Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

malware typu ?trackid=sp-006

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
deRadek
Návštěvník
Návštěvník
Příspěvky: 1
Registrován: 01 bře 2015 21:40

malware typu ?trackid=sp-006

#1 Příspěvek od deRadek »

Ahoj,
Potřeboval bych prosím pomoct s odstraněním "malwaru". Už to tu několikrát bylo ale vždy když napíšu něco do vyhledávače (používám chrome) tak se mi za něj doplní ?trackid=sp-006.

Četl jsem si návod, stáhl FRST, RSIT a scanoval. Snad správně.
Tady je text z RSIT:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Radek at 2015-03-01 22:10:03
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 168 GB (82%) free of 205 GB
Total RAM: 3980 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:10:34, on 1.3.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Radek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~2\mcafee\msc\mcsniepl.dll
O23 - Service: McAfee Application Installer Cleanup (0220791425237179) (0220791425237179mcinstcleanup) - McAfee, Inc. - C:\windows\TEMP\022079~1.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\mcafee\msc\mcawfwk.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee OOBE Service (McOobeSv) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 12013 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
C:\windows\system32\WLANExt.exe 2530768
\??\C:\windows\system32\conhost.exe "1932542488472421352-11501512531688259300-12947980944127598461466221603-1358760832
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe" /McCoreSvc
"C:\Windows\system32\mfevtps.exe"
C:\windows\system32\viakaraokesrv.exe
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe"
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe"
WLIDSvcM.exe 1808
C:\windows\system32\svchost.exe -k bthsvcs
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\windows\system32\Dwm.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
taskeng.exe {0C8CD694-1C8C-48B5-8425-A2E45FCD741A}
C:\windows\Explorer.EXE
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
taskeng.exe {D8C43C8D-4812-486A-A449-C7CC04AC7DE1}
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
ATKOSD.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
C:\windows\system32\wbem\wmiprvse.exe
KBFiltr.exe
WDC.exe
"C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe" --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d
"C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe" --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"c:\PROGRA~1\mcafee.com\agent\mcagent.exe" -Embedding
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding

"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"taskhost.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5320.0.1617479404\1275018118" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,18,39 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2653 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Control/RememberCertificateErrorDecisions/Default/SPDY/Spdy4Enabled-default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_85/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="5320.30.1811389958\989267065" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/GoogleNow/Enable/MaterialDesignNTP/Enabled/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Control/RememberCertificateErrorDecisions/Default/SPDY/Spdy4Enabled-default/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_85/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Default/" --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="5320.41.473112034\1555801581" /prefetch:673131151
taskeng.exe {E0B1D299-B917-452C-A46F-EC8292CA7F15}

"C:\Users\Radek\Desktop\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\System32\svchost.exe -k WerSvcGroup

======Scheduled tasks folder======

C:\windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller winlogon-impersonate
C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe --domain-id 4e00205a-2ab1-4423-8f77-cc25b82cde1d --caller scheduler-impersonate

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-18 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-16 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-01-19 51872]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2012-02-22 170264]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2012-02-22 398616]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2012-01-19 1016992]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2012-01-19 800416]
"ACMON"=C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-05-08 90792]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2010-11-16 35736]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-16 932288]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2013-02-23 3187360]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [2012-12-19 3576784]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2012-06-22 1527896]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-02-07 291608]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-04-19 5142128]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-26 322208]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"CLMLServer"=C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2012-05-25 111120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2012-02-22 430080]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-03-02 05:05:13 ----D---- C:\Program Files (x86)\CyberLink
2015-03-02 05:05:10 ----D---- C:\ProgramData\Temp
2015-03-02 05:05:10 ----D---- C:\ProgramData\CyberLink
2015-03-02 05:04:52 ----A---- C:\windows\AsChkDev.txt
2015-03-02 05:04:25 ----D---- C:\ProgramData\USBChargerPlus
2015-03-02 04:53:03 ----A---- C:\windows\SYSWOW64\ACEngSvr.exe
2015-03-02 04:52:44 ----D---- C:\Program Files\ASUS
2015-03-02 04:52:43 ----D---- C:\ProgramData\P4G
2015-03-02 04:52:04 ----D---- C:\ProgramData\Atheros
2015-03-02 04:46:12 ----D---- C:\Program Files (x86)\Bluetooth Suite
2015-03-02 04:44:05 ----A---- C:\windows\system32\drivers\athrx.sys
2015-03-02 04:44:05 ----A---- C:\windows\system32\athrx.sys
2015-03-02 04:44:04 ----D---- C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation
2015-03-02 04:43:20 ----D---- C:\ProgramData\Qualcomm Atheros
2015-03-02 04:42:48 ----D---- C:\windows\SYSWOW64\Atheros_L1e
2015-03-02 04:40:20 ----N---- C:\windows\difxapi.dll
2015-03-02 04:40:20 ----D---- C:\Program Files (x86)\VIA
2015-03-02 04:38:58 ----D---- C:\ProgramData\AmUStor
2015-03-02 04:38:58 ----D---- C:\Program Files (x86)\AmIcoSingLun
2015-03-02 04:37:09 ----D---- C:\Program Files\DIFX
2015-03-02 04:36:46 ----A---- C:\windows\system32\drivers\USB3Ver.dll
2015-03-02 04:36:27 ----A---- C:\windows\system32\drivers\IntelMEFWVer.dll
2015-03-02 04:36:23 ----A---- C:\windows\SYSWOW64\log.txt
2015-03-02 04:36:22 ----D---- C:\ProgramData\Intel
2015-03-02 04:36:19 ----D---- C:\Program Files\Intel
2015-03-02 04:35:55 ----A---- C:\windows\system32\drivers\HECIx64.sys
2015-03-02 04:35:53 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-03-02 04:33:04 ----A---- C:\windows\system32\OpenCL.dll
2015-03-02 04:33:04 ----A---- C:\windows\system32\IntelOpenCL64.dll
2015-03-02 04:33:02 ----A---- C:\windows\SYSWOW64\OpenCL.dll
2015-03-02 04:33:02 ----A---- C:\windows\SYSWOW64\IntelOpenCL32.dll
2015-03-02 04:32:57 ----D---- C:\Program Files\Common Files\Intel
2015-03-02 04:30:52 ----D---- C:\Program Files (x86)\Intel
2015-03-02 04:30:52 ----A---- C:\windows\SYSWOW64\CSVer.dll
2015-03-02 04:30:41 ----HD---- C:\Intel
2015-03-02 04:28:41 ----A---- C:\windows\SYSWOW64\ifsutil.dll
2015-03-02 04:28:41 ----A---- C:\windows\system32\ifsutil.dll
2015-03-02 04:26:44 ----D---- C:\windows\SoftwareDistribution
2015-03-02 04:21:47 ----SHD---- C:\System Volume Information
2015-03-02 04:21:47 ----ASH---- C:\pagefile.sys
2015-03-02 04:21:47 ----ASH---- C:\hiberfil.sys
2015-03-02 04:21:16 ----A---- C:\windows\AsToolCDVer.txt
2015-03-02 04:21:16 ----A---- C:\windows\AsRunBar.txt
2015-03-02 04:20:56 ----D---- C:\eSupport
2015-03-01 22:10:03 ----D---- C:\rsit
2015-03-01 22:10:03 ----D---- C:\Program Files\trend micro
2015-03-01 21:45:00 ----D---- C:\FRST
2015-03-01 21:00:59 ----D---- C:\Program Files (x86)\Google
2015-03-01 21:00:32 ----A---- C:\windows\system32\wups2.dll
2015-03-01 21:00:32 ----A---- C:\windows\system32\wucltux.dll
2015-03-01 21:00:32 ----A---- C:\windows\system32\wuaueng.dll
2015-03-01 21:00:32 ----A---- C:\windows\system32\wuauclt.exe
2015-03-01 21:00:02 ----A---- C:\windows\SYSWOW64\wuwebv.dll
2015-03-01 21:00:02 ----A---- C:\windows\SYSWOW64\wuapp.exe
2015-03-01 21:00:02 ----A---- C:\windows\system32\wuwebv.dll
2015-03-01 21:00:02 ----A---- C:\windows\system32\wuapp.exe
2015-03-01 20:59:56 ----D---- C:\Users\Radek\AppData\Roaming\Macromedia
2015-03-01 20:59:56 ----D---- C:\Users\Radek\AppData\Roaming\Adobe
2015-03-01 20:17:13 ----D---- C:\Users\Radek\AppData\Roaming\ASUS WebStorage
2015-03-01 20:16:54 ----D---- C:\Users\Radek\AppData\Roaming\Atheros
2015-03-01 20:16:54 ----A---- C:\Users\Radek\AppData\Roaming\sp_data.sys
2015-03-01 20:13:29 ----D---- C:\Users\Radek\AppData\Roaming\Identities
2015-03-01 20:12:49 ----D---- C:\ProgramData\FolderView
2015-03-01 20:12:21 ----SD---- C:\Users\Radek\AppData\Roaming\Microsoft
2015-03-01 20:12:21 ----D---- C:\Users\Radek\AppData\Roaming\Media Center Programs

======List of files/folders modified in the last 1 month======

2015-03-02 05:07:13 ----D---- C:\windows\system32\sysprep
2015-03-02 05:07:13 ----D---- C:\windows\Panther
2015-03-02 05:04:53 ----D---- C:\windows\SYSWOW64\drivers
2015-03-02 05:04:45 ----D---- C:\windows\Logs
2015-03-02 04:53:48 ----D---- C:\Program Files (x86)\Common Files
2015-03-02 04:53:48 ----D---- C:\Program Files (x86)\ASUS
2015-03-02 04:53:31 ----D---- C:\windows\system32\drivers
2015-03-02 04:49:38 ----D---- C:\windows\system32\DriverStore
2015-03-02 04:36:15 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-03-02 04:32:57 ----D---- C:\Program Files\Common Files
2015-03-02 04:21:00 ----D---- C:\windows\ASUS
2015-03-01 22:10:18 ----D---- C:\windows\Temp
2015-03-01 22:10:03 ----RD---- C:\Program Files
2015-03-01 21:47:08 ----D---- C:\Windows
2015-03-01 21:22:39 ----D---- C:\windows\system32\config
2015-03-01 21:06:40 ----D---- C:\windows\Prefetch
2015-03-01 21:06:04 ----SHD---- C:\windows\Installer
2015-03-01 21:01:52 ----RD---- C:\Program Files (x86)
2015-03-01 21:01:39 ----D---- C:\windows\System32
2015-03-01 21:01:30 ----D---- C:\windows\SysWOW64
2015-03-01 21:01:28 ----D---- C:\windows\winsxs
2015-03-01 21:01:19 ----D---- C:\windows\system32\sr-Latn-CS
2015-03-01 21:01:19 ----D---- C:\windows\system32\ro-RO
2015-03-01 21:01:19 ----D---- C:\windows\system32\lv-LV
2015-03-01 21:01:19 ----D---- C:\windows\system32\lt-LT
2015-03-01 21:01:18 ----D---- C:\windows\system32\sk-SK
2015-03-01 21:01:18 ----D---- C:\windows\system32\cs-CZ
2015-03-01 21:01:17 ----D---- C:\windows\system32\sl-SI
2015-03-01 21:01:17 ----D---- C:\windows\system32\pl-PL
2015-03-01 21:01:17 ----D---- C:\windows\system32\hr-HR
2015-03-01 21:01:17 ----D---- C:\windows\system32\et-EE
2015-03-01 21:01:17 ----D---- C:\windows\system32\en-US
2015-03-01 21:01:17 ----D---- C:\windows\system32\bg-BG
2015-03-01 21:01:16 ----D---- C:\windows\system32\hu-HU
2015-03-01 21:01:07 ----D---- C:\windows\Tasks
2015-03-01 21:01:07 ----D---- C:\windows\system32\Tasks
2015-03-01 21:00:57 ----D---- C:\windows\system32\catroot
2015-03-01 21:00:55 ----D---- C:\windows\system32\catroot2
2015-03-01 20:59:07 ----D---- C:\windows\system32\restore
2015-03-01 20:58:42 ----D---- C:\windows\system32\LogFiles
2015-03-01 20:58:35 ----SD---- C:\ProgramData\Microsoft
2015-03-01 20:46:06 ----D---- C:\windows\Microsoft.NET
2015-03-01 20:46:00 ----RSD---- C:\windows\assembly
2015-03-01 20:17:34 ----D---- C:\windows\inf
2015-03-01 20:17:34 ----A---- C:\windows\system32\PerfStringBackup.INI
2015-03-01 20:15:55 ----D---- C:\ProgramData\ChangeFolderView
2015-03-01 20:13:44 ----D---- C:\ProgramData\McAfee
2015-03-01 20:13:24 ----SHD---- C:\$Recycle.Bin
2015-03-01 20:13:07 ----D---- C:\windows\Log
2015-03-01 20:12:49 ----HD---- C:\ProgramData
2015-03-01 20:12:21 ----RD---- C:\Users
2015-03-01 20:10:10 ----SHD---- C:\Recovery
2015-03-01 20:10:00 ----D---- C:\windows\rescache

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-12-23 568600]
R0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver; C:\windows\system32\DRIVERS\iusb3hcs.sys [2012-02-07 16152]
R0 mfehidk;McAfee Inc. mfehidk; C:\windows\system32\drivers\mfehidk.sys [2012-06-22 752672]
R0 mfewfpk;McAfee Inc. mfewfpk; C:\windows\system32\drivers\mfewfpk.sys [2012-06-22 335784]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R3 AiCharger;ASUS Charger Driver; C:\windows\system32\DRIVERS\AiCharger.sys [2012-05-08 17152]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\windows\system32\DRIVERS\btath_flt.sys [2012-01-19 36000]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2012-01-11 2801664]
R3 ATP;ASUS Input Device; C:\windows\system32\DRIVERS\AsusTP.sys [2013-01-16 65784]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\windows\system32\drivers\btath_a2dp.sys [2012-01-19 339616]
R3 btath_avdt;Atheros Bluetooth AVDT Service; C:\windows\system32\drivers\btath_avdt.sys [2012-01-19 110752]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\windows\system32\DRIVERS\btath_bus.sys [2012-01-19 30368]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\windows\system32\DRIVERS\btath_hcrp.sys [2012-01-19 167584]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\windows\system32\DRIVERS\btath_lwflt.sys [2012-01-19 68256]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\windows\system32\DRIVERS\btath_rcp.sys [2012-01-19 280992]
R3 BtFilter;BtFilter; C:\windows\system32\DRIVERS\btfilter.sys [2012-01-19 550560]
R3 BthEnum;Bluetooth Enumerator Service; C:\windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\windows\System32\Drivers\BTHUSB.sys [2013-02-23 80384]
R3 cfwids;McAfee Inc. cfwids; C:\windows\system32\drivers\cfwids.sys [2012-06-22 69672]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2012-02-22 14692224]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2012-02-20 331264]
R3 iusb3hub;Intel(R) USB 3.0 Hub Driver; C:\windows\system32\DRIVERS\iusb3hub.sys [2012-02-07 356120]
R3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver; C:\windows\system32\DRIVERS\iusb3xhc.sys [2012-02-07 787736]
R3 kbfiltr;Keyboard Filter; C:\windows\system32\DRIVERS\kbfiltr.sys [2012-08-05 17280]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2012-04-25 104560]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\windows\system32\DRIVERS\HECIx64.sys [2012-07-03 62784]
R3 mfeapfk;McAfee Inc. mfeapfk; C:\windows\system32\drivers\mfeapfk.sys [2012-06-22 169320]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\windows\system32\drivers\mfeavfk.sys [2012-06-22 300392]
R3 mfefirek;McAfee Inc. mfefirek; C:\windows\system32\drivers\mfefirek.sys [2012-06-22 513456]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\windows\system32\drivers\viahduaa.sys [2012-03-23 2193008]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BTHPORT;Bluetooth Port Driver; C:\windows\System32\Drivers\BTHport.sys [2013-02-23 552960]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2012-09-13 57856]
S3 HipShieldK;McAfee Inc. HipShieldK; C:\windows\system32\drivers\HipShieldK.sys [2012-04-21 196440]
S3 mfeavfk01;McAfee Inc.; C:\windows\system32\drivers\mfeavfk01.sys []
S3 mferkdet;McAfee Inc. mferkdet; C:\windows\system32\drivers\mferkdet.sys [2012-06-22 106112]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 WinUsb;WinUSB Driver; C:\windows\system32\DRIVERS\WinUSB.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-04-13 277120]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2012-01-19 106144]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 mcmscsvc;McAfee Services; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 McNASvc;McAfee Network Agent; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 McOobeSv;McAfee OOBE Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 McShield;McAfee McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [2012-06-22 237920]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-06-22 218320]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\Windows\system32\mfevtps.exe [2012-06-22 177144]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-05-11 200728]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\windows\system32\viakaraokesrv.exe [2012-03-23 27760]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-18 2292480]
R2 ZAtheros Bt&Wlan Coex Agent;ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2012-01-19 158880]
S2 0220791425237179mcinstcleanup;McAfee Application Installer Cleanup (0220791425237179); C:\windows\TEMP\022079~1.EXE [2012-09-04 828032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-01 107848]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-23 253600]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 cphs;Intel(R) Content Protection HECI Service; C:\windows\SysWow64\IntelCpHeciSvc.exe [2012-02-22 276248]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-09-13 1512448]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-01 107848]
S3 McAWFwk;McAfee Activation Service; c:\PROGRA~1\mcafee\msc\mcawfwk.exe [2012-01-26 332080]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2012-05-22 383608]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------






















Tady je text z FRST:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-02-2015
Ran by Radek (administrator) on RADEK-PC on 01-03-2015 21:45:48
Running from C:\Users\Radek\Desktop
Loaded Profiles: Radek (Available profiles: Radek)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe
() C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1016992 2012-01-19] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800416 2012-01-19] (Atheros Commnucations)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [90792 2012-05-08] (ASUS)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-16] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-02-23] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1527896 2012-06-22] (McAfee, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-07] (Intel Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5142128 2012-04-19] (VIA)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [111120 2012-05-25] (CyberLink)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1692147083-820335443-128930799-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
HKU\S-1-5-21-1692147083-820335443-128930799-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
SearchScopes: HKU\S-1-5-21-1692147083-820335443-128930799-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.2.254 10.0.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-02-23]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> google
CHR DefaultSearchURL: Default -> https://www.google.de/search?q={searchT ... kid=sp-006
CHR DefaultSuggestURL: Default -> https://www.google.com/complete/search? ... earchTerms}
CHR Profile: C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-01]
CHR Extension: (Google Docs) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-01]
CHR Extension: (Google Drive) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-01]
CHR Extension: (YouTube) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-01]
CHR Extension: (Google Search) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-01]
CHR Extension: (Google Sheets) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-01]
CHR Extension: (Flow Game ) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhkenkiidlghkpkihaiojpjnngfocahn [2015-03-01]
CHR Extension: (Gmail) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-01]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 0220791425237179mcinstcleanup; C:\windows\TEMP\022079~1.EXE [828032 2012-09-04] (McAfee, Inc.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-01-19] (Atheros Commnucations) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [332080 2012-01-26] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [383608 2012-05-22] (McAfee, Inc.)
R2 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [237920 2012-06-22] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218320 2012-06-22] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [177144 2012-06-22] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-03-23] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-01-19] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ATP; C:\Windows\System32\DRIVERS\AsusTP.sys [65784 2013-01-16] (ASUS Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [69672 2012-06-22] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-21] (McAfee, Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [17280 2012-08-05] ( )
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [104560 2012-04-25] (Qualcomm Atheros Co., Ltd.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [169320 2012-06-22] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [300392 2012-06-22] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [513456 2012-06-22] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [752672 2012-06-22] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106112 2012-06-22] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [335784 2012-06-22] (McAfee, Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-02 05:06 - 2015-03-02 05:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite
2015-03-02 05:05 - 2015-03-02 05:06 - 00000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2015-03-02 05:05 - 2015-03-02 05:06 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2015-03-02 05:05 - 2015-03-02 05:05 - 00000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2015-03-02 05:05 - 2015-03-02 05:05 - 00000000 ____D () C:\ProgramData\Temp
2015-03-02 05:05 - 2015-03-02 05:05 - 00000000 ____D () C:\ProgramData\CyberLink
2015-03-02 05:04 - 2015-03-02 05:04 - 00060446 _____ () C:\windows\AsChkDev.txt
2015-03-02 05:04 - 2015-03-02 05:04 - 00000000 ____D () C:\ProgramData\USBChargerPlus
2015-03-02 05:04 - 2015-03-02 05:04 - 00000000 _____ () C:\windows\SysWOW64\Drivers\1043_ASUSTEK_X75A_X75VD_X75A1_X75VD1_V80_WIN7.MRK
2015-03-02 04:53 - 2015-03-02 04:53 - 00003112 _____ () C:\windows\System32\Tasks\ASUS Live Update
2015-03-02 04:53 - 2015-03-02 04:53 - 00003110 _____ () C:\windows\System32\Tasks\ASUS Wireless Console 3
2015-03-02 04:53 - 2015-03-02 04:53 - 00003026 _____ () C:\windows\System32\Tasks\ASUS USB Charger Plus
2015-03-02 04:53 - 2015-03-02 04:53 - 00002984 _____ () C:\windows\System32\Tasks\ASUS SmartLogon Console Sensor
2015-03-02 04:53 - 2012-05-08 01:48 - 00162456 _____ (ASUSTeK) C:\windows\SysWOW64\ACEngSvr.exe
2015-03-02 04:52 - 2015-03-02 04:53 - 00003230 _____ () C:\windows\System32\Tasks\SidebarExecute
2015-03-02 04:52 - 2015-03-02 04:52 - 00003054 _____ () C:\windows\System32\Tasks\ASUS P4G
2015-03-02 04:52 - 2015-03-02 04:52 - 00000000 ____D () C:\ProgramData\P4G
2015-03-02 04:52 - 2015-03-02 04:52 - 00000000 ____D () C:\Program Files\ASUS
2015-03-02 04:52 - 2015-03-01 20:17 - 00000000 ____D () C:\ProgramData\Atheros
2015-03-02 04:49 - 2015-03-02 04:49 - 00002984 _____ () C:\windows\System32\Tasks\ATKOSD2
2015-03-02 04:48 - 2015-03-02 04:48 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_btath_hcrp_01009.Wdf
2015-03-02 04:46 - 2015-03-02 04:46 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BT Program
2015-03-02 04:46 - 2015-03-02 04:46 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
2015-03-02 04:44 - 2015-03-02 04:44 - 00000000 ____D () C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation
2015-03-02 04:44 - 2012-01-15 17:37 - 00072526 _____ () C:\windows\system32\athrextx.cat
2015-03-02 04:44 - 2012-01-11 06:38 - 02801664 _____ (Atheros Communications, Inc.) C:\windows\system32\Drivers\athrx.sys
2015-03-02 04:44 - 2012-01-11 06:38 - 02801664 _____ (Atheros Communications, Inc.) C:\windows\system32\athrx.sys
2015-03-02 04:43 - 2015-03-02 04:43 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2015-03-02 04:42 - 2015-03-02 04:42 - 00000000 ____D () C:\windows\SysWOW64\Atheros_L1e
2015-03-02 04:40 - 2015-03-02 04:40 - 00001212 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
2015-03-02 04:40 - 2015-03-02 04:40 - 00000000 ____D () C:\Program Files (x86)\VIA
2015-03-02 04:40 - 2007-04-11 08:35 - 00414632 ____N (Microsoft Corporation) C:\windows\difxapi.dll
2015-03-02 04:38 - 2015-03-02 04:38 - 00000000 ____D () C:\ProgramData\AmUStor
2015-03-02 04:38 - 2015-03-02 04:38 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-03-02 04:37 - 2015-03-02 04:37 - 00004906 _____ () C:\windows\DPINST.LOG
2015-03-02 04:37 - 2015-03-02 04:37 - 00003540 _____ () C:\windows\System32\Tasks\ASUS Touchpad Launcher (x64)
2015-03-02 04:37 - 2015-03-02 04:37 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf
2015-03-02 04:37 - 2015-03-02 04:37 - 00000000 ____D () C:\Program Files\DIFX
2015-03-02 04:37 - 2015-03-02 04:37 - 00000000 _____ () C:\windows\SysWOW64\agent.log
2015-03-02 04:36 - 2015-03-02 04:38 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-03-02 04:36 - 2015-03-02 04:36 - 00003492 _____ () C:\windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d
2015-03-02 04:36 - 2015-03-02 04:36 - 00003188 _____ () C:\windows\System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon
2015-03-02 04:36 - 2015-03-02 04:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-03-02 04:36 - 2015-03-02 04:36 - 00000000 ____D () C:\ProgramData\Intel
2015-03-02 04:36 - 2015-03-02 04:36 - 00000000 ____D () C:\Program Files\Intel
2015-03-02 04:36 - 2015-03-01 20:12 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-03-02 04:36 - 2012-06-25 19:42 - 00015168 _____ (Intel Corporation) C:\windows\system32\Drivers\IntelMEFWVer.dll
2015-03-02 04:36 - 2012-02-07 05:12 - 00041984 _____ (Intel Corporation) C:\windows\system32\Drivers\USB3Ver.dll
2015-03-02 04:35 - 2015-03-02 05:06 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-03-02 04:35 - 2012-07-03 00:16 - 00062784 _____ (Intel Corporation) C:\windows\system32\Drivers\HECIx64.sys
2015-03-02 04:34 - 2015-03-02 04:34 - 00015390 _____ () C:\windows\system32\results.xml
2015-03-02 04:33 - 2011-12-26 13:07 - 00086016 _____ (Intel Corporation) C:\windows\SysWOW64\IntelOpenCL32.dll
2015-03-02 04:33 - 2011-12-26 13:06 - 00017920 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2015-03-02 04:33 - 2011-12-26 13:02 - 00120832 _____ (Intel Corporation) C:\windows\system32\IntelOpenCL64.dll
2015-03-02 04:33 - 2011-12-26 13:02 - 00020992 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2015-03-02 04:32 - 2015-03-02 04:32 - 00000000 ____D () C:\Program Files\Common Files\Intel
2015-03-02 04:30 - 2015-03-02 04:36 - 00000000 ____D () C:\Program Files (x86)\Intel
2015-03-02 04:30 - 2015-03-02 04:32 - 00000000 ___HD () C:\Intel
2015-03-02 04:30 - 2012-02-02 05:58 - 00053248 _____ (Windows XP Bundled build C-Centric Single User) C:\windows\SysWOW64\CSVer.dll
2015-03-02 04:28 - 2011-01-28 20:03 - 00180736 _____ (Microsoft Corporation) C:\windows\system32\ifsutil.dll
2015-03-02 04:28 - 2011-01-28 06:46 - 00148992 _____ (Microsoft Corporation) C:\windows\SysWOW64\ifsutil.dll
2015-03-02 04:26 - 2015-03-01 21:01 - 00303510 _____ () C:\windows\WindowsUpdate.log
2015-03-02 04:21 - 2015-03-02 04:21 - 00000000 _____ () C:\windows\AsRunBar.txt
2015-03-02 04:21 - 2012-08-13 05:47 - 00000031 _____ () C:\windows\AsToolCDVer.txt
2015-03-02 04:20 - 2015-03-02 04:53 - 00000000 ____D () C:\eSupport
2015-03-01 21:45 - 2015-03-01 21:45 - 00017249 _____ () C:\Users\Radek\Desktop\FRST.txt
2015-03-01 21:45 - 2015-03-01 21:45 - 00000000 ____D () C:\FRST
2015-03-01 21:43 - 2015-03-01 21:44 - 02092544 _____ (Farbar) C:\Users\Radek\Desktop\FRST64.exe
2015-03-01 21:04 - 2015-03-01 21:04 - 00000000 ____D () C:\Users\Radek\Desktop\Radek
2015-03-01 21:01 - 2015-03-01 21:06 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-01 21:01 - 2015-03-01 21:06 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-01 21:01 - 2015-03-01 21:01 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-01 21:01 - 2015-03-01 21:01 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-01 21:01 - 2015-03-01 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-01 21:00 - 2015-03-01 21:01 - 00000000 ____D () C:\Users\Radek\AppData\Local\Google
2015-03-01 21:00 - 2015-03-01 21:01 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-01 21:00 - 2015-03-01 21:00 - 00000000 ____D () C:\Users\Radek\AppData\Local\Deployment
2015-03-01 21:00 - 2015-03-01 21:00 - 00000000 ____D () C:\Users\Radek\AppData\Local\Apps\2.0
2015-03-01 21:00 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-03-01 21:00 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-03-01 21:00 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-03-01 21:00 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-03-01 21:00 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-03-01 21:00 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-03-01 21:00 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-03-01 21:00 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-03-01 20:59 - 2015-03-01 20:59 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\Macromedia
2015-03-01 20:59 - 2015-03-01 20:59 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\Adobe
2015-03-01 20:22 - 2015-03-01 20:22 - 00000000 _____ () C:\Users\Radek\agent.log
2015-03-01 20:17 - 2015-03-01 20:17 - 00000000 ___RD () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-03-01 20:17 - 2015-03-01 20:17 - 00000000 ____D () C:\Users\Radek\Documents\Bluetooth Folder
2015-03-01 20:17 - 2015-03-01 20:17 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\ASUS WebStorage
2015-03-01 20:17 - 2015-03-01 20:17 - 00000000 ____D () C:\Users\Radek\AppData\Local\Power2Go
2015-03-01 20:17 - 2015-03-01 20:17 - 00000000 ____D () C:\Users\Radek\AppData\Local\BMExplorer
2015-03-01 20:17 - 2015-03-01 20:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-03-01 20:16 - 2015-03-01 20:16 - 00000352 _____ () C:\Users\Radek\AppData\Roaming\sp_data.sys
2015-03-01 20:16 - 2015-03-01 20:16 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\Atheros
2015-03-01 20:15 - 2015-03-01 20:15 - 00001391 _____ () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-03-01 20:13 - 2015-03-01 20:13 - 00001425 _____ () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-01 20:13 - 2015-03-01 20:13 - 00000000 ____D () C:\Users\Radek\AppData\Local\VirtualStore
2015-03-01 20:12 - 2015-03-01 20:22 - 00000000 ____D () C:\Users\Radek
2015-03-01 20:12 - 2015-03-01 20:12 - 00058016 _____ () C:\Users\Radek\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-01 20:12 - 2015-03-01 20:12 - 00000192 _____ () C:\windows\FixPatch.log
2015-03-01 20:12 - 2015-03-01 20:12 - 00000020 ___SH () C:\Users\Radek\ntuser.ini
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Šablony
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Soubory cookie
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Poslední
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Okolní tiskárny
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Okolní síť
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Nabídka Start
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Dokumenty
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Documents\Obrázky
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Documents\Hudba
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Documents\Filmy
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\Data aplikací
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 _SHDL () C:\Users\Radek\AppData\Local\Data aplikací
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 ____D () C:\Users\Radek\AppData\Local\ASUS
2015-03-01 20:12 - 2015-03-01 20:12 - 00000000 ____D () C:\ProgramData\FolderView
2015-03-01 20:12 - 2013-02-23 08:38 - 00002098 _____ () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SkyDrive.lnk
2015-03-01 20:12 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-01 20:12 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-02 05:07 - 2009-07-29 07:03 - 00000000 ____D () C:\windows\Panther
2015-03-02 05:07 - 2009-07-14 05:46 - 00005075 _____ () C:\windows\DtcInstall.log
2015-03-02 05:07 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\sysprep
2015-03-02 04:53 - 2013-02-23 08:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-03-02 04:53 - 2013-02-23 08:45 - 00000000 ____D () C:\Program Files (x86)\ASUS
2015-03-02 04:47 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-02 04:46 - 2012-01-19 21:08 - 00246804 _____ () C:\windows\system32\Drivers\AtherosBt.bin
2015-03-02 04:46 - 2012-01-19 21:08 - 00001796 _____ () C:\windows\system32\Drivers\ramps_0x11020000_40.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001242 _____ () C:\windows\system32\Drivers\ramps_0x01020200_40_0x01.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001228 _____ () C:\windows\system32\Drivers\ramps_0x01020200_40_0x04.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001214 _____ () C:\windows\system32\Drivers\ramps_0x01020200_40_0x03.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001204 _____ () C:\windows\system32\Drivers\ramps_0x01020200_40_0x02.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001204 _____ () C:\windows\system32\Drivers\ramps_0x01020200_40.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001198 _____ () C:\windows\system32\Drivers\ramps_0x01020200_26.dfu
2015-03-02 04:46 - 2012-01-19 21:08 - 00001192 _____ () C:\windows\system32\Drivers\ramps_0x01020200_26_0x01.dfu
2015-03-02 04:36 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-03-02 04:23 - 2009-07-29 06:07 - 00008134 _____ () C:\windows\TSSysprep.log
2015-03-02 04:21 - 2013-02-23 07:49 - 00160326 _____ () C:\windows\AsFac.log
2015-03-02 04:21 - 2013-02-23 07:49 - 00007970 _____ () C:\windows\AsRecoveryHD.log
2015-03-02 04:21 - 2009-07-29 06:20 - 00000000 ____D () C:\windows\ASUS
2015-03-02 04:21 - 2009-07-14 06:38 - 00025600 ___SH () C:\windows\system32\config\BCD-Template.LOG
2015-03-02 04:21 - 2009-07-14 06:32 - 00028672 _____ () C:\windows\system32\config\BCD-Template
2015-03-01 21:36 - 2013-02-23 08:37 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2015-03-01 21:36 - 2013-02-23 08:37 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-01 21:08 - 2009-07-14 05:45 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-01 21:08 - 2009-07-14 05:45 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\sr-Latn-CS
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\sl-SI
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\sk-SK
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\ro-RO
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\lv-LV
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\lt-LT
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\hr-HR
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\et-EE
2015-03-01 21:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\bg-BG
2015-03-01 20:59 - 2009-07-14 06:32 - 00000000 ____D () C:\windows\system32\restore
2015-03-01 20:17 - 2011-02-19 06:40 - 00672778 _____ () C:\windows\system32\perfh00E.dat
2015-03-01 20:17 - 2011-02-19 06:40 - 00169370 _____ () C:\windows\system32\perfc00E.dat
2015-03-01 20:17 - 2011-02-19 06:36 - 00665944 _____ () C:\windows\system32\perfh005.dat
2015-03-01 20:17 - 2011-02-19 06:36 - 00139608 _____ () C:\windows\system32\perfc005.dat
2015-03-01 20:17 - 2011-02-19 06:31 - 00729294 _____ () C:\windows\system32\perfh015.dat
2015-03-01 20:17 - 2011-02-19 06:31 - 00153986 _____ () C:\windows\system32\perfc015.dat
2015-03-01 20:17 - 2009-07-14 06:13 - 03300262 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-01 20:15 - 2013-02-23 08:45 - 00000000 ____D () C:\ProgramData\ChangeFolderView
2015-03-01 20:13 - 2013-02-23 08:45 - 00000000 ____D () C:\ProgramData\McAfee
2015-03-01 20:13 - 2013-02-23 08:37 - 04765124 _____ () C:\windows\AsDebug.log
2015-03-01 20:13 - 2011-02-18 21:12 - 00466286 _____ () C:\windows\AsCDProc.log
2015-03-01 20:13 - 2009-07-29 06:20 - 00000000 ____D () C:\windows\Log
2015-03-01 20:12 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-01 20:11 - 2009-07-14 05:51 - 00048515 _____ () C:\windows\setupact.log
2015-03-01 20:11 - 2009-07-14 05:45 - 00276128 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-01 20:10 - 2009-07-29 06:10 - 00000000 __SHD () C:\Recovery
2015-03-01 20:10 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache

==================== Files in the root of some directories =======

2015-03-01 20:16 - 2015-03-01 20:16 - 0000352 _____ () C:\Users\Radek\AppData\Roaming\sp_data.sys
2013-02-23 08:37 - 2012-09-07 12:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2013-02-23 08:37 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2013-02-23 08:37 - 2012-09-07 12:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
2009-07-29 06:21 - 2009-07-28 19:31 - 0000223 _____ () C:\ProgramData\setwallpaper.cmd
2009-07-29 06:21 - 2009-07-23 02:04 - 0024576 _____ () C:\ProgramData\SetWallpaper.exe
2015-03-02 05:05 - 2015-03-02 05:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2015-03-02 05:05 - 2015-03-02 05:05 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
C:\ProgramData\SetWallpaper.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2009-07-29 06:04

==================== End Of Log ============================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15798
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: malware typu ?trackid=sp-006

#2 Příspěvek od JaRon »

ahoj,
1. pouzi navod kolegu - zoek - http://forum.viry.cz/viewtopic.php?f=13 ... k#p1382782
2. nainstaluj MSIE10 a vsetky dostupne aktualizacie
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět