.exe, , [06f87fe96b11a88e7f92bf401be6f10f],
PUP.Optional.Excellent4App, D:\Dan\vyzvaneni\Sound effects - Chainsaw (1).exe, , [f10df474e09c1a1cc960326ccc3549b7],
PUP.Optional.Excellent4App, D:\Dan\vyzvaneni\Sound effects - Chainsaw.exe, , [57a76503691369cda188237bf30e2ad6],
Trojan.Agent.W, D:\download\windows 7 instal\sources\$OEM$\$$\SETUP\SCRIPTS\Windows7Loader.exe, , [35c9f3757c009f977e2acd6703028e72],
Physical Sectors: 0
(No malicious items detected)
(end)
behem testu 2x vyzkocilo avg s hlaskama viz priloha a tvarilo se, ze to vyresilo
http://www.malwarebytes.org
Scan Date: 30.12.2014
Scan Time: 18:16:14
Logfile: mamt.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.30.06
Rootkit Database: v2014.12.29.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: petra
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 718609
Time Elapsed: 6 hr, 15 min, 14 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 25
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Application Updater\ApplicationUpdater.exe.vir, , [b846590ff587a096f216f2b003fe05fb],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe.vir, , [1ce22d3bdf9d82b43804cdfebe432ed2],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Spigot\Search Settings\wth187.dll.vir, , [7a84cb9ddba11b1b5fddf1da768bf10f],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\Spigot\Search Settings\wthx187.dll.vir, , [9668d791bcc011253804fccf0cf5619f],
PUP.Optional.Norpalla.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Norpalla\NorpallaBHO.dll.vir, , [7d81cc9c7507999dd71b6223936eaf51],
PUP.Optional.Norpalla.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Norpalla\updateNorpalla.exe.vir, , [9e605d0bdca092a418db97eed62b21df],
PUP.Optional.Norpalla.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Norpalla\bin\utilNorpalla.exe.vir, , [798575f37a0287af12e14d3803fea35d],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\pdfforge Toolbar\WidgiHelper.exe.vir, , [cf2fc5a395e75dd98a7fb6ec56abf808],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\pdfforge Toolbar\IE\9.7\pdfforgeToolbarIE.dll.vir, , [7e80d395ff7de94d201c23a8b948a35d],
PUP.Optional.Spigot.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\pdfforge Toolbar\IE\9.7\pdfforgeToolbarIE64.dll.vir, , [738b1652dca0ed491b21b51618e94eb2],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir, , [fe00e187bfbdd85ec2f7495c2ad7d22e],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir, , [0df1a1c7314bb18504b54e57eb16649c],
PUP.Optional.SearchProtect, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader64.exe.vir, , [1ae42b3d07757eb8cf2115cfc33ebb45],
PUP.Optional.IEPluginService.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir, , [629c5b0da8d45bdbbdf280088b765da3],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir, , [0ef06107d2aa67cf8d2cc8dd48b9a759],
PUP.Optional.Skytech.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir, , [d925bdab1c602115b504abfa2cd5bc44],
PUP.Optional.IePluginService.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe.vir, , [23dbc6a24438d95dce0a87ee4db4fa06],
PUP.Optional.SupTab.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir, , [3fbf95d399e3cd69e9c9ee471de32dd3],
PUP.Optional.IePluginService.A, C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir, , [24da86e2770587af9d3bd69ff50c3cc4],
PUP.Optional.WPM.A, C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir, , [f70791d7f38989ad610109a05aa7837d],
Trojan.Zemot.ED, C:\ProgramData\Microsoft\Secure\Icons\temp\tmp54D3.exe, , [03fbc4a4bac294a24574ad510ff2ac54],
Backdoor.Bot, C:\ProgramData\Microsoft\Secure\Icons\temp\tmpC27C.exe, , [06f87fe96b11a88e7f92bf401be6f10f],
PUP.Optional.Excellent4App, D:\Dan\vyzvaneni\Sound effects - Chainsaw (1).exe, , [f10df474e09c1a1cc960326ccc3549b7],
PUP.Optional.Excellent4App, D:\Dan\vyzvaneni\Sound effects - Chainsaw.exe, , [57a76503691369cda188237bf30e2ad6],
Trojan.Agent.W, D:\download\windows 7 instal\sources\$OEM$\$$\SETUP\SCRIPTS\Windows7Loader.exe, , [35c9f3757c009f977e2acd6703028e72],
Physical Sectors: 0
(No malicious items detected)
(end)
behem testu 2x vyzkocilo avg s hlaskama viz priloha a tvarilo se, ze to vyresilo
- Přílohy
-
- avg.png (11.79 KiB) Zobrazeno 3797 x
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
s tim crackem nevim. Zkousela jsem zezacatku jak se objevili ty problemy udelat upgrade windowsu z cd, ale nepovedlo se mi to. Nevim, ale jestli to nejak souvisi s tim na co se ptate.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by petra (administrator) on PETRA-HP on 31-12-2014 01:20:45
Running from C:\Users\petra\Desktop
Loaded Profile: petra (Available profiles: petra)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Citrix Systems, Inc) C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Citrix Systems, Inc) C:\Program Files\Citrix\Secure Access Client\nsload.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(FutureDial Inc.) C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Nokia) C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Irfan Skiljan) C:\Program Files (x86)\IrfanView\i_view32.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\petra\Desktop\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SmartSoft PDF Printer Agent] => C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe [50560 2011-05-17] ()
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2013-06-21] (IDT, Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-01-12] (PDF Complete Inc)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [NortonOnlineBackup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1110360 2010-05-03] (Symantec Corporation)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-09] (Nullsoft, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [HTC Sync] => C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe [180224 2010-04-16] (FutureDial Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [220552 2011-04-28] (Geek Software GmbH)
HKLM-x32\...\Run: [NokiaMServer] => C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-10-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [570880 2013-12-27] (Nikon Corporation)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Communicator] => C:\Program Files (x86)\Microsoft Lync\communicator.exe [12117312 2014-05-01] (Microsoft Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-10] ()
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Citrix Access Gateway.lnk
ShortcutTarget: Citrix Access Gateway.lnk -> C:\Program Files\Citrix\Secure Access Client\nsload.exe (Citrix Systems, Inc)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://cag.autocont.cz/
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {C7CD73CA-3327-4E63-911E-C23C78A3C332} URL = http://search.yahoo.com/search?p={searc ... type=10809
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {F533918A-A8C5-4CB0-B704-1CDF6E16E34A} - No File
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @Citrix.com/npagee64,version=10.1.123.9 -> C:\Program Files\Citrix\Secure Access Client\npagee64.dll (Citrix Systems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @Citrix.com/npagee,version=10.1.123.9 -> C:\Program Files\Citrix\Secure Access Client\npagee.dll (Citrix Systems, Inc.)
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 -> C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1537954393-1589409457-3668467252-1002: @tools.google.com/Google Update;version=3 -> C:\Users\petra\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1537954393-1589409457-3668467252-1002: @tools.google.com/Google Update;version=9 -> C:\Users\petra\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\petra\AppData\Roaming\mozilla\plugins\npagee.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\petra\AppData\Roaming\mozilla\plugins\npagee64.dll (Citrix Systems, Inc.)
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-02-16]
FF HKLM-x32\...\Firefox\Extensions: [{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}] - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
FF Extension: Firefox Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension [2011-07-03]
FF HKLM-x32\...\Thunderbird\Extensions: [{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}] - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension
FF Extension: Thunderbird Address Book Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension [2011-07-03]
Chrome:
=======
CHR HomePage: Default -> https://www.seznam.cz/?clid=22668
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-14]
CHR Extension: (VyhledávánàGoogle) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-14]
CHR Extension: (Peněženka Google) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-03]
CHR Extension: (Gmail) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-14]
CHR StartMenuInternet: Google Chrome - C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-09-27] (Macrovision Europe Ltd.) [File not signed]
R3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1028096 2010-09-27] (Macrovision Europe Ltd.) [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [280120 2010-10-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2782552 2010-05-03] (Symantec Corporation)
R2 nsverctl; C:\Program Files\Citrix\Secure Access Client\nsverctl.exe [157744 2014-01-10] (Citrix Systems, Inc)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [633856 2011-06-08] (Nokia) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [263960 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [50976 2014-12-09] (AVG Technologies)
S3 btmaudio; C:\Windows\System32\drivers\btmaud.sys [42496 2010-05-20] (Motorola, Inc.)
S3 BTMNET; C:\Windows\System32\DRIVERS\btmnet.sys [28672 2010-06-18] (Motorola, Inc.)
R2 cag; C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys [102160 2013-04-01] (Citrix Systems, Inc.)
R3 ctxva51; C:\Windows\System32\DRIVERS\ctxva51.sys [46640 2014-01-10] (Citrix Systems, Inc.)
R1 DNE; C:\Windows\System32\DRIVERS\dnelwf64.sys [119120 2013-02-20] (Citrix Systems, Inc.)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [118872 2009-07-30] (QUALCOMM Incorporated)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R4 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-31] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [96384 2010-05-21] (Realtek Semiconductor Corp.)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 01:20 - 2014-12-31 01:21 - 00027415 _____ () C:\Users\petra\Desktop\FRST.txt
2014-12-31 00:32 - 2014-12-31 00:32 - 00004626 _____ () C:\Users\petra\Desktop\mamt.txt
2014-12-30 17:02 - 2014-12-30 17:02 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForpetra.job
2014-12-30 16:59 - 2014-12-30 16:59 - 02173952 _____ () C:\Users\petra\Desktop\adwcleaner_4.106.exe
2014-12-30 16:58 - 2014-12-30 16:58 - 00000396 _____ () C:\Users\petra\Desktop\TODO.txt
2014-12-30 16:18 - 2014-12-30 16:18 - 00025555 _____ () C:\ComboFix.txt
2014-12-30 15:59 - 2014-12-31 00:37 - 00007848 _____ () C:\windows\PFRO.log
2014-12-30 15:59 - 2014-12-31 00:37 - 00000168 _____ () C:\windows\setupact.log
2014-12-30 15:59 - 2014-12-30 15:59 - 00000000 _____ () C:\windows\setuperr.log
2014-12-30 13:56 - 2011-06-26 07:45 - 00256000 _____ () C:\windows\PEV.exe
2014-12-30 13:56 - 2010-11-07 18:20 - 00208896 _____ () C:\windows\MBR.exe
2014-12-30 13:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00098816 _____ () C:\windows\sed.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00080412 _____ () C:\windows\grep.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00068096 _____ () C:\windows\zip.exe
2014-12-30 13:55 - 2014-12-30 16:18 - 00000000 ____D () C:\Qoobox
2014-12-30 13:55 - 2014-12-30 15:58 - 00000000 ____D () C:\windows\erdnt
2014-12-30 13:16 - 2014-12-30 13:16 - 05604036 ____R (Swearware) C:\Users\petra\Desktop\ComboFix.exe
2014-12-30 13:15 - 2014-12-30 13:15 - 01940728 _____ (Bleeping Computer, LLC) C:\Users\petra\Desktop\rkill.com
2014-12-30 12:57 - 2014-12-30 12:57 - 00012898 _____ () C:\Users\petra\Desktop\Addition.zip
2014-12-29 21:27 - 2014-12-29 21:27 - 00000000 ____D () C:\Users\petra\Desktop\PCHunter_free
2014-12-29 21:26 - 2014-12-29 21:27 - 06739485 _____ () C:\Users\petra\Desktop\PCHunter_free.zip
2014-12-29 20:58 - 2014-12-29 21:25 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-29 20:06 - 2014-12-29 21:25 - 00000000 ____D () C:\Users\petra\Desktop\mbar
2014-12-29 20:05 - 2014-12-29 20:06 - 16448208 _____ (Malwarebytes Corp.) C:\Users\petra\Desktop\mbar-1.08.2.1001.exe
2014-12-29 19:23 - 2014-12-29 19:23 - 00522240 _____ (OldTimer Tools) C:\Users\petra\Desktop\OTM.exe
2014-12-29 17:49 - 2014-12-31 01:20 - 00000000 ____D () C:\FRST
2014-12-29 17:27 - 2014-12-29 17:27 - 02123264 _____ (Farbar) C:\Users\petra\Desktop\FRST64 (1).exe
2014-12-29 17:20 - 2014-12-29 17:20 - 00522240 _____ (OldTimer Tools) C:\Users\petra\Documents\OTM (1).exe
2014-12-29 17:17 - 2014-12-29 17:18 - 00522240 _____ (OldTimer Tools) C:\Users\petra\Documents\OTM.exe
2014-12-29 17:12 - 2014-12-29 17:12 - 00000000 ____D () C:\_OTM
2014-12-29 16:05 - 2014-12-29 16:05 - 00002020 _____ () C:\Users\petra\Desktop\Windows Compatibility Report.htm
2014-12-29 15:26 - 2014-12-29 15:26 - 00015392 _____ () C:\Users\petra\Documents\cc_20141229_152623.reg
2014-12-28 10:55 - 2014-12-31 00:38 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-28 10:53 - 2014-12-29 20:57 - 00096472 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-12-28 10:53 - 2014-12-28 10:53 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-28 10:53 - 2014-12-28 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-28 10:53 - 2014-12-28 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-28 10:53 - 2014-12-28 10:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-28 10:53 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-12-28 10:53 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-12-28 10:49 - 2014-12-28 10:50 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\petra\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-28 10:38 - 2014-12-28 10:38 - 00331552 _____ () C:\Users\petra\Documents\zaloha registru.reg
2014-12-28 10:27 - 2014-12-28 10:27 - 00002772 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-12-28 10:27 - 2014-12-28 10:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-12-28 10:27 - 2014-12-28 10:27 - 00000000 ____D () C:\Program Files\CCleaner
2014-12-28 10:26 - 2014-12-28 10:26 - 05317104 _____ (Piriform Ltd) C:\Users\petra\Downloads\ccsetup501.exe
2014-12-28 10:20 - 2014-12-28 23:06 - 00000000 ____D () C:\Program Files\trend micro
2014-12-28 10:20 - 2014-12-28 10:21 - 00000000 ____D () C:\rsit
2014-12-28 10:20 - 2014-12-28 10:20 - 01222144 _____ () C:\Users\petra\Downloads\RSITx64.exe
2014-12-27 20:02 - 2014-12-27 20:02 - 00001715 _____ () C:\Users\petra\Desktop\Computer.lnk
2014-12-26 23:04 - 2014-12-26 23:04 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV (3).application
2014-12-26 23:04 - 2014-12-26 23:04 - 00000370 _____ () C:\Users\petra\Desktop\eTesty - klient (ACV).appref-ms
2014-12-26 23:04 - 2014-12-26 23:04 - 00000000 ____D () C:\Users\petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ministerstvo dopravy
2014-12-26 23:03 - 2014-12-26 23:03 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV (2).application
2014-12-26 11:45 - 2014-12-29 16:34 - 00004268 _____ () C:\Users\petra\Desktop\Soubor Windows Compatibility Report.htm
2014-12-26 11:37 - 2014-12-29 18:59 - 00002544 _____ () C:\windows\diagwrn.xml
2014-12-26 11:37 - 2014-12-29 18:59 - 00001890 _____ () C:\windows\diagerr.xml
2014-12-26 08:17 - 2014-12-26 08:17 - 00003126 _____ () C:\windows\System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846}
2014-12-25 16:48 - 2014-12-25 16:49 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV.application
2014-12-20 22:06 - 2014-12-20 22:06 - 04085248 _____ () C:\Users\petra\Desktop\teorie_treninku_strelby_zacatecniku.ppt
2014-12-18 06:13 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-12-18 06:13 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-12-17 12:41 - 2014-12-17 12:41 - 00413005 _____ () C:\Users\petra\Desktop\MD_eKom_ UAT_171204 MD.xlsx
2014-12-14 14:32 - 2014-12-14 14:32 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV (1).application
2014-12-10 06:34 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-12-10 06:34 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-12-10 06:34 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-12-10 06:34 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-12-10 06:33 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-12-10 06:33 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-12-10 06:33 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-12-10 06:33 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-12-10 06:33 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-12-10 06:33 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-12-10 06:33 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-12-10 06:33 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-12-10 06:33 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-12-10 06:33 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-12-10 06:33 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-12-10 06:33 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-12-10 06:33 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-12-10 06:33 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-12-10 06:33 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-12-10 06:33 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-12-10 06:33 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 06:33 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-12-10 06:33 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-12-10 06:33 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-12-10 06:33 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 06:33 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-12-10 06:33 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-12-10 06:33 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-12-10 06:33 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-12-10 06:33 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-12-10 06:33 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-12-10 06:33 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-12-10 06:33 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-12-10 06:33 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-12-10 06:33 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-12-10 06:33 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-12-10 06:33 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-12-10 06:33 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-12-10 06:33 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-12-10 06:33 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-12-10 06:33 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-12-10 06:33 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 06:33 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-12-10 06:33 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-12-10 06:33 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-12-10 06:33 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-12-10 06:33 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-12-10 06:33 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-12-10 06:33 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-12-10 06:33 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-12-10 06:33 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-12-10 06:33 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-12-10 06:33 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-12-10 06:33 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-12-10 06:33 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-12-10 06:33 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-12-09 09:45 - 2014-12-09 13:45 - 00000000 ____D () C:\Users\petra\AppData\Local\AVG Web TuneUp
2014-12-09 09:45 - 2014-12-09 09:45 - 00050976 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2014-12-09 09:45 - 2014-12-09 09:45 - 00000000 ____D () C:\ProgramData\AVG Web TuneUp
2014-12-09 09:45 - 2014-12-09 09:45 - 00000000 ____D () C:\Program Files (x86)\AVG Web TuneUp
2014-12-08 22:41 - 2014-12-08 22:41 - 00000000 ____D () C:\Users\petra\Záznamy aplikace Lync
2014-12-08 20:10 - 2014-12-08 20:10 - 00000000 ____D () C:\Users\petra\AppData\Roaming\AVG2015
2014-12-08 20:09 - 2014-12-08 20:09 - 00000000 ____D () C:\Users\petra\AppData\Roaming\TuneUp Software
2014-12-08 20:09 - 2014-12-08 20:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-12-08 20:07 - 2014-12-28 10:02 - 00000000 ____D () C:\ProgramData\AVG2015
2014-12-08 20:07 - 2014-12-08 20:07 - 00000000 ____D () C:\$AVG
2014-12-08 20:06 - 2014-12-08 20:06 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-12-08 19:15 - 2014-12-30 21:03 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-08 19:15 - 2014-12-09 09:36 - 00000000 ____D () C:\Users\petra\AppData\Local\Avg2015
2014-12-08 19:15 - 2014-12-08 19:15 - 00000000 ____D () C:\Users\petra\AppData\Local\MFAData
2014-12-08 18:42 - 2014-12-08 18:42 - 04578048 _____ (AVG Technologies) C:\Users\petra\Downloads\avg_free_stb_all_2015_5315_ppc2.exe
2014-12-06 07:44 - 2014-12-06 07:47 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2012
2014-12-06 07:44 - 2014-12-06 07:47 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2012
2014-12-05 13:58 - 2014-12-05 13:58 - 00000045 _____ () C:\Users\petra\Documents\2014_12.txt
2014-12-05 02:04 - 2014-12-25 18:49 - 00000000 ____D () C:\Users\petra\Documents\Visual Studio 2012
2014-12-05 02:01 - 2014-12-05 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK
2014-12-05 02:01 - 2014-12-05 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 4 SDK
2014-12-05 01:59 - 2014-12-05 01:59 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-12-05 01:59 - 2014-12-05 01:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-12-05 01:58 - 2014-12-05 01:58 - 00000000 ____D () C:\ProgramData\Windows App Certification Kit
2014-12-05 01:58 - 2014-12-05 01:58 - 00000000 ____D () C:\Program Files\Application Verifier
2014-12-05 01:58 - 2014-12-05 01:58 - 00000000 ____D () C:\Program Files (x86)\Application Verifier
2014-12-05 01:57 - 2014-12-05 01:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2014-12-05 01:57 - 2014-12-05 01:57 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
2014-12-05 01:54 - 2014-12-05 01:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-12-05 01:53 - 2014-12-05 01:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Web Tools
2014-12-05 01:53 - 2014-12-05 01:53 - 00002019 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
2014-12-05 01:52 - 2014-12-05 01:53 - 00000000 ____D () C:\Program Files\IIS Express
2014-12-05 01:52 - 2014-12-05 01:53 - 00000000 ____D () C:\Program Files (x86)\IIS Express
2014-12-05 01:52 - 2014-12-05 01:52 - 00000000 ____D () C:\Program Files (x86)\NuGet
2014-12-05 01:52 - 2014-12-05 01:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft WCF Data Services
2014-12-05 01:50 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
2014-12-05 01:49 - 2014-12-05 01:49 - 00000000 ____D () C:\Program Files (x86)\Windows Kits
2014-12-05 01:44 - 2014-12-05 01:44 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
2014-12-05 01:43 - 2014-12-05 01:43 - 00000000 ____D () C:\Program Files (x86)\Microsoft Help Viewer
2014-12-05 01:41 - 2014-12-05 02:00 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2014-12-05 01:41 - 2014-12-05 02:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
2014-12-05 01:41 - 2014-12-05 01:47 - 00000000 ____D () C:\windows\SysWOW64\1033
2014-12-05 01:36 - 2014-12-05 02:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2012
2014-12-05 01:36 - 2014-12-05 02:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-12-05 01:36 - 2014-12-05 02:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
2014-12-05 01:36 - 2014-12-05 01:41 - 00000000 ____D () C:\windows\system32\1033
2014-12-05 01:36 - 2014-12-05 01:36 - 00000000 ____D () C:\windows\symbols
2014-12-05 01:36 - 2014-12-05 01:36 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 11.0
2014-12-05 01:17 - 2014-12-18 05:57 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-04 23:47 - 2014-12-04 23:47 - 00777835 _____ () C:\Users\petra\Downloads\test
2014-12-04 20:52 - 2014-12-04 20:52 - 00003264 _____ () C:\windows\System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42}
2014-12-04 20:37 - 2014-12-04 20:37 - 00000894 _____ () C:\Users\petra\Downloads\AutoContCA2 (1).crt
2014-12-04 20:37 - 2014-12-04 20:37 - 00000890 _____ () C:\Users\petra\Downloads\AutoContCA (1).crt
2014-12-04 20:36 - 2014-12-04 20:36 - 00000890 _____ () C:\Users\petra\Downloads\cacert (1).crt
2014-12-04 13:51 - 2014-12-04 13:51 - 00000000 ____D () C:\ProgramData\Applications
2014-12-04 13:50 - 2014-12-28 14:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Lync
2014-12-04 13:50 - 2014-12-28 13:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Lync
2014-12-04 13:50 - 2014-12-06 07:57 - 00000000 ____D () C:\Program Files\Microsoft Lync
2014-12-04 13:49 - 2014-12-31 00:39 - 00000000 ____D () C:\Users\petra\Tracing
2014-12-04 13:49 - 2014-12-04 13:49 - 00000000 ____D () C:\Program Files (x86)\OCSetup
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 01:07 - 2014-03-05 14:21 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-12-31 00:45 - 2009-07-14 05:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-31 00:45 - 2009-07-14 05:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-31 00:42 - 2010-09-27 23:17 - 01236366 _____ () C:\windows\WindowsUpdate.log
2014-12-31 00:37 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-12-31 00:36 - 2010-09-09 22:43 - 00000000 ____D () C:\windows\OEMCert
2014-12-30 17:06 - 2014-09-21 20:05 - 00000000 ____D () C:\AdwCleaner
2014-12-30 17:02 - 2014-02-28 16:31 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForpetra
2014-12-30 16:18 - 2010-12-15 22:22 - 00000000 ____D () C:\Users\petra\AppData\Local\Apps\2.0
2014-12-30 16:12 - 2009-07-14 03:34 - 00000215 _____ () C:\windows\system.ini
2014-12-30 14:11 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-30 13:39 - 2010-12-27 20:33 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-30 13:39 - 2010-09-27 23:21 - 00000000 ____D () C:\ProgramData\Skype
2014-12-30 12:34 - 2010-12-19 15:39 - 00000000 ____D () C:\Users\petra\AppData\Roaming\uTorrent
2014-12-29 14:19 - 2010-09-09 22:18 - 00672408 _____ () C:\windows\system32\perfh005.dat
2014-12-29 14:19 - 2010-09-09 22:18 - 00142972 _____ () C:\windows\system32\perfc005.dat
2014-12-29 14:19 - 2009-07-14 06:13 - 01593238 _____ () C:\windows\system32\PerfStringBackup.INI
2014-12-29 10:08 - 2014-11-20 16:52 - 01611202 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-12-28 22:28 - 2013-07-11 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon Message Center 2
2014-12-28 22:12 - 2011-01-31 20:43 - 00000000 ____D () C:\Users\petra\AppData\Local\Downloaded Installations
2014-12-28 15:02 - 2010-12-15 22:22 - 00000000 ____D () C:\Users\petra\AppData\Local\Deployment
2014-12-28 10:34 - 2011-05-31 20:29 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-12-28 10:34 - 2010-12-28 20:53 - 00000000 ____D () C:\Users\petra\AppData\Roaming\Media Player Classic
2014-12-28 10:30 - 2009-07-27 16:04 - 00000000 ____D () C:\windows\Panther
2014-12-28 05:25 - 2010-09-09 22:23 - 00000000 ____D () C:\ProgramData\PDFC
2014-12-27 09:40 - 2010-12-27 20:58 - 00000000 ____D () C:\Users\petra\.gimp-2.6
2014-12-26 17:02 - 2011-10-28 19:20 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-12-26 17:02 - 2010-12-17 17:29 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-12-16 17:26 - 2012-08-28 20:31 - 00047616 _____ () C:\Users\petra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-12 18:06 - 2010-12-16 04:57 - 00000000 ____D () C:\windows\rescache
2014-12-12 16:53 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-12-12 16:36 - 2011-01-17 21:58 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-12 16:34 - 2013-08-15 07:13 - 00000000 ____D () C:\windows\system32\MRT
2014-12-12 16:18 - 2010-12-19 16:13 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-12-09 20:07 - 2014-03-05 14:21 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-12-09 20:07 - 2014-03-05 14:21 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-09 20:07 - 2014-03-05 14:21 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-12-09 18:54 - 2009-07-14 06:08 - 00032532 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-12-08 22:41 - 2010-12-15 21:07 - 00000000 ____D () C:\Users\petra
2014-12-07 18:29 - 2010-12-18 23:00 - 00000000 ____D () C:\Users\petra\AppData\Roaming\vlc
2014-12-06 08:38 - 2009-07-14 05:45 - 04971336 _____ () C:\windows\system32\FNTCACHE.DAT
2014-12-06 07:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-12-05 19:36 - 2014-09-17 07:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix
2014-12-05 01:56 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\MSBuild
2014-12-05 01:54 - 2010-12-15 21:23 - 00110440 _____ () C:\Users\petra\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-05 01:43 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
Some content of TEMP:
====================
C:\Users\petra\AppData\Local\Temp\Quarantine.exe
C:\Users\petra\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-26 11:09
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by petra (administrator) on PETRA-HP on 31-12-2014 01:20:45
Running from C:\Users\petra\Desktop
Loaded Profile: petra (Available profiles: petra)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Citrix Systems, Inc) C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Citrix Systems, Inc) C:\Program Files\Citrix\Secure Access Client\nsload.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(FutureDial Inc.) C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Nokia) C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Irfan Skiljan) C:\Program Files (x86)\IrfanView\i_view32.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\petra\Desktop\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SmartSoft PDF Printer Agent] => C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe [50560 2011-05-17] ()
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [489472 2013-06-21] (IDT, Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-01-12] (PDF Complete Inc)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [NortonOnlineBackup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1110360 2010-05-03] (Symantec Corporation)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2010-12-09] (Nullsoft, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [HTC Sync] => C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe [180224 2010-04-16] (FutureDial Inc.)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [220552 2011-04-28] (Geek Software GmbH)
HKLM-x32\...\Run: [NokiaMServer] => C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [395656 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-10-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Nikon Message Center 2] => C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [570880 2013-12-27] (Nikon Corporation)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [153992 2013-10-01] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Communicator] => C:\Program Files (x86)\Microsoft Lync\communicator.exe [12117312 2014-05-01] (Microsoft Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-10] ()
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Citrix Access Gateway.lnk
ShortcutTarget: Citrix Access Gateway.lnk -> C:\Program Files\Citrix\Secure Access Client\nsload.exe (Citrix Systems, Inc)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://cag.autocont.cz/
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {C7CD73CA-3327-4E63-911E-C23C78A3C332} URL = http://search.yahoo.com/search?p={searc ... type=10809
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {F533918A-A8C5-4CB0-B704-1CDF6E16E34A} - No File
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @Citrix.com/npagee64,version=10.1.123.9 -> C:\Program Files\Citrix\Secure Access Client\npagee64.dll (Citrix Systems, Inc.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @Citrix.com/npagee,version=10.1.123.9 -> C:\Program Files\Citrix\Secure Access Client\npagee.dll (Citrix Systems, Inc.)
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll (Citrix Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.5.1 -> C:\windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.5.1 -> C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1537954393-1589409457-3668467252-1002: @tools.google.com/Google Update;version=3 -> C:\Users\petra\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-1537954393-1589409457-3668467252-1002: @tools.google.com/Google Update;version=9 -> C:\Users\petra\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\petra\AppData\Roaming\mozilla\plugins\npagee.dll (Citrix Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\petra\AppData\Roaming\mozilla\plugins\npagee64.dll (Citrix Systems, Inc.)
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-02-16]
FF HKLM-x32\...\Firefox\Extensions: [{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}] - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
FF Extension: Firefox Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension [2011-07-03]
FF HKLM-x32\...\Thunderbird\Extensions: [{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}] - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension
FF Extension: Thunderbird Address Book Synchronisation Extension - C:\Program Files (x86)\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension [2011-07-03]
Chrome:
=======
CHR HomePage: Default -> https://www.seznam.cz/?clid=22668
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-14]
CHR Extension: (VyhledávánàGoogle) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-14]
CHR Extension: (Peněženka Google) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-03]
CHR Extension: (Gmail) - C:\Users\petra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-14]
CHR StartMenuInternet: Google Chrome - C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-09-27] (Macrovision Europe Ltd.) [File not signed]
R3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1028096 2010-09-27] (Macrovision Europe Ltd.) [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [280120 2010-10-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2782552 2010-05-03] (Symantec Corporation)
R2 nsverctl; C:\Program Files\Citrix\Secure Access Client\nsverctl.exe [157744 2014-01-10] (Citrix Systems, Inc)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [633856 2011-06-08] (Nokia) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [263960 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [50976 2014-12-09] (AVG Technologies)
S3 btmaudio; C:\Windows\System32\drivers\btmaud.sys [42496 2010-05-20] (Motorola, Inc.)
S3 BTMNET; C:\Windows\System32\DRIVERS\btmnet.sys [28672 2010-06-18] (Motorola, Inc.)
R2 cag; C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys [102160 2013-04-01] (Citrix Systems, Inc.)
R3 ctxva51; C:\Windows\System32\DRIVERS\ctxva51.sys [46640 2014-01-10] (Citrix Systems, Inc.)
R1 DNE; C:\Windows\System32\DRIVERS\dnelwf64.sys [119120 2013-02-20] (Citrix Systems, Inc.)
S3 HtcVCom32; C:\Windows\System32\DRIVERS\HtcVComV64.sys [118872 2009-07-30] (QUALCOMM Incorporated)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R4 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-31] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [96384 2010-05-21] (Realtek Semiconductor Corp.)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 01:20 - 2014-12-31 01:21 - 00027415 _____ () C:\Users\petra\Desktop\FRST.txt
2014-12-31 00:32 - 2014-12-31 00:32 - 00004626 _____ () C:\Users\petra\Desktop\mamt.txt
2014-12-30 17:02 - 2014-12-30 17:02 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForpetra.job
2014-12-30 16:59 - 2014-12-30 16:59 - 02173952 _____ () C:\Users\petra\Desktop\adwcleaner_4.106.exe
2014-12-30 16:58 - 2014-12-30 16:58 - 00000396 _____ () C:\Users\petra\Desktop\TODO.txt
2014-12-30 16:18 - 2014-12-30 16:18 - 00025555 _____ () C:\ComboFix.txt
2014-12-30 15:59 - 2014-12-31 00:37 - 00007848 _____ () C:\windows\PFRO.log
2014-12-30 15:59 - 2014-12-31 00:37 - 00000168 _____ () C:\windows\setupact.log
2014-12-30 15:59 - 2014-12-30 15:59 - 00000000 _____ () C:\windows\setuperr.log
2014-12-30 13:56 - 2011-06-26 07:45 - 00256000 _____ () C:\windows\PEV.exe
2014-12-30 13:56 - 2010-11-07 18:20 - 00208896 _____ () C:\windows\MBR.exe
2014-12-30 13:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00098816 _____ () C:\windows\sed.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00080412 _____ () C:\windows\grep.exe
2014-12-30 13:56 - 2000-08-31 01:00 - 00068096 _____ () C:\windows\zip.exe
2014-12-30 13:55 - 2014-12-30 16:18 - 00000000 ____D () C:\Qoobox
2014-12-30 13:55 - 2014-12-30 15:58 - 00000000 ____D () C:\windows\erdnt
2014-12-30 13:16 - 2014-12-30 13:16 - 05604036 ____R (Swearware) C:\Users\petra\Desktop\ComboFix.exe
2014-12-30 13:15 - 2014-12-30 13:15 - 01940728 _____ (Bleeping Computer, LLC) C:\Users\petra\Desktop\rkill.com
2014-12-30 12:57 - 2014-12-30 12:57 - 00012898 _____ () C:\Users\petra\Desktop\Addition.zip
2014-12-29 21:27 - 2014-12-29 21:27 - 00000000 ____D () C:\Users\petra\Desktop\PCHunter_free
2014-12-29 21:26 - 2014-12-29 21:27 - 06739485 _____ () C:\Users\petra\Desktop\PCHunter_free.zip
2014-12-29 20:58 - 2014-12-29 21:25 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-29 20:06 - 2014-12-29 21:25 - 00000000 ____D () C:\Users\petra\Desktop\mbar
2014-12-29 20:05 - 2014-12-29 20:06 - 16448208 _____ (Malwarebytes Corp.) C:\Users\petra\Desktop\mbar-1.08.2.1001.exe
2014-12-29 19:23 - 2014-12-29 19:23 - 00522240 _____ (OldTimer Tools) C:\Users\petra\Desktop\OTM.exe
2014-12-29 17:49 - 2014-12-31 01:20 - 00000000 ____D () C:\FRST
2014-12-29 17:27 - 2014-12-29 17:27 - 02123264 _____ (Farbar) C:\Users\petra\Desktop\FRST64 (1).exe
2014-12-29 17:20 - 2014-12-29 17:20 - 00522240 _____ (OldTimer Tools) C:\Users\petra\Documents\OTM (1).exe
2014-12-29 17:17 - 2014-12-29 17:18 - 00522240 _____ (OldTimer Tools) C:\Users\petra\Documents\OTM.exe
2014-12-29 17:12 - 2014-12-29 17:12 - 00000000 ____D () C:\_OTM
2014-12-29 16:05 - 2014-12-29 16:05 - 00002020 _____ () C:\Users\petra\Desktop\Windows Compatibility Report.htm
2014-12-29 15:26 - 2014-12-29 15:26 - 00015392 _____ () C:\Users\petra\Documents\cc_20141229_152623.reg
2014-12-28 10:55 - 2014-12-31 00:38 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-28 10:53 - 2014-12-29 20:57 - 00096472 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-12-28 10:53 - 2014-12-28 10:53 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-28 10:53 - 2014-12-28 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-28 10:53 - 2014-12-28 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-28 10:53 - 2014-12-28 10:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-28 10:53 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-12-28 10:53 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-12-28 10:49 - 2014-12-28 10:50 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\petra\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-28 10:38 - 2014-12-28 10:38 - 00331552 _____ () C:\Users\petra\Documents\zaloha registru.reg
2014-12-28 10:27 - 2014-12-28 10:27 - 00002772 _____ () C:\windows\System32\Tasks\CCleanerSkipUAC
2014-12-28 10:27 - 2014-12-28 10:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-12-28 10:27 - 2014-12-28 10:27 - 00000000 ____D () C:\Program Files\CCleaner
2014-12-28 10:26 - 2014-12-28 10:26 - 05317104 _____ (Piriform Ltd) C:\Users\petra\Downloads\ccsetup501.exe
2014-12-28 10:20 - 2014-12-28 23:06 - 00000000 ____D () C:\Program Files\trend micro
2014-12-28 10:20 - 2014-12-28 10:21 - 00000000 ____D () C:\rsit
2014-12-28 10:20 - 2014-12-28 10:20 - 01222144 _____ () C:\Users\petra\Downloads\RSITx64.exe
2014-12-27 20:02 - 2014-12-27 20:02 - 00001715 _____ () C:\Users\petra\Desktop\Computer.lnk
2014-12-26 23:04 - 2014-12-26 23:04 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV (3).application
2014-12-26 23:04 - 2014-12-26 23:04 - 00000370 _____ () C:\Users\petra\Desktop\eTesty - klient (ACV).appref-ms
2014-12-26 23:04 - 2014-12-26 23:04 - 00000000 ____D () C:\Users\petra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ministerstvo dopravy
2014-12-26 23:03 - 2014-12-26 23:03 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV (2).application
2014-12-26 11:45 - 2014-12-29 16:34 - 00004268 _____ () C:\Users\petra\Desktop\Soubor Windows Compatibility Report.htm
2014-12-26 11:37 - 2014-12-29 18:59 - 00002544 _____ () C:\windows\diagwrn.xml
2014-12-26 11:37 - 2014-12-29 18:59 - 00001890 _____ () C:\windows\diagerr.xml
2014-12-26 08:17 - 2014-12-26 08:17 - 00003126 _____ () C:\windows\System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846}
2014-12-25 16:48 - 2014-12-25 16:49 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV.application
2014-12-20 22:06 - 2014-12-20 22:06 - 04085248 _____ () C:\Users\petra\Desktop\teorie_treninku_strelby_zacatecniku.ppt
2014-12-18 06:13 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-12-18 06:13 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-12-17 12:41 - 2014-12-17 12:41 - 00413005 _____ () C:\Users\petra\Desktop\MD_eKom_ UAT_171204 MD.xlsx
2014-12-14 14:32 - 2014-12-14 14:32 - 00002146 _____ () C:\Users\petra\Downloads\eKomunikace.ClientACV (1).application
2014-12-10 06:34 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-12-10 06:34 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-12-10 06:34 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-12-10 06:34 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-12-10 06:33 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-12-10 06:33 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-12-10 06:33 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-12-10 06:33 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-12-10 06:33 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-12-10 06:33 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-12-10 06:33 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-12-10 06:33 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-12-10 06:33 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-12-10 06:33 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-12-10 06:33 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-12-10 06:33 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-12-10 06:33 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-12-10 06:33 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-12-10 06:33 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-12-10 06:33 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-12-10 06:33 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 06:33 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-12-10 06:33 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-12-10 06:33 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-12-10 06:33 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 06:33 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-12-10 06:33 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-12-10 06:33 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-12-10 06:33 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-12-10 06:33 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-12-10 06:33 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-12-10 06:33 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-12-10 06:33 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-12-10 06:33 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-12-10 06:33 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-12-10 06:33 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-12-10 06:33 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-12-10 06:33 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-12-10 06:33 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-12-10 06:33 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-12-10 06:33 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-12-10 06:33 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 06:33 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-12-10 06:33 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-12-10 06:33 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-12-10 06:33 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-12-10 06:33 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-12-10 06:33 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-12-10 06:33 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-12-10 06:33 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-12-10 06:33 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-12-10 06:33 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-12-10 06:33 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-12-10 06:33 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-12-10 06:33 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-12-10 06:33 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-12-09 09:45 - 2014-12-09 13:45 - 00000000 ____D () C:\Users\petra\AppData\Local\AVG Web TuneUp
2014-12-09 09:45 - 2014-12-09 09:45 - 00050976 _____ (AVG Technologies) C:\windows\system32\Drivers\avgtpx64.sys
2014-12-09 09:45 - 2014-12-09 09:45 - 00000000 ____D () C:\ProgramData\AVG Web TuneUp
2014-12-09 09:45 - 2014-12-09 09:45 - 00000000 ____D () C:\Program Files (x86)\AVG Web TuneUp
2014-12-08 22:41 - 2014-12-08 22:41 - 00000000 ____D () C:\Users\petra\Záznamy aplikace Lync
2014-12-08 20:10 - 2014-12-08 20:10 - 00000000 ____D () C:\Users\petra\AppData\Roaming\AVG2015
2014-12-08 20:09 - 2014-12-08 20:09 - 00000000 ____D () C:\Users\petra\AppData\Roaming\TuneUp Software
2014-12-08 20:09 - 2014-12-08 20:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-12-08 20:07 - 2014-12-28 10:02 - 00000000 ____D () C:\ProgramData\AVG2015
2014-12-08 20:07 - 2014-12-08 20:07 - 00000000 ____D () C:\$AVG
2014-12-08 20:06 - 2014-12-08 20:06 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-12-08 19:15 - 2014-12-30 21:03 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-08 19:15 - 2014-12-09 09:36 - 00000000 ____D () C:\Users\petra\AppData\Local\Avg2015
2014-12-08 19:15 - 2014-12-08 19:15 - 00000000 ____D () C:\Users\petra\AppData\Local\MFAData
2014-12-08 18:42 - 2014-12-08 18:42 - 04578048 _____ (AVG Technologies) C:\Users\petra\Downloads\avg_free_stb_all_2015_5315_ppc2.exe
2014-12-06 07:44 - 2014-12-06 07:47 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2012
2014-12-06 07:44 - 2014-12-06 07:47 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2012
2014-12-05 13:58 - 2014-12-05 13:58 - 00000045 _____ () C:\Users\petra\Documents\2014_12.txt
2014-12-05 02:04 - 2014-12-25 18:49 - 00000000 ____D () C:\Users\petra\Documents\Visual Studio 2012
2014-12-05 02:01 - 2014-12-05 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK
2014-12-05 02:01 - 2014-12-05 02:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 4 SDK
2014-12-05 01:59 - 2014-12-05 01:59 - 00000000 ____D () C:\Program Files\Microsoft SQL Server Compact Edition
2014-12-05 01:59 - 2014-12-05 01:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-12-05 01:58 - 2014-12-05 01:58 - 00000000 ____D () C:\ProgramData\Windows App Certification Kit
2014-12-05 01:58 - 2014-12-05 01:58 - 00000000 ____D () C:\Program Files\Application Verifier
2014-12-05 01:58 - 2014-12-05 01:58 - 00000000 ____D () C:\Program Files (x86)\Application Verifier
2014-12-05 01:57 - 2014-12-05 01:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2014-12-05 01:57 - 2014-12-05 01:57 - 00000000 ____D () C:\ProgramData\PreEmptive Solutions
2014-12-05 01:54 - 2014-12-05 01:55 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-12-05 01:53 - 2014-12-05 01:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Web Tools
2014-12-05 01:53 - 2014-12-05 01:53 - 00002019 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
2014-12-05 01:52 - 2014-12-05 01:53 - 00000000 ____D () C:\Program Files\IIS Express
2014-12-05 01:52 - 2014-12-05 01:53 - 00000000 ____D () C:\Program Files (x86)\IIS Express
2014-12-05 01:52 - 2014-12-05 01:52 - 00000000 ____D () C:\Program Files (x86)\NuGet
2014-12-05 01:52 - 2014-12-05 01:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft WCF Data Services
2014-12-05 01:50 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\windows\SysWOW64\D3DX9_43.dll
2014-12-05 01:49 - 2014-12-05 01:49 - 00000000 ____D () C:\Program Files (x86)\Windows Kits
2014-12-05 01:44 - 2014-12-05 01:44 - 00000000 ____D () C:\Program Files (x86)\HTML Help Workshop
2014-12-05 01:43 - 2014-12-05 01:43 - 00000000 ____D () C:\Program Files (x86)\Microsoft Help Viewer
2014-12-05 01:41 - 2014-12-05 02:00 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2014-12-05 01:41 - 2014-12-05 02:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
2014-12-05 01:41 - 2014-12-05 01:47 - 00000000 ____D () C:\windows\SysWOW64\1033
2014-12-05 01:36 - 2014-12-05 02:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2012
2014-12-05 01:36 - 2014-12-05 02:03 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-12-05 01:36 - 2014-12-05 02:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
2014-12-05 01:36 - 2014-12-05 01:41 - 00000000 ____D () C:\windows\system32\1033
2014-12-05 01:36 - 2014-12-05 01:36 - 00000000 ____D () C:\windows\symbols
2014-12-05 01:36 - 2014-12-05 01:36 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 11.0
2014-12-05 01:17 - 2014-12-18 05:57 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-04 23:47 - 2014-12-04 23:47 - 00777835 _____ () C:\Users\petra\Downloads\test
2014-12-04 20:52 - 2014-12-04 20:52 - 00003264 _____ () C:\windows\System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42}
2014-12-04 20:37 - 2014-12-04 20:37 - 00000894 _____ () C:\Users\petra\Downloads\AutoContCA2 (1).crt
2014-12-04 20:37 - 2014-12-04 20:37 - 00000890 _____ () C:\Users\petra\Downloads\AutoContCA (1).crt
2014-12-04 20:36 - 2014-12-04 20:36 - 00000890 _____ () C:\Users\petra\Downloads\cacert (1).crt
2014-12-04 13:51 - 2014-12-04 13:51 - 00000000 ____D () C:\ProgramData\Applications
2014-12-04 13:50 - 2014-12-28 14:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Lync
2014-12-04 13:50 - 2014-12-28 13:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft Lync
2014-12-04 13:50 - 2014-12-06 07:57 - 00000000 ____D () C:\Program Files\Microsoft Lync
2014-12-04 13:49 - 2014-12-31 00:39 - 00000000 ____D () C:\Users\petra\Tracing
2014-12-04 13:49 - 2014-12-04 13:49 - 00000000 ____D () C:\Program Files (x86)\OCSetup
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-31 01:07 - 2014-03-05 14:21 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-12-31 00:45 - 2009-07-14 05:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-31 00:45 - 2009-07-14 05:45 - 00019760 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-31 00:42 - 2010-09-27 23:17 - 01236366 _____ () C:\windows\WindowsUpdate.log
2014-12-31 00:37 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-12-31 00:36 - 2010-09-09 22:43 - 00000000 ____D () C:\windows\OEMCert
2014-12-30 17:06 - 2014-09-21 20:05 - 00000000 ____D () C:\AdwCleaner
2014-12-30 17:02 - 2014-02-28 16:31 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForpetra
2014-12-30 16:18 - 2010-12-15 22:22 - 00000000 ____D () C:\Users\petra\AppData\Local\Apps\2.0
2014-12-30 16:12 - 2009-07-14 03:34 - 00000215 _____ () C:\windows\system.ini
2014-12-30 14:11 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-30 13:39 - 2010-12-27 20:33 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-30 13:39 - 2010-09-27 23:21 - 00000000 ____D () C:\ProgramData\Skype
2014-12-30 12:34 - 2010-12-19 15:39 - 00000000 ____D () C:\Users\petra\AppData\Roaming\uTorrent
2014-12-29 14:19 - 2010-09-09 22:18 - 00672408 _____ () C:\windows\system32\perfh005.dat
2014-12-29 14:19 - 2010-09-09 22:18 - 00142972 _____ () C:\windows\system32\perfc005.dat
2014-12-29 14:19 - 2009-07-14 06:13 - 01593238 _____ () C:\windows\system32\PerfStringBackup.INI
2014-12-29 10:08 - 2014-11-20 16:52 - 01611202 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-12-28 22:28 - 2013-07-11 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nikon Message Center 2
2014-12-28 22:12 - 2011-01-31 20:43 - 00000000 ____D () C:\Users\petra\AppData\Local\Downloaded Installations
2014-12-28 15:02 - 2010-12-15 22:22 - 00000000 ____D () C:\Users\petra\AppData\Local\Deployment
2014-12-28 10:34 - 2011-05-31 20:29 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-12-28 10:34 - 2010-12-28 20:53 - 00000000 ____D () C:\Users\petra\AppData\Roaming\Media Player Classic
2014-12-28 10:30 - 2009-07-27 16:04 - 00000000 ____D () C:\windows\Panther
2014-12-28 05:25 - 2010-09-09 22:23 - 00000000 ____D () C:\ProgramData\PDFC
2014-12-27 09:40 - 2010-12-27 20:58 - 00000000 ____D () C:\Users\petra\.gimp-2.6
2014-12-26 17:02 - 2011-10-28 19:20 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-12-26 17:02 - 2010-12-17 17:29 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-12-16 17:26 - 2012-08-28 20:31 - 00047616 _____ () C:\Users\petra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-12 18:06 - 2010-12-16 04:57 - 00000000 ____D () C:\windows\rescache
2014-12-12 16:53 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-12-12 16:36 - 2011-01-17 21:58 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-12 16:34 - 2013-08-15 07:13 - 00000000 ____D () C:\windows\system32\MRT
2014-12-12 16:18 - 2010-12-19 16:13 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-12-09 20:07 - 2014-03-05 14:21 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-12-09 20:07 - 2014-03-05 14:21 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-09 20:07 - 2014-03-05 14:21 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-12-09 18:54 - 2009-07-14 06:08 - 00032532 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-12-08 22:41 - 2010-12-15 21:07 - 00000000 ____D () C:\Users\petra
2014-12-07 18:29 - 2010-12-18 23:00 - 00000000 ____D () C:\Users\petra\AppData\Roaming\vlc
2014-12-06 08:38 - 2009-07-14 05:45 - 04971336 _____ () C:\windows\system32\FNTCACHE.DAT
2014-12-06 07:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-12-05 19:36 - 2014-09-17 07:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix
2014-12-05 01:56 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files\MSBuild
2014-12-05 01:54 - 2010-12-15 21:23 - 00110440 _____ () C:\Users\petra\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-05 01:43 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
Some content of TEMP:
====================
C:\Users\petra\AppData\Local\Temp\Quarantine.exe
C:\Users\petra\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-26 11:09
==================== End Of Log ============================
- Přílohy
-
- Addition2.zip
- (12.08 KiB) Staženo 64 x
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File BootExecute: autocheck autochk * sdnclean64.exe HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms} SearchScopes: HKLM-x32 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://www.bing.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} URL = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms} SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} URL = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms} SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {C7CD73CA-3327-4E63-911E-C23C78A3C332} URL = http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10809 SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {F533918A-A8C5-4CB0-B704-1CDF6E16E34A} - No File Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File 2014-12-31 01:20 - 2014-12-31 01:21 - 00027415 _____ () C:\Users\petra\Desktop\FRST.txt 2014-12-30 16:59 - 2014-12-30 16:59 - 02173952 _____ () C:\Users\petra\Desktop\adwcleaner_4.106.exe 2014-12-30 17:06 - 2014-09-21 20:05 - 00000000 ____D () C:\AdwCleaner Task: {4637C94D-70E9-4131-8ABE-205BCA01F6A7} - System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846} => pcalua.exe -a C:\Users\petra\AppData\Roaming\uTorrent\uTorrent.exe -c /UNINSTALL Task: {B2119B51-1358-491A-9D63-E581A63DF8B9} - System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42} => pcalua.exe -a "C:\Users\petra\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MKOOTH0S\AGEE_setup.exe" -d C:\Users\petra\Desktop Unlock: C:\ProgramData\Microsoft\Secure\Icons C:\ProgramData\Microsoft\Secure\Icons EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2014
Ran by petra at 2014-12-31 09:36:53 Run:2
Running from C:\Users\petra\Desktop
Loaded Profile: petra (Available profiles: petra)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * sdnclean64.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} URL = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} URL = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {C7CD73CA-3327-4E63-911E-C23C78A3C332} URL = http://search.yahoo.com/search?p={searc ... type=10809
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {F533918A-A8C5-4CB0-B704-1CDF6E16E34A} - No File
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
2014-12-31 01:20 - 2014-12-31 01:21 - 00027415 _____ () C:\Users\petra\Desktop\FRST.txt
2014-12-30 16:59 - 2014-12-30 16:59 - 02173952 _____ () C:\Users\petra\Desktop\adwcleaner_4.106.exe
2014-12-30 17:06 - 2014-09-21 20:05 - 00000000 ____D () C:\AdwCleaner
Task: {4637C94D-70E9-4131-8ABE-205BCA01F6A7} - System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846} => pcalua.exe -a C:\Users\petra\AppData\Roaming\uTorrent\uTorrent.exe -c /UNINSTALL
Task: {B2119B51-1358-491A-9D63-E581A63DF8B9} - System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42} => pcalua.exe -a "C:\Users\petra\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MKOOTH0S\AGEE_setup.exe" -d C:\Users\petra\Desktop
Unlock: C:\ProgramData\Microsoft\Secure\Icons
C:\ProgramData\Microsoft\Secure\Icons
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => Key deleted successfully.
HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => Key deleted successfully.
HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => Key deleted successfully.
HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => Key deleted successfully.
HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A}" => Key deleted successfully.
HKCR\CLSID\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}" => Key deleted successfully.
HKCR\CLSID\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34}" => Key deleted successfully.
HKCR\CLSID\{4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD}" => Key deleted successfully.
HKCR\CLSID\{A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7CD73CA-3327-4E63-911E-C23C78A3C332}" => Key deleted successfully.
HKCR\CLSID\{C7CD73CA-3327-4E63-911E-C23C78A3C332} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A}" => Key deleted successfully.
HKCR\CLSID\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} => Key not found.
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F533918A-A8C5-4CB0-B704-1CDF6E16E34A} => value deleted successfully.
HKCR\CLSID\{F533918A-A8C5-4CB0-B704-1CDF6E16E34A} => Key not found.
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} => value deleted successfully.
HKCR\CLSID\{7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} => Key not found.
"HKCR\Wow6432Node\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"C:\Users\petra\Desktop\FRST.txt" => File/Directory not found.
C:\Users\petra\Desktop\adwcleaner_4.106.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4637C94D-70E9-4131-8ABE-205BCA01F6A7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4637C94D-70E9-4131-8ABE-205BCA01F6A7}" => Key deleted successfully.
C:\Windows\System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4547B2DF-65D8-4CDB-A59A-46A2937A7846}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B2119B51-1358-491A-9D63-E581A63DF8B9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2119B51-1358-491A-9D63-E581A63DF8B9}" => Key deleted successfully.
C:\Windows\System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42}" => Key deleted successfully.
"C:\ProgramData\Microsoft\Secure\Icons" => File/Directory unlocked successfully.
C:\ProgramData\Microsoft\Secure\Icons => Moved successfully.
EmptyTemp: => Removed 69.9 MB temporary data.
The system needed a reboot.
==== End of Fixlog 09:37:04 ====
RSIT.log
Logfile of random's system information tool 1.10 (written by random/random)
Run by petra at 2014-12-31 09:56:52
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 158 GB (66%) free of 239 GB
Total RAM: 3996 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:56:58, on 31.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Citrix\Secure Access Client\nsload.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe
C:\Program Files (x86)\PDF24\pdf24.exe
C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
C:\windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\petra.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://cag.autocont.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Lync add-on BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [NortonOnlineBackup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [HTC Sync] "C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe"
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [Redirector] "C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup
O4 - HKLM\..\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - Global Startup: Citrix Access Gateway.lnk = C:\Program Files\Citrix\Secure Access Client\nsload.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: XMLSpy_EditWith_IESupport - C:\Program Files (x86)\Altova\XMLSpy2015\spy.htm
O9 - Extra button: XMLSpy_EditWith_IESupport - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files (x86)\Altova\XMLSpy2015\spy.htm
O9 - Extra 'Tools' menuitem: XMLSpy_EditWith_IESupport - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files (x86)\Altova\XMLSpy2015\spy.htm
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra 'Tools' menuitem: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Citrix Secure Access Client Service (nsverctl) - Citrix Systems, Inc - C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 17377 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-5b01-514b88a6a041 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\LSI SoftModem\agr64svc.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" service
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files\Citrix\Secure Access Client\nsverctl.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
WLIDSvcM.exe 2972
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
C:\windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files\Citrix\Secure Access Client\nsload.exe" /noDisplayLogin
"C:\Program Files\Motorola\Bluetooth\audiosrv.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
"C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe"
"C:\Program Files (x86)\PDF24\pdf24.exe"
"C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe" /watchfiles startup
"C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" view=SYSTRAY
"C:\Program Files (x86)\Citrix\Receiver\Receiver.exe" -autoupdate -startplugins
C:\windows\System32\svchost.exe -k LocalServicePeerNet
ctfmon.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe" -Embedding
"C:\windows\system32\wuauclt.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe" -Embedding
"C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe"
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\windows\system32\NOTEPAD.EXE" C:\Users\petra\Desktop\Fixlog.txt
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6948.0.347180052\250143749" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x2a42 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2057 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Control/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="6948.1.555483554\46449867" /prefetch:673131151
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Control/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="6948.6.795927812\879598703" /prefetch:673131151
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Control/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="6948.7.5507919\267489296" /prefetch:673131151
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\petra\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\HPCeeScheduleForpetra.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForpetra (null)
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll [2010-11-03 211720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2010-01-08 186904]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-01-22 2028328]
"BTMTrayAgent"=C:\Program Files\Motorola\Bluetooth\btmshell.dll [2010-06-10 24783624]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2010-03-25 166424]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2010-03-25 390680]
"Persistence"=C:\windows\system32\igfxpers.exe [2010-03-25 410136]
"SmartSoft PDF Printer Agent"=C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe [2011-05-17 50560]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2013-06-21 489472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"=C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [2010-02-10 1712184]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-01-22 2363392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2010-01-12 563736]
"WirelessAssistant"=C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-09-01 499768]
"NortonOnlineBackup"=C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2010-05-03 1110360]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2010-12-09 74752]
"VirtualCloneDrive"=C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]
"HTC Sync"=C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe [2010-04-16 180224]
"PDFPrint"=C:\Program Files (x86)\PDF24\pdf24.exe [2011-04-28 220552]
"NokiaMServer"=C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"ConnectionCenter"=C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [2013-10-01 395656]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-10-01 256056]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2013-12-27 570880]
"Redirector"=C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [2013-10-01 153992]
"Communicator"=C:\Program Files (x86)\Microsoft Lync\communicator.exe [2014-05-01 12117312]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2014-11-09 3653136]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Citrix Access Gateway.lnk - C:\Program Files\Citrix\Secure Access Client\nsload.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2010-01-25 268800]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-12-30 16:18:49 ----SHD---- C:\$RECYCLE.BIN
2014-12-30 16:18:39 ----A---- C:\ComboFix.txt
2014-12-30 13:56:06 ----A---- C:\windows\zip.exe
2014-12-30 13:56:06 ----A---- C:\windows\SWSC.exe
2014-12-30 13:56:06 ----A---- C:\windows\SWREG.exe
2014-12-30 13:56:06 ----A---- C:\windows\sed.exe
2014-12-30 13:56:06 ----A---- C:\windows\PEV.exe
2014-12-30 13:56:06 ----A---- C:\windows\NIRCMD.exe
2014-12-30 13:56:06 ----A---- C:\windows\MBR.exe
2014-12-30 13:56:06 ----A---- C:\windows\grep.exe
2014-12-30 13:55:56 ----D---- C:\Qoobox
2014-12-30 13:55:36 ----D---- C:\windows\erdnt
2014-12-29 20:58:20 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-29 17:49:48 ----D---- C:\FRST
2014-12-29 17:12:28 ----D---- C:\_OTM
2014-12-29 15:27:24 ----A---- C:\TDSSKiller.3.0.0.42_29.12.2014_15.27.24_log.txt
2014-12-28 10:55:41 ----A---- C:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-28 10:53:30 ----D---- C:\ProgramData\Malwarebytes
2014-12-28 10:53:30 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-28 10:53:30 ----A---- C:\windows\system32\drivers\mwac.sys
2014-12-28 10:53:30 ----A---- C:\windows\system32\drivers\mbamchameleon.sys
2014-12-28 10:53:30 ----A---- C:\windows\system32\drivers\mbam.sys
2014-12-28 10:27:14 ----D---- C:\Program Files\CCleaner
2014-12-28 10:20:51 ----D---- C:\Program Files\trend micro
2014-12-28 10:20:49 ----D---- C:\rsit
2014-12-18 06:13:23 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-12-18 06:13:23 ----A---- C:\windows\system32\ieUnatt.exe
2014-12-10 06:34:09 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2014-12-10 06:34:09 ----A---- C:\windows\system32\WindowsCodecs.dll
2014-12-10 06:34:00 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-12-10 06:34:00 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-12-10 06:33:59 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-12-10 06:33:59 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-12-10 06:33:59 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-12-10 06:33:59 ----A---- C:\windows\system32\iernonce.dll
2014-12-10 06:33:59 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-12-10 06:33:59 ----A---- C:\windows\system32\ieetwcollector.exe
2014-12-10 06:33:59 ----A---- C:\windows\system32\ie4uinit.exe
2014-12-10 06:33:58 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-10 06:33:57 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-12-10 06:33:57 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-12-10 06:33:57 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-12-10 06:33:57 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 06:33:56 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-12-10 06:33:56 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-12-10 06:33:55 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-12-10 06:33:55 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-12-10 06:33:55 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-12-10 06:33:55 ----A---- C:\windows\system32\urlmon.dll
2014-12-10 06:33:55 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-12-10 06:33:55 ----A---- C:\windows\system32\iedkcs32.dll
2014-12-10 06:33:54 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 06:33:53 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-12-10 06:33:53 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-12-10 06:33:53 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-12-10 06:33:53 ----A---- C:\windows\system32\msfeeds.dll
2014-12-10 06:33:53 ----A---- C:\windows\system32\dxtrans.dll
2014-12-10 06:33:52 ----A---- C:\windows\system32\iesetup.dll
2014-12-10 06:33:52 ----A---- C:\windows\system32\ieapfltr.dll
2014-12-10 06:33:51 ----A---- C:\windows\system32\iertutil.dll
2014-12-10 06:33:50 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-12-10 06:33:50 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-12-10 06:33:49 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-12-10 06:33:49 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-12-10 06:33:49 ----A---- C:\windows\system32\jsproxy.dll
2014-12-10 06:33:47 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-12-10 06:33:47 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2014-12-10 06:33:46 ----A---- C:\windows\system32\dxtmsft.dll
2014-12-10 06:33:45 ----A---- C:\windows\system32\ieui.dll
2014-12-10 06:33:45 ----A---- C:\windows\system32\ieframe.dll
2014-12-10 06:33:44 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-12-10 06:33:44 ----A---- C:\windows\system32\mshtmled.dll
2014-12-10 06:33:44 ----A---- C:\windows\system32\jscript9diag.dll
2014-12-10 06:33:43 ----A---- C:\windows\system32\wininet.dll
2014-12-10 06:33:43 ----A---- C:\windows\system32\vbscript.dll
2014-12-10 06:33:43 ----A---- C:\windows\system32\jscript9.dll
2014-12-10 06:33:42 ----A---- C:\windows\system32\MshtmlDac.dll
2014-12-10 06:33:41 ----A---- C:\windows\system32\msrating.dll
2014-12-10 06:33:40 ----A---- C:\windows\system32\mshtml.dll
2014-12-09 09:45:22 ----A---- C:\windows\system32\drivers\avgtpx64.sys
2014-12-09 09:45:16 ----D---- C:\ProgramData\AVG Web TuneUp
2014-12-09 09:45:14 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2014-12-08 20:10:20 ----D---- C:\Users\petra\AppData\Roaming\AVG2015
2014-12-08 20:09:11 ----D---- C:\Users\petra\AppData\Roaming\TuneUp Software
2014-12-08 20:07:56 ----D---- C:\ProgramData\AVG2015
2014-12-08 20:07:56 ----D---- C:\$AVG
2014-12-08 20:06:17 ----D---- C:\Program Files (x86)\AVG
2014-12-08 19:15:29 ----D---- C:\ProgramData\MFAData
2014-12-07 17:37:50 ----SD---- C:\windows\SYSWOW64\Microsoft
2014-12-05 01:59:51 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-12-05 01:59:47 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-12-05 01:58:54 ----D---- C:\Program Files\Application Verifier
2014-12-05 01:58:54 ----D---- C:\Program Files (x86)\Application Verifier
2014-12-05 01:58:45 ----D---- C:\ProgramData\Windows App Certification Kit
2014-12-05 01:57:00 ----D---- C:\ProgramData\PreEmptive Solutions
2014-12-05 01:54:25 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2014-12-05 01:53:52 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2014-12-05 01:53:29 ----D---- C:\Program Files\Microsoft
2014-12-05 01:52:59 ----D---- C:\Program Files\IIS Express
2014-12-05 01:52:59 ----D---- C:\Program Files (x86)\IIS Express
2014-12-05 01:52:32 ----D---- C:\Program Files (x86)\NuGet
2014-12-05 01:52:25 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2014-12-05 01:50:27 ----A---- C:\windows\SYSWOW64\D3DX9_43.dll
2014-12-05 01:49:33 ----D---- C:\Program Files (x86)\Windows Kits
2014-12-05 01:44:06 ----D---- C:\Program Files (x86)\HTML Help Workshop
2014-12-05 01:43:32 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2014-12-05 01:41:58 ----D---- C:\windows\SYSWOW64\1033
2014-12-05 01:41:44 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2014-12-05 01:41:43 ----D---- C:\Program Files\Microsoft SQL Server
2014-12-05 01:36:42 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-12-05 01:36:40 ----D---- C:\windows\system32\1033
2014-12-05 01:36:33 ----D---- C:\windows\symbols
2014-12-05 01:36:32 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2014-12-05 01:36:32 ----D---- C:\Program Files (x86)\Microsoft SDKs
2014-12-05 01:17:39 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-12-05 01:17:39 ----D---- C:\ProgramData\Package Cache
2014-12-04 13:51:24 ----D---- C:\ProgramData\Applications
2014-12-04 13:50:27 ----D---- C:\Program Files\Microsoft Lync
2014-12-04 13:50:19 ----D---- C:\Program Files (x86)\Microsoft Lync
2014-12-04 13:49:49 ----D---- C:\Program Files (x86)\OCSetup
======List of files/folders modified in the last 1 month======
2014-12-31 09:54:24 ----D---- C:\windows\Temp
2014-12-31 09:52:58 ----D---- C:\windows\system32\config
2014-12-31 09:36:58 ----D---- C:\windows\system32\Tasks
2014-12-31 01:22:22 ----D---- C:\Windows
2014-12-31 00:36:43 ----D---- C:\windows\system32\drivers
2014-12-31 00:36:43 ----D---- C:\windows\OEMCert
2014-12-30 17:06:52 ----D---- C:\ProgramData
2014-12-30 17:06:52 ----D---- C:\Program Files (x86)\Common Files
2014-12-30 17:02:04 ----D---- C:\windows\Tasks
2014-12-30 16:12:19 ----A---- C:\windows\system.ini
2014-12-30 16:12:04 ----D---- C:\windows\system32\drivers\etc
2014-12-30 15:58:06 ----D---- C:\windows\inf
2014-12-30 15:52:40 ----D---- C:\windows\SYSWOW64\drivers
2014-12-30 15:52:40 ----D---- C:\windows\SysWOW64
2014-12-30 15:52:40 ----D---- C:\windows\AppPatch
2014-12-30 15:41:53 ----SHD---- C:\windows\Installer
2014-12-30 15:41:42 ----RD---- C:\Program Files (x86)
2014-12-30 15:41:15 ----SHD---- C:\System Volume Information
2014-12-30 13:39:36 ----D---- C:\ProgramData\Skype
2014-12-30 13:39:34 ----RD---- C:\Program Files (x86)\Skype
2014-12-30 12:34:02 ----D---- C:\Users\petra\AppData\Roaming\uTorrent
2014-12-29 16:09:32 ----D---- C:\windows\Microsoft.NET
2014-12-29 14:19:34 ----D---- C:\windows\System32
2014-12-29 14:19:34 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-12-29 10:25:52 ----SD---- C:\Users\petra\AppData\Roaming\Microsoft
2014-12-29 10:08:51 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2014-12-29 09:13:46 ----D---- C:\windows\winsxs
2014-12-28 22:31:14 ----D---- C:\windows\system32\DriverStore
2014-12-28 22:27:08 ----D---- C:\windows\Prefetch
2014-12-28 11:40:34 ----D---- C:\windows\ServiceProfiles
2014-12-28 10:34:13 ----D---- C:\Users\petra\AppData\Roaming\Media Player Classic
2014-12-28 10:34:10 ----D---- C:\Program Files (x86)\PDFCreator
2014-12-28 10:30:21 ----D---- C:\windows\Panther
2014-12-28 10:30:19 ----D---- C:\windows\Logs
2014-12-28 10:30:19 ----D---- C:\windows\debug
2014-12-28 10:27:14 ----D---- C:\Program Files
2014-12-28 05:25:47 ----D---- C:\ProgramData\PDFC
2014-12-26 17:02:01 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-12-25 19:19:47 ----SD---- C:\ProgramData\Microsoft
2014-12-18 06:09:34 ----D---- C:\windows\system32\catroot2
2014-12-12 18:06:35 ----D---- C:\windows\rescache
2014-12-12 16:53:06 ----D---- C:\Program Files\Internet Explorer
2014-12-12 16:53:05 ----D---- C:\windows\SYSWOW64\en-US
2014-12-12 16:53:05 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-12-12 16:53:04 ----D---- C:\windows\system32\en-US
2014-12-12 16:53:04 ----D---- C:\windows\system32\cs-CZ
2014-12-12 16:53:04 ----D---- C:\windows\PolicyDefinitions
2014-12-12 16:53:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-12 16:36:16 ----D---- C:\ProgramData\Microsoft Help
2014-12-12 16:34:59 ----D---- C:\windows\system32\MRT
2014-12-12 16:18:44 ----A---- C:\windows\system32\MRT.exe
2014-12-09 20:07:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-12-07 18:29:29 ----D---- C:\Users\petra\AppData\Roaming\vlc
2014-12-06 09:04:49 ----RSD---- C:\windows\assembly
2014-12-06 07:59:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-12-05 01:56:43 ----D---- C:\Program Files\MSBuild
2014-12-05 01:49:39 ----RSD---- C:\windows\Fonts
2014-12-05 01:43:40 ----D---- C:\Program Files (x86)\MSBuild
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\windows\system32\DRIVERS\avgidsha.sys [2014-06-18 190744]
R0 Avgloga;AVG Logging Driver; C:\windows\system32\DRIVERS\avgloga.sys [2014-07-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\windows\system32\DRIVERS\avgmfx64.sys [2014-10-05 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-01-08 409112]
R0 PxHlpa64;PxHlpa64; C:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 Avgdiska;AVG Disk Driver; C:\windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
R1 AVGIDSDriver;AVGIDSDriver; C:\windows\system32\DRIVERS\avgidsdrivera.sys [2014-10-29 263960]
R1 Avgldx64;AVG AVI Loader Driver; C:\windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
R1 Avgtdia;AVG TDI Driver; C:\windows\system32\DRIVERS\avgtdia.sys [2014-10-10 274200]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2014-12-09 50976]
R1 ctxusbm;Citrix USB Monitor Driver; C:\windows\system32\DRIVERS\ctxusbm.sys [2013-09-24 97768]
R1 DNE;DNE LightWeight Filter; C:\windows\system32\DRIVERS\dnelwf64.sys [2013-02-20 119120]
R1 ElbyCDIO;ElbyCDIO Driver; C:\windows\System32\Drivers\ElbyCDIO.sys [2013-03-04 40344]
R1 truecrypt;truecrypt; C:\windows\System32\drivers\truecrypt.sys [2012-08-20 231376]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 cag;Citrix cag plugin for Access Gateway; \??\C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys [2013-04-01 102160]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-11-02 1209856]
R3 ctxva51;Citrix Virtual Adapter; C:\windows\system32\DRIVERS\ctxva51.sys [2014-01-10 46640]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-16 25912]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2010-01-25 7842272]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\windows\system32\drivers\IntcHdmi.sys [2010-03-15 145408]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2014-11-21 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2014-12-31 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2014-11-21 63704]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2010-06-29 931168]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2010-05-03 331880]
R3 rtsuvc;HP Webcam [2 MP Fixed]; C:\windows\system32\DRIVERS\rtsuvc.sys [2010-05-21 96384]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2013-06-21 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-01-22 305200]
R3 VClone;VClone; C:\windows\system32\DRIVERS\VClone.sys [2013-07-24 34816]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btmaudio;Motorola Bluetooth Audio Service; C:\windows\system32\drivers\btmaud.sys [2010-05-20 42496]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-04-10 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-06-18 28672]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2010-07-08 3232768]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 HtcVCom32;HTC Diagnostic Port; C:\windows\system32\DRIVERS\HtcVComV64.sys [2009-07-30 118872]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-05-18 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-05-18 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\windows\system32\DRIVERS\ss_bus.sys [2009-09-21 127488]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\windows\system32\DRIVERS\ss_mdfl.sys [2009-09-21 18944]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\windows\system32\DRIVERS\ss_mdm.sys [2009-09-21 161280]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-05-18 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-05-18 9216]
S3 VSPerfDrv110;Performance Tools Driver 11.0; \??\C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2013-06-21 89600]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agr64svc.exe [2009-11-02 16896]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-11-09 3488784]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-11-09 298080]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-10-01 280120]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2010-01-08 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-01-22 73728]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 NOBU;Norton Online Backup; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-05-03 2782552]
R2 nsverctl;Citrix Secure Access Client Service; C:\Program Files\Citrix\Secure Access Client\nsverctl.exe [2014-01-10 157744]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-01-12 635416]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2013-06-21 271360]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
R3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-09-27 1028096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-27 647680]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 stllssvr;stllssvr; c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-12-19 1255736]
S4 NetMsmqActivator;@c:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetPipeActivator;@c:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetTcpActivator;@c:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
-----------------EOF-----------------
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2014
Ran by petra at 2014-12-31 09:36:53 Run:2
Running from C:\Users\petra\Desktop
Loaded Profile: petra (Available profiles: petra)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
BootExecute: autocheck autochk * sdnclean64.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://www.bing.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} URL = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} URL = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {C7CD73CA-3327-4E63-911E-C23C78A3C332} URL = http://search.yahoo.com/search?p={searc ... type=10809
SearchScopes: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> {EFD90A5C-C40F-45D9-92AB-A3DAE671237A} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {F533918A-A8C5-4CB0-B704-1CDF6E16E34A} - No File
Toolbar: HKU\S-1-5-21-1537954393-1589409457-3668467252-1002 -> No Name - {7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
2014-12-31 01:20 - 2014-12-31 01:21 - 00027415 _____ () C:\Users\petra\Desktop\FRST.txt
2014-12-30 16:59 - 2014-12-30 16:59 - 02173952 _____ () C:\Users\petra\Desktop\adwcleaner_4.106.exe
2014-12-30 17:06 - 2014-09-21 20:05 - 00000000 ____D () C:\AdwCleaner
Task: {4637C94D-70E9-4131-8ABE-205BCA01F6A7} - System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846} => pcalua.exe -a C:\Users\petra\AppData\Roaming\uTorrent\uTorrent.exe -c /UNINSTALL
Task: {B2119B51-1358-491A-9D63-E581A63DF8B9} - System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42} => pcalua.exe -a "C:\Users\petra\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MKOOTH0S\AGEE_setup.exe" -d C:\Users\petra\Desktop
Unlock: C:\ProgramData\Microsoft\Secure\Icons
C:\ProgramData\Microsoft\Secure\Icons
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => Key deleted successfully.
HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => Key deleted successfully.
HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => Key deleted successfully.
HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => Key deleted successfully.
HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => Key not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A}" => Key deleted successfully.
HKCR\CLSID\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0}" => Key deleted successfully.
HKCR\CLSID\{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34}" => Key deleted successfully.
HKCR\CLSID\{4C9CBA0D-2FB5-4A52-B2F2-309B981A6D34} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD}" => Key deleted successfully.
HKCR\CLSID\{A3C94BE3-88E5-49A7-8E8F-4118A4DDA8BD} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C7CD73CA-3327-4E63-911E-C23C78A3C332}" => Key deleted successfully.
HKCR\CLSID\{C7CD73CA-3327-4E63-911E-C23C78A3C332} => Key not found.
"HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A}" => Key deleted successfully.
HKCR\CLSID\{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} => Key not found.
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F533918A-A8C5-4CB0-B704-1CDF6E16E34A} => value deleted successfully.
HKCR\CLSID\{F533918A-A8C5-4CB0-B704-1CDF6E16E34A} => Key not found.
HKU\S-1-5-21-1537954393-1589409457-3668467252-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} => value deleted successfully.
HKCR\CLSID\{7BF9DE01-F60A-41F0-B158-ACF52E5F99B8} => Key not found.
"HKCR\Wow6432Node\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"C:\Users\petra\Desktop\FRST.txt" => File/Directory not found.
C:\Users\petra\Desktop\adwcleaner_4.106.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4637C94D-70E9-4131-8ABE-205BCA01F6A7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4637C94D-70E9-4131-8ABE-205BCA01F6A7}" => Key deleted successfully.
C:\Windows\System32\Tasks\{4547B2DF-65D8-4CDB-A59A-46A2937A7846} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4547B2DF-65D8-4CDB-A59A-46A2937A7846}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B2119B51-1358-491A-9D63-E581A63DF8B9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2119B51-1358-491A-9D63-E581A63DF8B9}" => Key deleted successfully.
C:\Windows\System32\Tasks\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{74AE9AB3-119A-4DD3-BCCA-0B26A6AAED42}" => Key deleted successfully.
"C:\ProgramData\Microsoft\Secure\Icons" => File/Directory unlocked successfully.
C:\ProgramData\Microsoft\Secure\Icons => Moved successfully.
EmptyTemp: => Removed 69.9 MB temporary data.
The system needed a reboot.
==== End of Fixlog 09:37:04 ====
RSIT.log
Logfile of random's system information tool 1.10 (written by random/random)
Run by petra at 2014-12-31 09:56:52
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 158 GB (66%) free of 239 GB
Total RAM: 3996 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:56:58, on 31.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Citrix\Secure Access Client\nsload.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe
C:\Program Files (x86)\PDF24\pdf24.exe
C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
C:\Program Files (x86)\AVG\AVG2015\avgui.exe
C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Citrix\Receiver\Receiver.exe
C:\windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\petra.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://cag.autocont.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Lync add-on BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [NortonOnlineBackup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [HTC Sync] "C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe"
O4 - HKLM\..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [Nikon Message Center 2] C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe -s
O4 - HKLM\..\Run: [Redirector] "C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup
O4 - HKLM\..\Run: [Communicator] "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - Global Startup: Citrix Access Gateway.lnk = C:\Program Files\Citrix\Secure Access Client\nsload.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: XMLSpy_EditWith_IESupport - C:\Program Files (x86)\Altova\XMLSpy2015\spy.htm
O9 - Extra button: XMLSpy_EditWith_IESupport - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files (x86)\Altova\XMLSpy2015\spy.htm
O9 - Extra 'Tools' menuitem: XMLSpy_EditWith_IESupport - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files (x86)\Altova\XMLSpy2015\spy.htm
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra 'Tools' menuitem: Doplněk aplikace Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Hotkey Monitor (hpHotkeyMonitor) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: Citrix Secure Access Client Service (nsverctl) - Citrix Systems, Inc - C:\Program Files\Citrix\Secure Access Client\nsverctl.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10122 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 17377 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
c:\PROGRA~2\AVG\AVG2015\avgrsa.exe /boot
C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe /pipeName=c2feea3f-0200-0000-5b01-514b88a6a041 /binaryPath="C:\Program Files (x86)\AVG\AVG2015\"
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
winlogon.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files\LSI SoftModem\agr64svc.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" service
"C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG2015\avgemca.exe"
"C:\Program Files\Citrix\Secure Access Client\nsverctl.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe"
C:\windows\system32\wbem\unsecapp.exe -Embedding
WLIDSvcM.exe 2972
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\System32\rundll32.exe" "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe"
"C:\Program Files\IDT\WDM\sttray64.exe"
C:\windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Program Files\Citrix\Secure Access Client\nsload.exe" /noDisplayLogin
"C:\Program Files\Motorola\Bluetooth\audiosrv.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
"C:\Program Files (x86)\Winamp\winampa.exe"
"C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
"C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe"
"C:\Program Files (x86)\PDF24\pdf24.exe"
"C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer.exe" /watchfiles startup
"C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
"C:\Program Files (x86)\Citrix\ICA Client\redirector.exe" /startup
"C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
"C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe" -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" view=SYSTRAY
"C:\Program Files (x86)\Citrix\Receiver\Receiver.exe" -autoupdate -startplugins
C:\windows\System32\svchost.exe -k LocalServicePeerNet
ctfmon.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe" -Embedding
"C:\windows\system32\wuauclt.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe" -Embedding
"C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe"
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\windows\system32\NOTEPAD.EXE" C:\Users\petra\Desktop\Fixlog.txt
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6948.0.347180052\250143749" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x2a42 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2057 --ignored=" --type=renderer " /prefetch:822062411
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Control/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="6948.1.555483554\46449867" /prefetch:673131151
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Control/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="6948.6.795927812\879598703" /prefetch:673131151
"C:\Users\petra\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group5 pct:10e stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleNow/Enable/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StableBookmarksIndexURLsControl/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Control/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_04/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="6948.7.5507919\267489296" /prefetch:673131151
"C:\windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\windows\system32\SearchFilterHost.exe" 0 508 512 520 65536 516
"C:\Users\petra\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\HPCeeScheduleForpetra.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForpetra (null)
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08 77424]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll [2010-11-03 211720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [2010-01-08 186904]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-01-22 2028328]
"BTMTrayAgent"=C:\Program Files\Motorola\Bluetooth\btmshell.dll [2010-06-10 24783624]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2010-03-25 166424]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2010-03-25 390680]
"Persistence"=C:\windows\system32\igfxpers.exe [2010-03-25 410136]
"SmartSoft PDF Printer Agent"=C:\Program Files\Smart PDF Creator\SmartSoft PDF Printer Agent.exe [2011-05-17 50560]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2013-06-21 489472]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"=C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [2010-02-10 1712184]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2010-01-22 2363392]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PDF Complete"=C:\Program Files (x86)\PDF Complete\pdfsty.exe [2010-01-12 563736]
"WirelessAssistant"=C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2009-09-01 499768]
"NortonOnlineBackup"=C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2010-05-03 1110360]
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe [2010-12-09 74752]
"VirtualCloneDrive"=C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]
"HTC Sync"=C:\Program Files (x86)\HTC\HTC Sync for BrewMP\AutoDetect.exe [2010-04-16 180224]
"PDFPrint"=C:\Program Files (x86)\PDF24\pdf24.exe [2011-04-28 220552]
"NokiaMServer"=C:\Program Files (x86)\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"ConnectionCenter"=C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [2013-10-01 395656]
"QLBController"=C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [2010-10-01 256056]
"Nikon Message Center 2"=C:\Program Files (x86)\Nikon\Nikon Message Center 2\NkMC2.exe [2013-12-27 570880]
"Redirector"=C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [2013-10-01 153992]
"Communicator"=C:\Program Files (x86)\Microsoft Lync\communicator.exe [2014-05-01 12117312]
"AVG_UI"=C:\Program Files (x86)\AVG\AVG2015\avgui.exe [2014-11-09 3653136]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Citrix Access Gateway.lnk - C:\Program Files\Citrix\Secure Access Client\nsload.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2010-01-25 268800]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2014-12-30 16:18:49 ----SHD---- C:\$RECYCLE.BIN
2014-12-30 16:18:39 ----A---- C:\ComboFix.txt
2014-12-30 13:56:06 ----A---- C:\windows\zip.exe
2014-12-30 13:56:06 ----A---- C:\windows\SWSC.exe
2014-12-30 13:56:06 ----A---- C:\windows\SWREG.exe
2014-12-30 13:56:06 ----A---- C:\windows\sed.exe
2014-12-30 13:56:06 ----A---- C:\windows\PEV.exe
2014-12-30 13:56:06 ----A---- C:\windows\NIRCMD.exe
2014-12-30 13:56:06 ----A---- C:\windows\MBR.exe
2014-12-30 13:56:06 ----A---- C:\windows\grep.exe
2014-12-30 13:55:56 ----D---- C:\Qoobox
2014-12-30 13:55:36 ----D---- C:\windows\erdnt
2014-12-29 20:58:20 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-29 17:49:48 ----D---- C:\FRST
2014-12-29 17:12:28 ----D---- C:\_OTM
2014-12-29 15:27:24 ----A---- C:\TDSSKiller.3.0.0.42_29.12.2014_15.27.24_log.txt
2014-12-28 10:55:41 ----A---- C:\windows\system32\drivers\MBAMSwissArmy.sys
2014-12-28 10:53:30 ----D---- C:\ProgramData\Malwarebytes
2014-12-28 10:53:30 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-28 10:53:30 ----A---- C:\windows\system32\drivers\mwac.sys
2014-12-28 10:53:30 ----A---- C:\windows\system32\drivers\mbamchameleon.sys
2014-12-28 10:53:30 ----A---- C:\windows\system32\drivers\mbam.sys
2014-12-28 10:27:14 ----D---- C:\Program Files\CCleaner
2014-12-28 10:20:51 ----D---- C:\Program Files\trend micro
2014-12-28 10:20:49 ----D---- C:\rsit
2014-12-18 06:13:23 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-12-18 06:13:23 ----A---- C:\windows\system32\ieUnatt.exe
2014-12-10 06:34:09 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2014-12-10 06:34:09 ----A---- C:\windows\system32\WindowsCodecs.dll
2014-12-10 06:34:00 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-12-10 06:34:00 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-12-10 06:33:59 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-12-10 06:33:59 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-12-10 06:33:59 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-12-10 06:33:59 ----A---- C:\windows\system32\iernonce.dll
2014-12-10 06:33:59 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-12-10 06:33:59 ----A---- C:\windows\system32\ieetwcollector.exe
2014-12-10 06:33:59 ----A---- C:\windows\system32\ie4uinit.exe
2014-12-10 06:33:58 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-10 06:33:57 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-12-10 06:33:57 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-12-10 06:33:57 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-12-10 06:33:57 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 06:33:56 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-12-10 06:33:56 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-12-10 06:33:55 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-12-10 06:33:55 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-12-10 06:33:55 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-12-10 06:33:55 ----A---- C:\windows\system32\urlmon.dll
2014-12-10 06:33:55 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-12-10 06:33:55 ----A---- C:\windows\system32\iedkcs32.dll
2014-12-10 06:33:54 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 06:33:53 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-12-10 06:33:53 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-12-10 06:33:53 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-12-10 06:33:53 ----A---- C:\windows\system32\msfeeds.dll
2014-12-10 06:33:53 ----A---- C:\windows\system32\dxtrans.dll
2014-12-10 06:33:52 ----A---- C:\windows\system32\iesetup.dll
2014-12-10 06:33:52 ----A---- C:\windows\system32\ieapfltr.dll
2014-12-10 06:33:51 ----A---- C:\windows\system32\iertutil.dll
2014-12-10 06:33:50 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-12-10 06:33:50 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-12-10 06:33:49 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-12-10 06:33:49 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-12-10 06:33:49 ----A---- C:\windows\system32\jsproxy.dll
2014-12-10 06:33:47 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-12-10 06:33:47 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2014-12-10 06:33:46 ----A---- C:\windows\system32\dxtmsft.dll
2014-12-10 06:33:45 ----A---- C:\windows\system32\ieui.dll
2014-12-10 06:33:45 ----A---- C:\windows\system32\ieframe.dll
2014-12-10 06:33:44 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-12-10 06:33:44 ----A---- C:\windows\system32\mshtmled.dll
2014-12-10 06:33:44 ----A---- C:\windows\system32\jscript9diag.dll
2014-12-10 06:33:43 ----A---- C:\windows\system32\wininet.dll
2014-12-10 06:33:43 ----A---- C:\windows\system32\vbscript.dll
2014-12-10 06:33:43 ----A---- C:\windows\system32\jscript9.dll
2014-12-10 06:33:42 ----A---- C:\windows\system32\MshtmlDac.dll
2014-12-10 06:33:41 ----A---- C:\windows\system32\msrating.dll
2014-12-10 06:33:40 ----A---- C:\windows\system32\mshtml.dll
2014-12-09 09:45:22 ----A---- C:\windows\system32\drivers\avgtpx64.sys
2014-12-09 09:45:16 ----D---- C:\ProgramData\AVG Web TuneUp
2014-12-09 09:45:14 ----D---- C:\Program Files (x86)\AVG Web TuneUp
2014-12-08 20:10:20 ----D---- C:\Users\petra\AppData\Roaming\AVG2015
2014-12-08 20:09:11 ----D---- C:\Users\petra\AppData\Roaming\TuneUp Software
2014-12-08 20:07:56 ----D---- C:\ProgramData\AVG2015
2014-12-08 20:07:56 ----D---- C:\$AVG
2014-12-08 20:06:17 ----D---- C:\Program Files (x86)\AVG
2014-12-08 19:15:29 ----D---- C:\ProgramData\MFAData
2014-12-07 17:37:50 ----SD---- C:\windows\SYSWOW64\Microsoft
2014-12-05 01:59:51 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-12-05 01:59:47 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2014-12-05 01:58:54 ----D---- C:\Program Files\Application Verifier
2014-12-05 01:58:54 ----D---- C:\Program Files (x86)\Application Verifier
2014-12-05 01:58:45 ----D---- C:\ProgramData\Windows App Certification Kit
2014-12-05 01:57:00 ----D---- C:\ProgramData\PreEmptive Solutions
2014-12-05 01:54:25 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2014-12-05 01:53:52 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2014-12-05 01:53:29 ----D---- C:\Program Files\Microsoft
2014-12-05 01:52:59 ----D---- C:\Program Files\IIS Express
2014-12-05 01:52:59 ----D---- C:\Program Files (x86)\IIS Express
2014-12-05 01:52:32 ----D---- C:\Program Files (x86)\NuGet
2014-12-05 01:52:25 ----D---- C:\Program Files (x86)\Microsoft WCF Data Services
2014-12-05 01:50:27 ----A---- C:\windows\SYSWOW64\D3DX9_43.dll
2014-12-05 01:49:33 ----D---- C:\Program Files (x86)\Windows Kits
2014-12-05 01:44:06 ----D---- C:\Program Files (x86)\HTML Help Workshop
2014-12-05 01:43:32 ----D---- C:\Program Files (x86)\Microsoft Help Viewer
2014-12-05 01:41:58 ----D---- C:\windows\SYSWOW64\1033
2014-12-05 01:41:44 ----D---- C:\Program Files (x86)\Microsoft SQL Server
2014-12-05 01:41:43 ----D---- C:\Program Files\Microsoft SQL Server
2014-12-05 01:36:42 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 11.0
2014-12-05 01:36:40 ----D---- C:\windows\system32\1033
2014-12-05 01:36:33 ----D---- C:\windows\symbols
2014-12-05 01:36:32 ----D---- C:\Program Files\Microsoft Visual Studio 11.0
2014-12-05 01:36:32 ----D---- C:\Program Files (x86)\Microsoft SDKs
2014-12-05 01:17:39 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-12-05 01:17:39 ----D---- C:\ProgramData\Package Cache
2014-12-04 13:51:24 ----D---- C:\ProgramData\Applications
2014-12-04 13:50:27 ----D---- C:\Program Files\Microsoft Lync
2014-12-04 13:50:19 ----D---- C:\Program Files (x86)\Microsoft Lync
2014-12-04 13:49:49 ----D---- C:\Program Files (x86)\OCSetup
======List of files/folders modified in the last 1 month======
2014-12-31 09:54:24 ----D---- C:\windows\Temp
2014-12-31 09:52:58 ----D---- C:\windows\system32\config
2014-12-31 09:36:58 ----D---- C:\windows\system32\Tasks
2014-12-31 01:22:22 ----D---- C:\Windows
2014-12-31 00:36:43 ----D---- C:\windows\system32\drivers
2014-12-31 00:36:43 ----D---- C:\windows\OEMCert
2014-12-30 17:06:52 ----D---- C:\ProgramData
2014-12-30 17:06:52 ----D---- C:\Program Files (x86)\Common Files
2014-12-30 17:02:04 ----D---- C:\windows\Tasks
2014-12-30 16:12:19 ----A---- C:\windows\system.ini
2014-12-30 16:12:04 ----D---- C:\windows\system32\drivers\etc
2014-12-30 15:58:06 ----D---- C:\windows\inf
2014-12-30 15:52:40 ----D---- C:\windows\SYSWOW64\drivers
2014-12-30 15:52:40 ----D---- C:\windows\SysWOW64
2014-12-30 15:52:40 ----D---- C:\windows\AppPatch
2014-12-30 15:41:53 ----SHD---- C:\windows\Installer
2014-12-30 15:41:42 ----RD---- C:\Program Files (x86)
2014-12-30 15:41:15 ----SHD---- C:\System Volume Information
2014-12-30 13:39:36 ----D---- C:\ProgramData\Skype
2014-12-30 13:39:34 ----RD---- C:\Program Files (x86)\Skype
2014-12-30 12:34:02 ----D---- C:\Users\petra\AppData\Roaming\uTorrent
2014-12-29 16:09:32 ----D---- C:\windows\Microsoft.NET
2014-12-29 14:19:34 ----D---- C:\windows\System32
2014-12-29 14:19:34 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-12-29 10:25:52 ----SD---- C:\Users\petra\AppData\Roaming\Microsoft
2014-12-29 10:08:51 ----A---- C:\windows\SYSWOW64\PerfStringBackup.INI
2014-12-29 09:13:46 ----D---- C:\windows\winsxs
2014-12-28 22:31:14 ----D---- C:\windows\system32\DriverStore
2014-12-28 22:27:08 ----D---- C:\windows\Prefetch
2014-12-28 11:40:34 ----D---- C:\windows\ServiceProfiles
2014-12-28 10:34:13 ----D---- C:\Users\petra\AppData\Roaming\Media Player Classic
2014-12-28 10:34:10 ----D---- C:\Program Files (x86)\PDFCreator
2014-12-28 10:30:21 ----D---- C:\windows\Panther
2014-12-28 10:30:19 ----D---- C:\windows\Logs
2014-12-28 10:30:19 ----D---- C:\windows\debug
2014-12-28 10:27:14 ----D---- C:\Program Files
2014-12-28 05:25:47 ----D---- C:\ProgramData\PDFC
2014-12-26 17:02:01 ----A---- C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-12-25 19:19:47 ----SD---- C:\ProgramData\Microsoft
2014-12-18 06:09:34 ----D---- C:\windows\system32\catroot2
2014-12-12 18:06:35 ----D---- C:\windows\rescache
2014-12-12 16:53:06 ----D---- C:\Program Files\Internet Explorer
2014-12-12 16:53:05 ----D---- C:\windows\SYSWOW64\en-US
2014-12-12 16:53:05 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-12-12 16:53:04 ----D---- C:\windows\system32\en-US
2014-12-12 16:53:04 ----D---- C:\windows\system32\cs-CZ
2014-12-12 16:53:04 ----D---- C:\windows\PolicyDefinitions
2014-12-12 16:53:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-12 16:36:16 ----D---- C:\ProgramData\Microsoft Help
2014-12-12 16:34:59 ----D---- C:\windows\system32\MRT
2014-12-12 16:18:44 ----A---- C:\windows\system32\MRT.exe
2014-12-09 20:07:18 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-12-07 18:29:29 ----D---- C:\Users\petra\AppData\Roaming\vlc
2014-12-06 09:04:49 ----RSD---- C:\windows\assembly
2014-12-06 07:59:48 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-12-05 01:56:43 ----D---- C:\Program Files\MSBuild
2014-12-05 01:49:39 ----RSD---- C:\windows\Fonts
2014-12-05 01:43:40 ----D---- C:\Program Files (x86)\MSBuild
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSHA;AVGIDSHA; C:\windows\system32\DRIVERS\avgidsha.sys [2014-06-18 190744]
R0 Avgloga;AVG Logging Driver; C:\windows\system32\DRIVERS\avgloga.sys [2014-07-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\windows\system32\DRIVERS\avgmfx64.sys [2014-10-05 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\windows\system32\DRIVERS\avgrkx64.sys [2014-06-18 31512]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2010-01-08 409112]
R0 PxHlpa64;PxHlpa64; C:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 Avgdiska;AVG Disk Driver; C:\windows\system32\DRIVERS\avgdiska.sys [2014-06-18 153368]
R1 AVGIDSDriver;AVGIDSDriver; C:\windows\system32\DRIVERS\avgidsdrivera.sys [2014-10-29 263960]
R1 Avgldx64;AVG AVI Loader Driver; C:\windows\system32\DRIVERS\avgldx64.sys [2014-08-28 243480]
R1 Avgtdia;AVG TDI Driver; C:\windows\system32\DRIVERS\avgtdia.sys [2014-10-10 274200]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2014-12-09 50976]
R1 ctxusbm;Citrix USB Monitor Driver; C:\windows\system32\DRIVERS\ctxusbm.sys [2013-09-24 97768]
R1 DNE;DNE LightWeight Filter; C:\windows\system32\DRIVERS\dnelwf64.sys [2013-02-20 119120]
R1 ElbyCDIO;ElbyCDIO Driver; C:\windows\System32\Drivers\ElbyCDIO.sys [2013-03-04 40344]
R1 truecrypt;truecrypt; C:\windows\System32\drivers\truecrypt.sys [2012-08-20 231376]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 cag;Citrix cag plugin for Access Gateway; \??\C:\Program Files\Common Files\Deterministic Networks\Common Files\cag.sys [2013-04-01 102160]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-11-02 1209856]
R3 ctxva51;Citrix Virtual Adapter; C:\windows\system32\DRIVERS\ctxva51.sys [2014-01-10 46640]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\windows\system32\DRIVERS\HpqKbFiltr.sys [2010-02-16 25912]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2010-01-25 7842272]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\windows\system32\drivers\IntcHdmi.sys [2010-03-15 145408]
R3 MBAMProtector;MBAMProtector; \??\C:\windows\system32\drivers\mbam.sys [2014-11-21 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [2014-12-31 129752]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\windows\system32\drivers\mwac.sys [2014-11-21 63704]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2010-06-29 931168]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2010-05-03 331880]
R3 rtsuvc;HP Webcam [2 MP Fixed]; C:\windows\system32\DRIVERS\rtsuvc.sys [2010-05-21 96384]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10322; C:\windows\system32\DRIVERS\stwrt64.sys [2013-06-21 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-01-22 305200]
R3 VClone;VClone; C:\windows\system32\DRIVERS\VClone.sys [2013-07-24 34816]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btmaudio;Motorola Bluetooth Audio Service; C:\windows\system32\drivers\btmaud.sys [2010-05-20 42496]
S3 BTMCOM;Bluetooth Serial Port; C:\windows\System32\Drivers\btmcom.sys [2010-04-10 52736]
S3 BTMNET;Motorola Bluetooth Network Adapter Service; C:\windows\system32\DRIVERS\btmnet.sys [2010-06-18 28672]
S3 BTMUSB;Motorola Bluetooth Radio Service; C:\windows\System32\Drivers\btmusb.sys [2010-07-08 3232768]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 HtcVCom32;HTC Diagnostic Port; C:\windows\system32\DRIVERS\HtcVComV64.sys [2009-07-30 118872]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2011-05-18 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2011-05-18 27136]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 sdbus;sdbus; C:\windows\system32\drivers\sdbus.sys [2010-11-20 109056]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\windows\system32\DRIVERS\ss_bus.sys [2009-09-21 127488]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\windows\system32\DRIVERS\ss_mdfl.sys [2009-09-21 18944]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\windows\system32\DRIVERS\ss_mdm.sys [2009-09-21 161280]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2011-05-18 9216]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2011-05-18 9216]
S3 VSPerfDrv110;Performance Tools Driver 11.0; \??\C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2013-06-21 89600]
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Program Files\LSI SoftModem\agr64svc.exe [2009-11-02 16896]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-11-09 3488784]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-11-09 298080]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2013-11-04 92160]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2013-05-13 270624]
R2 hpHotkeyMonitor;HP Hotkey Monitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [2010-10-01 280120]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2010-01-08 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-01-22 73728]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-11-21 969016]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-11-21 1871160]
R2 NOBU;Norton Online Backup; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-05-03 2782552]
R2 nsverctl;Citrix Secure Access Client Service; C:\Program Files\Citrix\Secure Access Client\nsverctl.exe [2014-01-10 157744]
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-01-12 635416]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10122; C:\Program Files\IDT\WDM\STacSV64.exe [2013-06-21 271360]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
R3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-09-27 1028096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2013-05-13 1129760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-27 647680]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2011-06-08 633856]
S3 stllssvr;stllssvr; c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe [2009-10-16 74392]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2010-12-19 1255736]
S4 NetMsmqActivator;@c:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetPipeActivator;@c:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
S4 NetTcpActivator;@c:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; c:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139680]
-----------------EOF-----------------
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
pchunter mi vyhodil modrou obrazovku windousu a po restartu se objevila chyba viz priloha
Podpis problému:
Název události problému: BlueScreen
Verze operačního systému: 6.1.7601.2.1.0.768.3
ID národního prostředí: 1029
Další informace o problému:
BCCode: 1e
BCP1: FFFFFFFFC0000005
BCP2: 000000001D3407FF
BCP3: 0000000000000008
BCP4: 000000001D3407FF
OS Version: 6_1_7601
Service Pack: 1_0
Product: 768_1
Soubory, které popisují problém:
C:\Windows\Minidump\123114-49249-01.dmp
C:\Users\petra\AppData\Local\Temp\WER-150587-0.sysdata.xml
Přečtěte si prohlášení o zásadách ochrany osobních údajů online:
http://go.microsoft.com/fwlink/?linkid= ... cid=0x0405
Pokud není k dispozici Prohlášení o zásadách ochrany osobních údajů online, přečtěte si toto prohlášení offline:
C:\windows\system32\cs-CZ\erofflps.txt
Ma pustit pchunter znova?
Podpis problému:
Název události problému: BlueScreen
Verze operačního systému: 6.1.7601.2.1.0.768.3
ID národního prostředí: 1029
Další informace o problému:
BCCode: 1e
BCP1: FFFFFFFFC0000005
BCP2: 000000001D3407FF
BCP3: 0000000000000008
BCP4: 000000001D3407FF
OS Version: 6_1_7601
Service Pack: 1_0
Product: 768_1
Soubory, které popisují problém:
C:\Windows\Minidump\123114-49249-01.dmp
C:\Users\petra\AppData\Local\Temp\WER-150587-0.sysdata.xml
Přečtěte si prohlášení o zásadách ochrany osobních údajů online:
http://go.microsoft.com/fwlink/?linkid= ... cid=0x0405
Pokud není k dispozici Prohlášení o zásadách ochrany osobních údajů online, přečtěte si toto prohlášení offline:
C:\windows\system32\cs-CZ\erofflps.txt
Ma pustit pchunter znova?
- Přílohy
-
- chyba po restartu.png (35.4 KiB) Zobrazeno 3776 x
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
Ano, pustte ho znovu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
v priloze
- Přílohy
-
- pc hunter log.zip
- (160.48 KiB) Staženo 74 x
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
dneska avg objevilo jeste
- Přílohy
-
- avg3.png (13.27 KiB) Zobrazeno 3766 x
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
- Prejmenujte ComboFix na Uninstall a spustte jako spravce
- ComboFix se odinstaluje.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: nelze spustit aplikace + iexplore.exe - chyba aplikace
Nemate zac, rad jsem pomohl
Mejte se a treba zase nekdy
Mejte se a treba zase nekdy
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.


Přispějete na provoz fóra?