Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

SearchProtect

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

SearchProtect

#1 Příspěvek od Ivošisko »

A už jsem tu zase. Stahoval jsem ze stránek CHIPu diagnostický sw "SensorsView Pro" a najednou se mi tam začala cpát nějaká hra. Nic moc s tím nešlo dělat, ale naštěstí (snad) se to nezdařilo nainstalovat. Ovšem od tohoto incidentu se mi chvíli po re/startu objeví v SYStray ikonka podobná IE - na pravou myš nereaguje, při poklepání levou se otevře okno - viz obrázek:

Obrázek



RSIT log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by uzivatel at 2015-07-19 15:20:18
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 14 GB (12%) free of 114 GB
Total RAM: 3007 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:20:26, on 19.7.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Documents and Settings\All Users\Data aplikací\WindowsMangerProtect\ProtectWindowsManager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eM Client\MailClient.exe
C:\Program Files\MiuiTab\ProtectService.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\MiuiTab\cmdshell.exe
C:\Program Files\SensorsViewPro41\svservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SensorsViewPro41\sviewpro.exe
C:\Program Files\MiuiTab\HPNotify.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\uzivatel\Plocha\RSIT.exe
C:\Program Files\trend micro\uzivatel.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... m=cvs&uid=_
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... m=cvs&uid=_
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... m=cvs&uid=_
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mystartsearch.com/?type=hp&t ... m=cvs&uid=_
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: LuckyTab Class - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} - C:\Program Files\MiuiTab\SupTab.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SensorsView] C:\Program Files\SensorsViewPro41\sviewpro.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - Startup: E-mail.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IHProtect Service - XTab system - C:\Program Files\MiuiTab\ProtectService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SensorsVService - Unknown owner - C:\Program Files\SensorsViewPro41\svservice.exe
O23 - Service: WindowsMangerProtect Service (WindowsMangerProtect) - DTools LIMITED - C:\Documents and Settings\All Users\Data aplikací\WindowsMangerProtect\ProtectWindowsManager.exe

--
End of file - 8458 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\User_Feed_Synchronization-{79D0B19C-05FC-4F37-8300-D83CFD8BCC1A}.job - C:\WINDOWS\system32\msfeedssync.exe sync

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
LuckyTab Class - C:\Program Files\MiuiTab\SupTab.dll [2015-06-24 544952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2015-07-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-08 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-07-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\WINDOWS\JM\JMInsIDE.exe [2006-10-30 36864]
"JMB36X Configure"=C:\WINDOWS\system32\JMRaidSetup.exe [2006-10-30 1953792]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-07-08 5515496]
"NUSB3MON"=C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2011-09-16 115048]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"uTorrent"=C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe [2015-02-22 416168]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SensorsView"=C:\Program Files\SensorsViewPro41\sviewpro.exe [2011-04-05 2267648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2012-09-23 40592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2012-09-23 689304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []

C:\Documents and Settings\uzivatel\Nabídka Start\Programy\Po spuštění
E-mail.lnk -

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=255
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\InterVideo\DVD6\WinDVD.exe"="C:\Program Files\InterVideo\DVD6\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\WINDOWS\system32\winver.exe"="C:\WINDOWS\system32\winver.exe:*:Enabled:winver"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Sprite Software\Sprite Backup\spriteservice.exe"="C:\Program Files\Sprite Software\Sprite Backup\spriteservice.exe:*:Enabled:Sprite PC Service"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi"
"C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe"="C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=vp6vfw.dll
"vidc.VP61"=vp6vfw.dll
"vidc.xvid"=xvidvfw.dll
"vidc.ffds"=ff_vfw.dll
"vidc.vp62"=vp6vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.divxa32"=DivXa32.acm
"msacm.lameacm"=LameACM.acm
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2015-07-19 15:20:18 ----D---- C:\rsit
2015-07-19 15:20:18 ----D---- C:\Program Files\trend micro
2015-07-19 14:19:37 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\STV Software
2015-07-19 14:19:31 ----D---- C:\Program Files\SensorsViewPro41
2015-07-19 14:16:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\IHProtectUpDate
2015-07-19 14:16:31 ----D---- C:\Program Files\MiuiTab
2015-07-19 14:16:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\WindowsMangerProtect
2015-07-19 14:16:12 ----A---- C:\WINDOWS\prleth.sys
2015-07-19 14:16:12 ----A---- C:\WINDOWS\hgfs.sys
2015-07-18 20:29:28 ----D---- C:\Program Files\SpeedFan
2015-07-16 11:36:07 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Wondershare
2015-07-16 11:31:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\wondershare
2015-07-16 10:36:17 ----A---- C:\WINDOWS\system32\ZSHP1020.EXE
2015-07-16 10:36:17 ----A---- C:\WINDOWS\system32\ZLhp1020.DLL
2015-07-16 10:30:33 ----A---- C:\WINDOWS\system32\zshp1020s.dll
2015-07-16 10:30:26 ----D---- C:\Program Files\HP
2015-07-16 10:30:26 ----A---- C:\WINDOWS\system32\Difxapi.dll
2015-07-16 10:29:57 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\HP
2015-07-16 10:29:18 ----D---- C:\hp_lj1020_Full_Solution
2015-07-12 20:16:49 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Avant Downloader
2015-07-11 23:19:47 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\eM Client
2015-07-11 23:18:48 ----D---- C:\Program Files\eM Client
2015-07-11 23:04:28 ----A---- C:\WINDOWS\system32\drivers\nusb3xhc.sys
2015-07-11 23:04:27 ----A---- C:\WINDOWS\system32\nusb3co3.dll
2015-07-11 23:04:27 ----A---- C:\WINDOWS\system32\drivers\nusb3hub.sys
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\2C0A
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0C0A
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0C04
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0816
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0804
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0424
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041F
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041E
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041D
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041B
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0419
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0416
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0415
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0414
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0413
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0412
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0411
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0410
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040E
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040D
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040C
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040B
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040A
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0409
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0408
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0407
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0406
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0405
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0404
2015-07-11 23:04:20 ----D---- C:\Program Files\Renesas Electronics
2015-07-11 23:03:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
2015-07-11 19:28:07 ----D---- C:\Program Files\Defraggler
2015-07-11 17:03:15 ----D---- C:\Program Files\Unlocker
2015-07-10 19:25:46 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Google Chrome Backup
2015-07-10 07:30:58 ----D---- C:\Program Files\FastStone Image Viewer
2015-07-09 18:08:02 ----D---- C:\Program Files\Subtitle Edit
2015-07-09 18:08:02 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Subtitle Edit
2015-07-09 13:16:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Caphyon
2015-07-09 10:40:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2015-07-09 10:36:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$
2015-07-09 10:36:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2015-07-09 10:12:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$
2015-07-09 10:11:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$
2015-07-09 10:11:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2834886$
2015-07-09 10:11:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2015-07-09 10:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2015-07-09 10:05:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2847311$
2015-07-09 10:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2015-07-09 10:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2802968$
2015-07-09 10:04:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2015-07-09 10:04:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$
2015-07-09 10:03:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2862335$
2015-07-09 10:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2015-07-09 10:03:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2780091$
2015-07-09 10:03:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2015-07-09 10:02:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2876217$
2015-07-09 10:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$
2015-07-09 10:02:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2864063$
2015-07-09 10:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2015-07-09 10:01:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2015-07-09 09:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2015-07-09 09:59:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2850869$
2015-07-09 09:59:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2015-07-09 09:58:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2859537$
2015-07-09 09:57:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2015-07-09 09:52:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2868038$
2015-07-09 09:52:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2820917$
2015-07-09 09:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2015-07-09 09:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2015-07-09 09:50:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2015-07-09 09:49:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2015-07-09 09:49:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2015-07-09 09:49:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2015-07-09 09:49:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2015-07-09 09:48:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2015-07-09 09:46:03 ----D---- C:\Program Files\NVIDIA Corporation
2015-07-09 09:43:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2862330$
2015-07-09 09:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2813345$
2015-07-09 09:02:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2015-07-08 23:11:41 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\uTorrent
2015-07-08 21:30:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\GRETECH
2015-07-08 21:29:05 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\GRETECH
2015-07-08 21:28:45 ----D---- C:\Program Files\GRETECH
2015-07-08 20:13:41 ----D---- C:\WINDOWS\jumpshot.com
2015-07-08 19:58:39 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\AVAST Software
2015-07-08 19:55:03 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2015-07-08 19:54:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2015-07-08 19:54:51 ----A---- C:\WINDOWS\avastSS.scr
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2015-07-08 19:27:56 ----N---- C:\WINDOWS\system32\xp_eos.exe
2015-07-08 19:27:30 ----N---- C:\WINDOWS\system32\tzchange.exe
2015-07-08 19:27:16 ----A---- C:\WINDOWS\system32\javaws.exe
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\javaw.exe
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\java.exe
2015-07-08 19:25:11 ----N---- C:\WINDOWS\system32\occache.dll
2015-07-08 19:25:11 ----N---- C:\WINDOWS\system32\licmgr10.dll
2015-07-08 19:25:10 ----N---- C:\WINDOWS\system32\mshtmled.dll
2015-07-08 19:25:09 ----N---- C:\WINDOWS\system32\iepeers.dll
2015-07-08 19:25:09 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2015-07-08 19:24:02 ----N---- C:\WINDOWS\system32\vbscript.dll

======List of files/folders modified in the last 1 month======

2015-07-19 15:20:26 ----D---- C:\WINDOWS\Prefetch
2015-07-19 15:20:18 ----RD---- C:\Program Files
2015-07-19 14:59:40 ----D---- C:\WINDOWS\system32
2015-07-19 14:59:34 ----D---- C:\WINDOWS\Temp
2015-07-19 14:58:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-07-19 14:28:06 ----SHD---- C:\WINDOWS\Installer
2015-07-19 14:18:13 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2015-07-19 14:16:12 ----D---- C:\WINDOWS
2015-07-19 12:49:45 ----D---- C:\Program Files\PowerArchiver
2015-07-18 08:02:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2015-07-17 07:09:25 ----D---- C:\WINDOWS\system32\CatRoot2
2015-07-16 11:45:33 ----SD---- C:\Documents and Settings\uzivatel\Data aplikací\Microsoft
2015-07-16 11:45:33 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Adobe
2015-07-16 11:30:44 ----D---- C:\WINDOWS\WinSxS
2015-07-16 11:30:24 ----RSD---- C:\WINDOWS\Fonts
2015-07-16 10:36:10 ----HD---- C:\WINDOWS\inf
2015-07-16 10:30:33 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-07-16 06:16:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2015-07-16 06:16:03 ----D---- C:\Program Files\Common Files
2015-07-16 06:15:53 ----D---- C:\WINDOWS\system32\drivers
2015-07-16 02:01:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\ashampoo
2015-07-15 22:31:33 ----SD---- C:\WINDOWS\Tasks
2015-07-15 01:37:10 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-14 20:02:09 ----D---- C:\Program Files\Common Files\Adobe
2015-07-14 20:02:00 ----D---- C:\Program Files\Adobe
2015-07-12 20:27:12 ----D---- C:\Program Files\Google
2015-07-12 03:52:56 ----RSD---- C:\WINDOWS\assembly
2015-07-12 03:52:56 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-12 03:43:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-11 23:04:37 ----HD---- C:\Program Files\InstallShield Installation Information
2015-07-10 22:36:46 ----D---- C:\ZÁLOHY
2015-07-09 21:22:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2015-07-09 18:01:07 ----D---- C:\WINDOWS\system32\en-US
2015-07-09 18:00:37 ----D---- C:\Program Files\Microsoft.NET
2015-07-09 10:40:22 ----DC---- C:\WINDOWS\system32\dllcache
2015-07-09 10:29:50 ----D---- C:\Program Files\CCleaner
2015-07-09 09:57:38 ----HD---- C:\WINDOWS\$hf_mig$
2015-07-09 09:50:37 ----D---- C:\Program Files\Internet Explorer
2015-07-09 09:50:10 ----D---- C:\WINDOWS\ie8updates
2015-07-09 09:47:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2015-07-09 09:20:22 ----D---- C:\WINDOWS\system32\XPSViewer
2015-07-08 22:08:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2015-07-08 19:53:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-07-08 19:27:23 ----D---- C:\Program Files\Common Files\Java
2015-07-08 19:26:13 ----D---- C:\Program Files\Java
2015-07-08 19:21:35 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-07-08 49904]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-07-08 209048]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-10-30 43648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-01-14 47616]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2012-12-29 24184]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-01-03 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2015-07-08 55200]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-07-08 787760]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-07-08 428120]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2015-07-08 57888]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sensorsview;sensorsview; \??\C:\Program Files\SensorsViewPro41\drv\sensorsview32.sys []
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-07-08 24144]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-07-08 74976]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\WINDOWS\system32\DRIVERS\nusb3hub.sys [2012-05-10 75904]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\WINDOWS\system32\DRIVERS\nusb3xhc.sys [2012-05-10 168448]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-27 83712]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 a2h6fovs;a2h6fovs; C:\WINDOWS\system32\drivers\a2h6fovs.sys []
S3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCTINDIS5.SYS []
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys []
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 w900bus;Sony Ericsson 900i driver (WDM); C:\WINDOWS\system32\DRIVERS\w900bus.sys []
S3 w900mdfl;Sony Ericsson 900i USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w900mdfl.sys []
S3 w900mdm;Sony Ericsson 900i USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\w900mdm.sys []
S3 w900mgmt;Sony Ericsson 900i USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\w900mgmt.sys []
S3 w900obex;Sony Ericsson 900i USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\w900obex.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-08 343336]
R2 IHProtect Service;IHProtect Service; C:\Program Files\MiuiTab\ProtectService.exe [2015-06-24 125112]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2015-07-08 182696]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 SensorsVService;SensorsVService; C:\Program Files\SensorsViewPro41\svservice.exe [2010-06-17 923648]
R2 WindowsMangerProtect;WindowsMangerProtect Service; C:\Documents and Settings\All Users\Data aplikací\WindowsMangerProtect\ProtectWindowsManager.exe [2015-07-19 707240]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-10 107848]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-18 163908]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15 268976]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-10 107848]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Dík, Ivo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119675
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: SearchProtect

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#3 Příspěvek od Ivošisko »

Log z ADWcleaneru:


# AdwCleaner v4.208 - Log vytvořen 19/07/2015 v 17:50:13
# Aktualizováno 09/07/2015 by Xplode
# Databáze : 2015-07-15.1 [Server]
# Operační system : Microsoft Windows XP Service Pack 3 (x86)
# Uživatelské jméno : uzivatel - PCNEW
# Spuštěno z : C:\Documents and Settings\uzivatel\Plocha\adwcleaner_4.208.exe
# Nastavení : Čištění

***** [ Služby ] *****

[#] Služba Smazáno : IHProtect Service
[#] Služba Smazáno : WindowsMangerProtect

***** [ Soubory / Složky ] *****

Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\WindowsMangerProtect
Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\IHProtectUpDate
Složka Smazáno : C:\Program Files\miuitab
Složka Smazáno : C:\Documents and Settings\uzivatel\Dokumenty\PC Speed Maximizer

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Klíč Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{03DCDBBF-4DD6-4111-B4C0-3DF6249220E3}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{22CC10DF-C285-4EC4-8769-CC9F481F7874}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3EC4DBFF-46C7-4964-AB26-60E942F7387C}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{75C3F1D5-F961-47FC-9C9F-5E573C85DDA6}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8588BED3-78EA-42AF-841C-6BA975F9C4FA}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A3B1A68E-51A6-4355-BBD8-4F9F33248A0A}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AB65709D-7E2C-44EB-8B19-51828FE1828A}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Klíč Smazáno : HKCU\Software\APN PIP
Klíč Smazáno : HKCU\Software\AskPartnerNetwork
Klíč Smazáno : HKCU\Software\HomeTab
Klíč Smazáno : HKCU\Software\simplytech
Klíč Smazáno : HKCU\Software\WajIEnhance
Klíč Smazáno : HKCU\Software\TNT2
Klíč Smazáno : HKCU\Software\WajIntEnhance
Klíč Smazáno : HKCU\Software\SearchProtectWS
Klíč Smazáno : HKCU\Software\Linkey
Klíč Smazáno : HKCU\Software\Kromtech
Klíč Smazáno : HKLM\SOFTWARE\AskPartnerNetwork
Klíč Smazáno : HKLM\SOFTWARE\Conduit
Klíč Smazáno : HKLM\SOFTWARE\Iminent
Klíč Smazáno : HKLM\SOFTWARE\SearchProtect
Klíč Smazáno : HKLM\SOFTWARE\Speedchecker Limited
Klíč Smazáno : HKLM\SOFTWARE\SupDp
Klíč Smazáno : HKLM\SOFTWARE\SupTab
Klíč Smazáno : HKLM\SOFTWARE\supWindowsMangerProtect
Klíč Smazáno : HKLM\SOFTWARE\mystartsearchSoftware
Klíč Smazáno : HKLM\SOFTWARE\IHProtect
Klíč Smazáno : HKLM\SOFTWARE\WajIntEnhance
Klíč Smazáno : HKLM\SOFTWARE\SpeedBit
Klíč Smazáno : HKLM\SOFTWARE\AIM Toolbar
Klíč Smazáno : HKLM\SOFTWARE\searchult
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey

***** [ Prohlížeče ] *****

-\\ Internet Explorer v8.0.6001.18702

Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]

-\\ Mozilla Firefox v


-\\ Google Chrome v43.0.2357.134

[C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] :
[C:\Documents and Settings\uzivatel\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Startup_URLs] : 64D086718530E7F45DC38579DE123A1C46B70CD395886BBE4877C77066926E8E"},"software_reporter":{"prompt_reason":"C52EC77D4A223CE017D0A7E9D0A92D52BD5C1C6D302DAFEC1D294CF81B5110C9","prompt_seed":"2EDC389238D54F9F3B873CB5F8CF2FCE8C06DF0EE71ACE4373E9B9DBFD83D23A","prompt_version":"A17872282D62A9BCA793A962EEFFF056AE22139A1951CED0B3F065BE0E01BDBF"},"sync":{"remaining_rollback_tries":"8FE8CB11516DC5499CC9B871353EE195D8226D7B01814AB304D1B072B40DCA29"}},"super_mac":"BFB925CC4EFBF2E01DEB650DB33E9E376B06649CE522947F90AAAF2F7CFED4C3"},"session":{"restore_on_startup":1,"startup_urls":["hxxp://www.google.com/","hxxp://www.google.com ... m=cvs&uid=_

*************************

AdwCleaner[R0].txt - [13349 bytů] - [19/07/2015 17:48:18]
AdwCleaner[S0].txt - [7461 bytů] - [19/07/2015 17:50:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7519 bytů] ##########
Dík, Ivo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119675
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: SearchProtect

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#5 Příspěvek od Ivošisko »

Log RSIT:


Logfile of random's system information tool 1.10 (written by random/random)
Run by uzivatel at 2015-07-19 20:12:04
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 18 GB (15%) free of 114 GB
Total RAM: 3007 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:12:10, on 19.7.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SensorsViewPro41\sviewpro.exe
C:\Program Files\eM Client\MailClient.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\SensorsViewPro41\svservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msfeedssync.exe
C:\Documents and Settings\uzivatel\Plocha\RSIT.exe
C:\Program Files\trend micro\uzivatel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SensorsView] C:\Program Files\SensorsViewPro41\sviewpro.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - Startup: E-mail.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SensorsVService - Unknown owner - C:\Program Files\SensorsViewPro41\svservice.exe

--
End of file - 5947 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\User_Feed_Synchronization-{79D0B19C-05FC-4F37-8300-D83CFD8BCC1A}.job - C:\WINDOWS\system32\msfeedssync.exe sync

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2015-07-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-08 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-07-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\WINDOWS\JM\JMInsIDE.exe [2006-10-30 36864]
"JMB36X Configure"=C:\WINDOWS\system32\JMRaidSetup.exe [2006-10-30 1953792]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-07-08 5515496]
"NUSB3MON"=C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2011-09-16 115048]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"uTorrent"=C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe [2015-02-22 416168]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SensorsView"=C:\Program Files\SensorsViewPro41\sviewpro.exe [2011-04-05 2267648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2012-09-23 40592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2012-09-23 689304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []

C:\Documents and Settings\uzivatel\Nabídka Start\Programy\Po spuštění
E-mail.lnk -

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=255
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\InterVideo\DVD6\WinDVD.exe"="C:\Program Files\InterVideo\DVD6\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\WINDOWS\system32\winver.exe"="C:\WINDOWS\system32\winver.exe:*:Enabled:winver"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Sprite Software\Sprite Backup\spriteservice.exe"="C:\Program Files\Sprite Software\Sprite Backup\spriteservice.exe:*:Enabled:Sprite PC Service"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi"
"C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe"="C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=vp6vfw.dll
"vidc.VP61"=vp6vfw.dll
"vidc.xvid"=xvidvfw.dll
"vidc.ffds"=ff_vfw.dll
"vidc.vp62"=vp6vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.divxa32"=DivXa32.acm
"msacm.lameacm"=LameACM.acm
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2015-07-19 17:48:11 ----D---- C:\AdwCleaner
2015-07-19 15:20:18 ----D---- C:\rsit
2015-07-19 15:20:18 ----D---- C:\Program Files\trend micro
2015-07-19 14:19:37 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\STV Software
2015-07-19 14:19:31 ----D---- C:\Program Files\SensorsViewPro41
2015-07-19 14:16:12 ----A---- C:\WINDOWS\prleth.sys
2015-07-19 14:16:12 ----A---- C:\WINDOWS\hgfs.sys
2015-07-18 20:29:28 ----D---- C:\Program Files\SpeedFan
2015-07-16 11:36:07 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Wondershare
2015-07-16 11:31:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\wondershare
2015-07-16 10:36:17 ----A---- C:\WINDOWS\system32\ZSHP1020.EXE
2015-07-16 10:36:17 ----A---- C:\WINDOWS\system32\ZLhp1020.DLL
2015-07-16 10:30:33 ----A---- C:\WINDOWS\system32\zshp1020s.dll
2015-07-16 10:30:26 ----D---- C:\Program Files\HP
2015-07-16 10:30:26 ----A---- C:\WINDOWS\system32\Difxapi.dll
2015-07-16 10:29:57 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\HP
2015-07-16 10:29:18 ----D---- C:\hp_lj1020_Full_Solution
2015-07-12 20:16:49 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Avant Downloader
2015-07-11 23:19:47 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\eM Client
2015-07-11 23:18:48 ----D---- C:\Program Files\eM Client
2015-07-11 23:04:28 ----A---- C:\WINDOWS\system32\drivers\nusb3xhc.sys
2015-07-11 23:04:27 ----A---- C:\WINDOWS\system32\nusb3co3.dll
2015-07-11 23:04:27 ----A---- C:\WINDOWS\system32\drivers\nusb3hub.sys
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\2C0A
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0C0A
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0C04
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0816
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0804
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0424
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041F
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041E
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041D
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041B
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0419
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0416
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0415
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0414
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0413
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0412
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0411
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0410
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040E
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040D
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040C
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040B
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040A
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0409
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0408
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0407
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0406
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0405
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0404
2015-07-11 23:04:20 ----D---- C:\Program Files\Renesas Electronics
2015-07-11 23:03:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
2015-07-11 19:28:07 ----D---- C:\Program Files\Defraggler
2015-07-11 17:03:15 ----D---- C:\Program Files\Unlocker
2015-07-10 19:25:46 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Google Chrome Backup
2015-07-10 07:30:58 ----D---- C:\Program Files\FastStone Image Viewer
2015-07-09 18:08:02 ----D---- C:\Program Files\Subtitle Edit
2015-07-09 18:08:02 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Subtitle Edit
2015-07-09 13:16:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Caphyon
2015-07-09 10:40:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2015-07-09 10:36:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$
2015-07-09 10:36:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2015-07-09 10:12:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$
2015-07-09 10:11:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$
2015-07-09 10:11:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2834886$
2015-07-09 10:11:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2015-07-09 10:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2015-07-09 10:05:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2847311$
2015-07-09 10:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2015-07-09 10:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2802968$
2015-07-09 10:04:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2015-07-09 10:04:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$
2015-07-09 10:03:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2862335$
2015-07-09 10:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2015-07-09 10:03:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2780091$
2015-07-09 10:03:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2015-07-09 10:02:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2876217$
2015-07-09 10:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$
2015-07-09 10:02:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2864063$
2015-07-09 10:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2015-07-09 10:01:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2015-07-09 09:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2015-07-09 09:59:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2850869$
2015-07-09 09:59:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2015-07-09 09:58:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2859537$
2015-07-09 09:57:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2015-07-09 09:52:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2868038$
2015-07-09 09:52:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2820917$
2015-07-09 09:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2015-07-09 09:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2015-07-09 09:50:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2015-07-09 09:49:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2015-07-09 09:49:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2015-07-09 09:49:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2015-07-09 09:49:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2015-07-09 09:48:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2015-07-09 09:46:03 ----D---- C:\Program Files\NVIDIA Corporation
2015-07-09 09:43:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2862330$
2015-07-09 09:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2813345$
2015-07-09 09:02:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2015-07-08 23:11:41 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\uTorrent
2015-07-08 21:30:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\GRETECH
2015-07-08 21:29:05 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\GRETECH
2015-07-08 21:28:45 ----D---- C:\Program Files\GRETECH
2015-07-08 20:13:41 ----D---- C:\WINDOWS\jumpshot.com
2015-07-08 19:58:39 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\AVAST Software
2015-07-08 19:55:03 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2015-07-08 19:54:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2015-07-08 19:54:51 ----A---- C:\WINDOWS\avastSS.scr
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2015-07-08 19:27:56 ----N---- C:\WINDOWS\system32\xp_eos.exe
2015-07-08 19:27:30 ----N---- C:\WINDOWS\system32\tzchange.exe
2015-07-08 19:27:16 ----A---- C:\WINDOWS\system32\javaws.exe
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\javaw.exe
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\java.exe
2015-07-08 19:25:11 ----N---- C:\WINDOWS\system32\occache.dll
2015-07-08 19:25:11 ----N---- C:\WINDOWS\system32\licmgr10.dll
2015-07-08 19:25:10 ----N---- C:\WINDOWS\system32\mshtmled.dll
2015-07-08 19:25:09 ----N---- C:\WINDOWS\system32\iepeers.dll
2015-07-08 19:25:09 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2015-07-08 19:24:02 ----N---- C:\WINDOWS\system32\vbscript.dll

======List of files/folders modified in the last 1 month======

2015-07-19 18:44:53 ----D---- C:\Program Files\PowerArchiver
2015-07-19 18:35:14 ----D---- C:\WINDOWS\Temp
2015-07-19 17:52:51 ----D---- C:\WINDOWS\Prefetch
2015-07-19 17:51:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-07-19 17:50:14 ----RD---- C:\Program Files
2015-07-19 14:59:40 ----D---- C:\WINDOWS\system32
2015-07-19 14:28:06 ----SHD---- C:\WINDOWS\Installer
2015-07-19 14:18:13 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2015-07-19 14:16:12 ----D---- C:\WINDOWS
2015-07-18 08:02:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2015-07-17 07:09:25 ----D---- C:\WINDOWS\system32\CatRoot2
2015-07-16 11:45:33 ----SD---- C:\Documents and Settings\uzivatel\Data aplikací\Microsoft
2015-07-16 11:45:33 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Adobe
2015-07-16 11:30:44 ----D---- C:\WINDOWS\WinSxS
2015-07-16 11:30:24 ----RSD---- C:\WINDOWS\Fonts
2015-07-16 10:36:10 ----HD---- C:\WINDOWS\inf
2015-07-16 10:30:33 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-07-16 06:16:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2015-07-16 06:16:03 ----D---- C:\Program Files\Common Files
2015-07-16 06:15:53 ----D---- C:\WINDOWS\system32\drivers
2015-07-16 02:01:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\ashampoo
2015-07-15 22:31:33 ----SD---- C:\WINDOWS\Tasks
2015-07-15 01:37:10 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-14 20:02:09 ----D---- C:\Program Files\Common Files\Adobe
2015-07-14 20:02:00 ----D---- C:\Program Files\Adobe
2015-07-12 20:27:12 ----D---- C:\Program Files\Google
2015-07-12 03:52:56 ----RSD---- C:\WINDOWS\assembly
2015-07-12 03:52:56 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-12 03:43:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-11 23:04:37 ----HD---- C:\Program Files\InstallShield Installation Information
2015-07-10 22:36:46 ----D---- C:\ZÁLOHY
2015-07-09 21:22:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2015-07-09 18:01:07 ----D---- C:\WINDOWS\system32\en-US
2015-07-09 18:00:37 ----D---- C:\Program Files\Microsoft.NET
2015-07-09 10:40:22 ----DC---- C:\WINDOWS\system32\dllcache
2015-07-09 10:29:50 ----D---- C:\Program Files\CCleaner
2015-07-09 09:57:38 ----HD---- C:\WINDOWS\$hf_mig$
2015-07-09 09:50:37 ----D---- C:\Program Files\Internet Explorer
2015-07-09 09:50:10 ----D---- C:\WINDOWS\ie8updates
2015-07-09 09:47:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2015-07-09 09:20:22 ----D---- C:\WINDOWS\system32\XPSViewer
2015-07-08 22:08:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2015-07-08 19:53:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-07-08 19:27:23 ----D---- C:\Program Files\Common Files\Java
2015-07-08 19:26:13 ----D---- C:\Program Files\Java
2015-07-08 19:21:35 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-07-08 49904]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-07-08 209048]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-10-30 43648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-01-14 47616]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2012-12-29 24184]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-01-03 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2015-07-08 55200]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-07-08 787760]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-07-08 428120]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2015-07-08 57888]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sensorsview;sensorsview; \??\C:\Program Files\SensorsViewPro41\drv\sensorsview32.sys []
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-07-08 24144]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-07-08 74976]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\WINDOWS\system32\DRIVERS\nusb3hub.sys [2012-05-10 75904]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\WINDOWS\system32\DRIVERS\nusb3xhc.sys [2012-05-10 168448]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-27 83712]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 aqtsvwly;aqtsvwly; C:\WINDOWS\system32\drivers\aqtsvwly.sys []
S3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCTINDIS5.SYS []
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys []
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 w900bus;Sony Ericsson 900i driver (WDM); C:\WINDOWS\system32\DRIVERS\w900bus.sys []
S3 w900mdfl;Sony Ericsson 900i USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w900mdfl.sys []
S3 w900mdm;Sony Ericsson 900i USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\w900mdm.sys []
S3 w900mgmt;Sony Ericsson 900i USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\w900mgmt.sys []
S3 w900obex;Sony Ericsson 900i USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\w900obex.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-08 343336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2015-07-08 182696]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 SensorsVService;SensorsVService; C:\Program Files\SensorsViewPro41\svservice.exe [2010-06-17 923648]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-10 107848]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-18 163908]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15 268976]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-10 107848]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Dík, Ivo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119675
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: SearchProtect

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

:services
aqtsvwly

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#7 Příspěvek od Ivošisko »

Nový log z RSIT:


Logfile of random's system information tool 1.10 (written by random/random)
Run by uzivatel at 2015-07-19 21:26:02
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 18 GB (15%) free of 114 GB
Total RAM: 3007 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:26:31, on 19.7.2015
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\SensorsViewPro41\svservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SensorsViewPro41\sviewpro.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\eM Client\MailClient.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\uzivatel\Plocha\RSIT.exe
C:\Program Files\trend micro\uzivatel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SensorsView] C:\Program Files\SensorsViewPro41\sviewpro.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - Startup: E-mail.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SensorsVService - Unknown owner - C:\Program Files\SensorsViewPro41\svservice.exe

--
End of file - 5992 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\avast! Emergency Update.job - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe
C:\WINDOWS\tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job - C:\WINDOWS\system32\xp_eos.exe -c
C:\WINDOWS\tasks\User_Feed_Synchronization-{79D0B19C-05FC-4F37-8300-D83CFD8BCC1A}.job - C:\WINDOWS\system32\msfeedssync.exe sync

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2015-07-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-08 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-07-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"=C:\WINDOWS\JM\JMInsIDE.exe [2006-10-30 36864]
"JMB36X Configure"=C:\WINDOWS\system32\JMRaidSetup.exe [2006-10-30 1953792]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2006-12-18 868352]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-07-08 5515496]
"NUSB3MON"=C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2011-09-16 115048]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"uTorrent"=C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe [2015-02-22 416168]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SensorsView"=C:\Program Files\SensorsViewPro41\sviewpro.exe [2011-04-05 2267648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE [2012-09-23 40592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Synchronizer.lnk]
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE [2012-09-23 689304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []

C:\Documents and Settings\uzivatel\Nabídka Start\Programy\Po spuštění
E-mail.lnk -

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=255
"NoDrives"=0
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\InterVideo\DVD6\WinDVD.exe"="C:\Program Files\InterVideo\DVD6\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\WINDOWS\system32\winver.exe"="C:\WINDOWS\system32\winver.exe:*:Enabled:winver"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Sprite Software\Sprite Backup\spriteservice.exe"="C:\Program Files\Sprite Software\Sprite Backup\spriteservice.exe:*:Enabled:Sprite PC Service"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ"
"C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe"="C:\Program Files\Pinnacle\Studio 15\Programs\umi.exe:*:Enabled:umi"
"C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe"="C:\Documents and Settings\uzivatel\Data aplikací\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.VP60"=vp6vfw.dll
"vidc.VP61"=vp6vfw.dll
"vidc.xvid"=xvidvfw.dll
"vidc.ffds"=ff_vfw.dll
"vidc.vp62"=vp6vfw.dll
"msacm.ac3filter"=ac3filter.acm
"msacm.divxa32"=DivXa32.acm
"msacm.lameacm"=LameACM.acm
"msacm.vorbis"=vorbis.acm

======List of files/folders created in the last 1 month======

2015-07-19 21:17:27 ----D---- C:\_OTM
2015-07-19 17:48:11 ----D---- C:\AdwCleaner
2015-07-19 15:20:18 ----D---- C:\rsit
2015-07-19 15:20:18 ----D---- C:\Program Files\trend micro
2015-07-19 14:19:37 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\STV Software
2015-07-19 14:19:31 ----D---- C:\Program Files\SensorsViewPro41
2015-07-19 14:16:12 ----A---- C:\WINDOWS\prleth.sys
2015-07-19 14:16:12 ----A---- C:\WINDOWS\hgfs.sys
2015-07-18 20:29:28 ----D---- C:\Program Files\SpeedFan
2015-07-16 11:36:07 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Wondershare
2015-07-16 11:31:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\wondershare
2015-07-16 10:36:17 ----A---- C:\WINDOWS\system32\ZSHP1020.EXE
2015-07-16 10:36:17 ----A---- C:\WINDOWS\system32\ZLhp1020.DLL
2015-07-16 10:30:33 ----A---- C:\WINDOWS\system32\zshp1020s.dll
2015-07-16 10:30:26 ----D---- C:\Program Files\HP
2015-07-16 10:30:26 ----A---- C:\WINDOWS\system32\Difxapi.dll
2015-07-16 10:29:57 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\HP
2015-07-16 10:29:18 ----D---- C:\hp_lj1020_Full_Solution
2015-07-12 20:16:49 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Avant Downloader
2015-07-11 23:19:47 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\eM Client
2015-07-11 23:18:48 ----D---- C:\Program Files\eM Client
2015-07-11 23:04:28 ----A---- C:\WINDOWS\system32\drivers\nusb3xhc.sys
2015-07-11 23:04:27 ----A---- C:\WINDOWS\system32\nusb3co3.dll
2015-07-11 23:04:27 ----A---- C:\WINDOWS\system32\drivers\nusb3hub.sys
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\2C0A
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0C0A
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0C04
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0816
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0804
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0424
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041F
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041E
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041D
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\041B
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0419
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0416
2015-07-11 23:04:25 ----D---- C:\WINDOWS\system32\0415
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0414
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0413
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0412
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0411
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0410
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040E
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040D
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040C
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040B
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\040A
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0409
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0408
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0407
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0406
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0405
2015-07-11 23:04:24 ----D---- C:\WINDOWS\system32\0404
2015-07-11 23:04:20 ----D---- C:\Program Files\Renesas Electronics
2015-07-11 23:03:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Downloaded Installations
2015-07-11 19:28:07 ----D---- C:\Program Files\Defraggler
2015-07-11 17:03:15 ----D---- C:\Program Files\Unlocker
2015-07-10 19:25:46 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Google Chrome Backup
2015-07-10 07:30:58 ----D---- C:\Program Files\FastStone Image Viewer
2015-07-09 18:08:02 ----D---- C:\Program Files\Subtitle Edit
2015-07-09 18:08:02 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Subtitle Edit
2015-07-09 13:16:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Caphyon
2015-07-09 10:40:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2868626$
2015-07-09 10:36:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2922229$
2015-07-09 10:36:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2712808$
2015-07-09 10:12:12 ----HDC---- C:\WINDOWS\$NtUninstallKB2916036$
2015-07-09 10:11:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2934207$
2015-07-09 10:11:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2834886$
2015-07-09 10:11:07 ----HDC---- C:\WINDOWS\$NtUninstallKB2691442$
2015-07-09 10:05:23 ----HDC---- C:\WINDOWS\$NtUninstallKB2900986$
2015-07-09 10:05:06 ----HDC---- C:\WINDOWS\$NtUninstallKB2847311$
2015-07-09 10:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2655992$
2015-07-09 10:04:47 ----HDC---- C:\WINDOWS\$NtUninstallKB2802968$
2015-07-09 10:04:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2898715$
2015-07-09 10:04:13 ----HDC---- C:\WINDOWS\$NtUninstallKB2929961$
2015-07-09 10:03:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2862335$
2015-07-09 10:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB2834904-v2_WM11$
2015-07-09 10:03:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2780091$
2015-07-09 10:03:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2904266$
2015-07-09 10:02:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2876217$
2015-07-09 10:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2930275$
2015-07-09 10:02:08 ----HDC---- C:\WINDOWS\$NtUninstallKB2864063$
2015-07-09 10:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2719985$
2015-07-09 10:01:46 ----HDC---- C:\WINDOWS\$NtUninstallKB2862152$
2015-07-09 09:59:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2770660$
2015-07-09 09:59:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2850869$
2015-07-09 09:59:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2876331$
2015-07-09 09:58:32 ----HDC---- C:\WINDOWS\$NtUninstallKB2859537$
2015-07-09 09:57:53 ----HDC---- C:\WINDOWS\$NtUninstallKB2807986$
2015-07-09 09:52:38 ----HDC---- C:\WINDOWS\$NtUninstallKB2868038$
2015-07-09 09:52:15 ----HDC---- C:\WINDOWS\$NtUninstallKB2820917$
2015-07-09 09:51:57 ----HDC---- C:\WINDOWS\$NtUninstallKB2893294$
2015-07-09 09:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2757638$
2015-07-09 09:50:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2749655$
2015-07-09 09:49:44 ----HDC---- C:\WINDOWS\$NtUninstallKB2892075$
2015-07-09 09:49:30 ----HDC---- C:\WINDOWS\$NtUninstallKB2698365$
2015-07-09 09:49:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2705219-v2$
2015-07-09 09:49:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2727528$
2015-07-09 09:48:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2723135-v2$
2015-07-09 09:46:03 ----D---- C:\Program Files\NVIDIA Corporation
2015-07-09 09:43:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2862330$
2015-07-09 09:41:48 ----HDC---- C:\WINDOWS\$NtUninstallKB2813345$
2015-07-09 09:02:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2914368$
2015-07-08 23:11:41 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\uTorrent
2015-07-08 21:30:25 ----D---- C:\Documents and Settings\All Users\Data aplikací\GRETECH
2015-07-08 21:29:05 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\GRETECH
2015-07-08 21:28:45 ----D---- C:\Program Files\GRETECH
2015-07-08 20:13:41 ----D---- C:\WINDOWS\jumpshot.com
2015-07-08 19:58:39 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\AVAST Software
2015-07-08 19:55:03 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2015-07-08 19:54:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2015-07-08 19:54:51 ----A---- C:\WINDOWS\avastSS.scr
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2015-07-08 19:52:19 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2015-07-08 19:27:56 ----N---- C:\WINDOWS\system32\xp_eos.exe
2015-07-08 19:27:30 ----N---- C:\WINDOWS\system32\tzchange.exe
2015-07-08 19:27:16 ----A---- C:\WINDOWS\system32\javaws.exe
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\javaw.exe
2015-07-08 19:27:00 ----A---- C:\WINDOWS\system32\java.exe
2015-07-08 19:25:11 ----N---- C:\WINDOWS\system32\occache.dll
2015-07-08 19:25:11 ----N---- C:\WINDOWS\system32\licmgr10.dll
2015-07-08 19:25:10 ----N---- C:\WINDOWS\system32\mshtmled.dll
2015-07-08 19:25:09 ----N---- C:\WINDOWS\system32\iepeers.dll
2015-07-08 19:25:09 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2015-07-08 19:24:02 ----N---- C:\WINDOWS\system32\vbscript.dll

======List of files/folders modified in the last 1 month======

2015-07-19 21:21:45 ----D---- C:\WINDOWS\Prefetch
2015-07-19 21:20:05 ----D---- C:\WINDOWS\Temp
2015-07-19 21:18:51 ----A---- C:\WINDOWS\SchedLgU.Txt
2015-07-19 21:18:24 ----SD---- C:\WINDOWS\Tasks
2015-07-19 20:19:13 ----D---- C:\Program Files\PowerArchiver
2015-07-19 17:50:14 ----RD---- C:\Program Files
2015-07-19 14:59:40 ----D---- C:\WINDOWS\system32
2015-07-19 14:28:06 ----SHD---- C:\WINDOWS\Installer
2015-07-19 14:18:13 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2015-07-19 14:16:12 ----D---- C:\WINDOWS
2015-07-18 08:02:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2015-07-17 07:09:25 ----D---- C:\WINDOWS\system32\CatRoot2
2015-07-16 11:45:33 ----SD---- C:\Documents and Settings\uzivatel\Data aplikací\Microsoft
2015-07-16 11:45:33 ----D---- C:\Documents and Settings\uzivatel\Data aplikací\Adobe
2015-07-16 11:30:44 ----D---- C:\WINDOWS\WinSxS
2015-07-16 11:30:24 ----RSD---- C:\WINDOWS\Fonts
2015-07-16 10:36:10 ----HD---- C:\WINDOWS\inf
2015-07-16 10:30:33 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-07-16 06:16:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2015-07-16 06:16:03 ----D---- C:\Program Files\Common Files
2015-07-16 06:15:53 ----D---- C:\WINDOWS\system32\drivers
2015-07-16 02:01:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\ashampoo
2015-07-15 01:37:10 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2015-07-14 20:02:09 ----D---- C:\Program Files\Common Files\Adobe
2015-07-14 20:02:00 ----D---- C:\Program Files\Adobe
2015-07-12 20:27:12 ----D---- C:\Program Files\Google
2015-07-12 03:52:56 ----RSD---- C:\WINDOWS\assembly
2015-07-12 03:52:56 ----D---- C:\WINDOWS\Microsoft.NET
2015-07-12 03:43:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-07-11 23:04:37 ----HD---- C:\Program Files\InstallShield Installation Information
2015-07-10 22:36:46 ----D---- C:\ZÁLOHY
2015-07-09 21:22:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2015-07-09 18:01:07 ----D---- C:\WINDOWS\system32\en-US
2015-07-09 18:00:37 ----D---- C:\Program Files\Microsoft.NET
2015-07-09 10:40:22 ----DC---- C:\WINDOWS\system32\dllcache
2015-07-09 10:29:50 ----D---- C:\Program Files\CCleaner
2015-07-09 09:57:38 ----HD---- C:\WINDOWS\$hf_mig$
2015-07-09 09:50:37 ----D---- C:\Program Files\Internet Explorer
2015-07-09 09:50:10 ----D---- C:\WINDOWS\ie8updates
2015-07-09 09:47:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2015-07-09 09:20:22 ----D---- C:\WINDOWS\system32\XPSViewer
2015-07-08 22:08:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2015-07-08 19:53:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2015-07-08 19:27:23 ----D---- C:\Program Files\Common Files\Java
2015-07-08 19:26:13 ----D---- C:\Program Files\Java
2015-07-08 19:21:35 ----D---- C:\WINDOWS\Help

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-07-08 49904]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-07-08 209048]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 JGOGO;JMicron Hot-Plug Driver; C:\WINDOWS\system32\DRIVERS\JGOGO.sys [2006-02-07 6912]
R0 JRAID;JRAID; C:\WINDOWS\system32\DRIVERS\jraid.sys [2006-10-30 43648]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-01-14 47616]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2004-10-28 6656]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2012-12-29 24184]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-01-03 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2015-07-08 55200]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-07-08 787760]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-07-08 428120]
R1 aswTdi;aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [2015-07-08 57888]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sensorsview;sensorsview; \??\C:\Program Files\SensorsViewPro41\drv\sensorsview32.sys []
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-07-08 24144]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-07-08 74976]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2007-01-16 293888]
R3 AEAudio;AE Audio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2006-08-07 93952]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\WINDOWS\system32\DRIVERS\nusb3hub.sys [2012-05-10 75904]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\WINDOWS\system32\DRIVERS\nusb3xhc.sys [2012-05-10 168448]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2013-02-08 12648960]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2006-07-27 83712]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2006-03-17 392960]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S3 acuv70py;acuv70py; C:\WINDOWS\system32\drivers\acuv70py.sys []
S3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-09-23 171520]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCTINDIS5.SYS []
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys []
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 w900bus;Sony Ericsson 900i driver (WDM); C:\WINDOWS\system32\DRIVERS\w900bus.sys []
S3 w900mdfl;Sony Ericsson 900i USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\w900mdfl.sys []
S3 w900mdm;Sony Ericsson 900i USB WMC Modem Drivers; C:\WINDOWS\system32\DRIVERS\w900mdm.sys []
S3 w900mgmt;Sony Ericsson 900i USB WMC Device Management Drivers; C:\WINDOWS\system32\DRIVERS\w900mgmt.sys []
S3 w900obex;Sony Ericsson 900i USB WMC OBEX Interface Drivers; C:\WINDOWS\system32\DRIVERS\w900obex.sys []
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-08 343336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2015-07-08 182696]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 SensorsVService;SensorsVService; C:\Program Files\SensorsViewPro41\svservice.exe [2010-06-17 923648]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-10 107848]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-18 163908]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-15 268976]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-07-10 107848]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-07-20 754856]
S4 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe []
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Dík, Ivo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119675
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: SearchProtect

#8 Příspěvek od Rudy »

Dvouklikem na soubor C:\Program Files\trend micro\uzivatel.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - Startup: E-mail.lnk = ?
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#9 Příspěvek od Ivošisko »

Ha.....když mám ty položky zafajfklé, tak co s tím dělat? Tuto operaci zatím neznám :shock:
Dík, Ivo.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#10 Příspěvek od Ivošisko »

Sorry, já to přehlíd - Fix Checked - už jedu :)
Dík, Ivo.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#11 Příspěvek od Ivošisko »

Takže vše proběhlo dle Tvého scénáře. Ale chtěl jsem se ještě zeptat na věc, která ne příliš souvisí s viry - když otevřu "Start/Ovládací panely/Přidat n. odebrat programy", tak tam mám mj. i spoustu Frameworků a Jav a dalších MS položek - mohou se ty starší verze odinstalovat?
Dík, Ivo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119675
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: SearchProtect

#12 Příspěvek od Rudy »

U FW určitě ne, různé věci používají různé verze. A u Javy asi také ne, ta je jen jedna, ale upgraduje se. Problé pominul?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
Ivošisko
Návštěvník
Návštěvník
Příspěvky: 411
Registrován: 04 říj 2006 11:26
Bydliště: Ostrava/Jeseníky
Kontaktovat uživatele:

Re: SearchProtect

#13 Příspěvek od Ivošisko »

Rudy, zdá se že ano.....jsi moje dobrá víla.....nečekal jsem, že z tak "prestižních" stránek si natáhnu nějaké "svinstvo"

Děkuji moc.
Dík, Ivo.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119675
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: SearchProtect

#14 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno