Stránka 2 z 2

Re: omezený přístup na internet

Napsal: 03 led 2012 09:54
od chodnik74
Chtělo by to nějaký antivirus :) Třeba ten Avast nainstalovat ;-)

:arrow: Stáhneme si na Plochu program OTLObrázek
  • Spustíme soubor OTL.exe (pokud máte Windows Vista nebo Windows 7,tak na soubor klikněte pravým tlačítkem myši a dejte ,,Spustit jako správce,,)
  • Do dolního okna Vlastní skenování/opravy vložíme následující skript a stiskneme tlačítko Opravit

    Kód: Vybrat vše

    :Files
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :OTL
    [3 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
    [5 C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\*.tmp -> ]
    [1 C:\Windows\SoftwareDistribution\Download\33a1b5a0475cdbfea139233e4d990a8c\*.tmp files -> C:\Windows\SoftwareDistribution\Download\33a1b5a0475cdbfea139233e4d990a8c\*.tmp -> ]
    [1 C:\Windows\SoftwareDistribution\Download\3fedcac79b66bcf0809496c7a29500cd\*.tmp files -> C:\Windows\SoftwareDistribution\Download\3fedcac79b66bcf0809496c7a29500cd\*.tmp -> ]
    [1 C:\Windows\SoftwareDistribution\Download\744d0a29f79b4b4949620ac5107e09ad\*.tmp files -> C:\Windows\SoftwareDistribution\Download\744d0a29f79b4b4949620ac5107e09ad\*.tmp -> ]
    [1 C:\Windows\SoftwareDistribution\Download\ab84c9ab9bce3d469fb4251d05dba4af\*.tmp files -> C:\Windows\SoftwareDistribution\Download\ab84c9ab9bce3d469fb4251d05dba4af\*.tmp -> ]
    [11 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://asus.msn.com
    
    :Commands
    [ClearAllRestorePoints]
    [EmptyFlash]
    [EmptyTemp]
    [ResetHosts]
    
  • Po restartu pc se vám objeví log z OTL,ten mi sem prosím vložte..

Re: omezený přístup na internet

Napsal: 03 led 2012 16:53
od MAT
Tak jsem vse udelal dle instrukci, jen se to samo nerestartovalo, musel jsem udelat restart sam a potom to nevytvořilo žádný log. Jestli to neblouknu avast. JInak od včerejška večera vše už funguje jak má. Ještě jsem mrknul na wifinu a možná byl problém i v ní, restartnul jsem jí celou a trochu poladil připojení. Snad to vydrží.

Re: omezený přístup na internet

Napsal: 03 led 2012 20:17
od chodnik74
Zkus ten krok udělat ještě jednou :) pak mrkneme, zda je vše v pořádku :)

Re: omezený přístup na internet

Napsal: 03 led 2012 20:42
od MAT
Teď se mi to už podařilo. Opravdu to asi blokoval avast, špatně jsem potvrdil povolení. :D


All processes killed
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== OTL ==========
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP9E41.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPC948.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPD401.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAP2617.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPD4FA.tmp\mscorlib.dll deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPD4FA.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE291.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPE56E.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_64\Temp\ZAPF528.tmp folder deleted successfully.
C:\Windows\SoftwareDistribution\Download\33a1b5a0475cdbfea139233e4d990a8c\BIT8B87.tmp deleted successfully.
C:\Windows\SoftwareDistribution\Download\3fedcac79b66bcf0809496c7a29500cd\BIT8BB7.tmp deleted successfully.
C:\Windows\SoftwareDistribution\Download\744d0a29f79b4b4949620ac5107e09ad\BIT2819.tmp deleted successfully.
C:\Windows\SoftwareDistribution\Download\ab84c9ab9bce3d469fb4251d05dba4af\BIT8B48.tmp deleted successfully.
C:\Windows\Temp\avg-7062ce1f-a3d5-437b-a4cf-362915f6b33a.tmp deleted successfully.
C:\Windows\Temp\RGI406B.tmp deleted successfully.
C:\Windows\Temp\RGI406B.tmp-tmp deleted successfully.
C:\Windows\Temp\RGI5A90.tmp deleted successfully.
C:\Windows\Temp\RGI5A90.tmp-tmp deleted successfully.
C:\Windows\Temp\RGI81C.tmp deleted successfully.
C:\Windows\Temp\RGI81C.tmp-tmp deleted successfully.
C:\Windows\Temp\RGIC726.tmp deleted successfully.
C:\Windows\Temp\RGIC726.tmp-tmp deleted successfully.
C:\Windows\Temp\SEP384F.tmp deleted successfully.
C:\Windows\Temp\TS_732C.tmp deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Gabriela
->Flash cache emptied: 5021 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Gabriela
->Temp folder emptied: 6970086 bytes
->Temporary Internet Files folder emptied: 20728680 bytes
->FireFox cache emptied: 64870999 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 81105955 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 166,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.31.0 log created on 01032012_203438

Files\Folders moved on Reboot...
C:\Users\Gabriela\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\Windows\temp\TMP00000776A66EABE6B5F78209 not found!

Registry entries deleted on Reboot...

Re: omezený přístup na internet

Napsal: 03 led 2012 20:45
od chodnik74
Výborně :) U Avastu bych doporučil ten Autosandbox vypnout, otravné :D (Dodatečná ochrana-Autosandbox- Nastavení ;-) )

:arrow: Obrázek OTC
  • Spustíme,zmáčkneme CleanUp a potvrdíme YES :) Program uklidí a následně restartuje
:arrow: ObrázekT-Cleaner
  • Spustíme,zmáčkneme klávesu A a potvrdíme ENTER(některé antiviry mohou detekovat utilitu jako vir-jedá se o falešný poplach,proto IGNOROVAT nebo dočasně vypnout antivir )
  • po použití T-Cleaner smažte ;-)

:arrow: Obrázek TFC
  • Stáhneme a spustíme program
  • Klikneme na Start a potvrdíme OK
  • Program začne uklízet,poté restartuje pc
  • po použití program smažte



Údržba PC:

1)Čištění dočasných složek + neplatné registry
:arrow: ObrázekCcleaner
  • Stáhneme a nainstalujeme program
  • Spustíme program
  • ČISTIČ
    Windows zde necháme vše jak je (pokud používáme IE,tak odškrkneme jeho položky) a zaškrkneme položky Start Menu zástupci a Zástupci na ploše a odškrkneme volbu Zbytky souborů v paměti
    Aplikace - necháme jak je,ale pokud používáme nějaký prohlížeč (Google chrome,Firefox,Opera..) tak odškrkneme jeho položky
    >Stiskeneme tlačítko Analyzovat a poté Spustit Cleaner
  • Registry
    >Stiskneme tlačítko Hledej problémy,program začne hledat neplatné registry..podé zvolíme Opravit vybrané problémy..
    >Program se zeptá,zda chceme vytvořit zálohu registrů,zvolíme ano a uložíme si někde zálohu(kdyby byli po opravení registru s něčím problémy,tak zálohu obnovíme tak,že spustíme uloženou zálohu a potvrdíme ano),dále zvolíme Opravit všechny problémy a Zavřít
    >opakujte dokud nebude registr bez problémů
  • Program používáme 1x 14dní (záleží na používání pc,můžeme i jednou týdně)
2)Defragmentace disku
:arrow: ObrázekDefraggler
  • Stáhneme a nainstalujeme program
  • Spustíme program
  • Vybereme disk ( C:,D:..prostě který používáme)
  • Pokud je ve sloupci Fragmentace více než 5% dejte Defragmentovat
  • Proveďte se všemi používanými disky
  • Provádíme 1x za měsíc
3)Aktualizace programů
:arrow: ObrázekFileHippo.com Update Checker
  • Stáhneme a nainstalujeme program(Při instalaci odškrkneme volbu Run at Startup )
  • Spustíme program
  • Program vyhledá nainstalované programy v PC a zjistí dostupné aktualizace
  • Poté se vám otevře internetová stránka,kde budou nabídnuté aplikace k aktualizování
    >X Updates Detected..to jsou dostupné aktualizace..
    > klikneme na zelenou šipečku a stáhneme program,poté nainstalujeme jeho aktuální verzi
    > :!: X Beta Updates Detected..tyto aktualizace nestahujte,jedná se o betaverze,které jsou ve vývoji a jsou nestabilní :)
  • Provádíme 1x za 14 dní nebo jednou za měsíc
:arrow: Jak se chová PC :???: + nový RSIT

Re: omezený přístup na internet

Napsal: 03 led 2012 20:53
od MAT
Mooooooc díky, moc jste mi pomohl. Peníze na podporu fóra jako vždy pošlu, Vaše rady jsou k nezaplacení.

MAT

Re: omezený přístup na internet

Napsal: 03 led 2012 20:57
od chodnik74
I tak bych poprosil o výsledný log, aby bylo vše hezky čisté do posledního detailu ;) Za případnou podporu jménem týmu fora viry.cz děkuji :worship:

Re: omezený přístup na internet

Napsal: 03 led 2012 21:21
od MAT
Nedělal jsem jen tu pravidelnou údržbu - měl jsem?



Logfile of random's system information tool 1.09 (written by random/random)
Run by Gabriela at 2012-01-03 21:16:58
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 29 GB (30%) free of 98 GB
Total RAM: 3999 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:17:15, on 3.1.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\Gabriela.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [FLxHCIm64] "C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Intel(R) Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10297 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
C:\Windows\system32\WLANExt.exe 20075552
\??\C:\Windows\system32\conhost.exe "2080036785-470313903-1614478267-17839076531148967304766132389-392311045-800669162
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {E182BB21-B360-4CB5-9B91-83E721FE4AA6}
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
taskeng.exe {9CCFC795-F3CC-4CC6-B655-8B4BAD13A34A}
"C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe"
"C:\Program Files\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
taskeng.exe {A8F63E3D-F052-40F4-ACD4-961320C1B980}
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files\ASUS\ASUS Secure Delete\ADDEL.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
WLIDSvcM.exe 2604
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\igfxtray.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
ATKOSD.exe
KBFiltr.exe
WDC.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4592.12404300.359032193 "C:\Windows\system32\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.9.0.1 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 4592 "\\.\pipe\gecko-crash-server-pipe.4592" plugin
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe"
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Users\Gabriela\Desktop\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\Gabriela\AppData\Roaming\Mozilla\Firefox\Profiles\28i91e2l.default

prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\ZEON/PDF,version=2.0]
"Description"=
"Path"=C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
avg-secure-search.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Gabriela\AppData\Roaming\Mozilla\Firefox\Profiles\28i91e2l.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28 963064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 689040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-08-02 51872]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-12-21 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-11-28 963064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-11-28 809040]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-09-16 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-09-16 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-09-16 416024]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2011-10-18 2776880]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-08-25 12681320]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2011-08-02 961184]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [2011-08-02 798880]
"IntelTBRunOnce"=wscript.exe //b //nologo C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2011-10-19 3331312]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe [2011-07-29 737104]
"FLxHCIm64"=C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [2011-10-17 47616]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22 5716608]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2010-10-07 170624]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2011-09-09 2317312]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-11-01 59240]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-12-08 421736]
"Malwarebytes' Anti-Malware"=C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe [2011-12-24 460872]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-11-28 3744552]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
AsusVibeLauncher.lnk - C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-09-16 390144]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2012-01-03 21:16:58 ----D---- C:\rsit
2012-01-03 21:16:58 ----D---- C:\Program Files\trend micro
2012-01-03 16:36:03 ----A---- C:\Windows\system32\drivers\aswSP.sys
2012-01-03 16:36:03 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2012-01-03 16:36:02 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2012-01-03 16:36:02 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2012-01-03 16:36:02 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2012-01-03 16:36:02 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2012-01-03 16:36:02 ----A---- C:\Windows\system32\aswBoot.exe
2012-01-03 16:35:53 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2012-01-03 16:35:53 ----A---- C:\Windows\avastSS.scr
2012-01-03 16:35:35 ----D---- C:\ProgramData\AVAST Software
2012-01-03 16:35:35 ----D---- C:\Program Files\AVAST Software
2012-01-03 16:25:07 ----SHD---- C:\Config.Msi
2012-01-02 23:42:22 ----D---- C:\Program Files (x86)\SPW
2012-01-02 23:41:40 ----D---- C:\ProgramData\SPW
2012-01-02 21:13:59 ----A---- C:\PRIKAZ.TXT
2012-01-02 20:53:36 ----N---- C:\Windows\system32\MpSigStub.exe
2012-01-02 15:30:31 ----D---- C:\Users\Gabriela\AppData\Roaming\Malwarebytes
2012-01-02 15:30:24 ----D---- C:\ProgramData\Malwarebytes
2012-01-02 15:30:20 ----D---- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-02 15:30:20 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-01-01 21:27:26 ----D---- C:\Users\Gabriela\AppData\Roaming\Mozilla
2012-01-01 20:03:50 ----D---- C:\Users\Gabriela\AppData\Roaming\pdfforge
2012-01-01 20:03:43 ----A---- C:\Windows\system32\pdfcmnnt.dll
2012-01-01 20:03:39 ----D---- C:\Program Files (x86)\PDFCreator
2012-01-01 20:03:39 ----A---- C:\Windows\SYSWOW64\MSMPIDE.DLL
2012-01-01 19:15:48 ----A---- C:\Windows\system32\MRT.exe
2011-12-31 17:29:20 ----D---- C:\ProgramData\Hewlett-Packard
2011-12-31 17:04:01 ----N---- C:\bootsqm.dat
2011-12-31 13:06:26 ----D---- C:\ProgramData\IObit
2011-12-31 13:06:13 ----D---- C:\Users\Gabriela\AppData\Roaming\FreeSoftwareDownload
2011-12-31 13:05:49 ----D---- C:\Users\Gabriela\AppData\Roaming\IObit
2011-12-31 13:05:37 ----D---- C:\Program Files (x86)\IObit
2011-12-31 12:20:53 ----D---- C:\Windows\system32\appmgmt
2011-12-30 17:51:31 ----D---- C:\Users\Gabriela\AppData\Roaming\Rovio
2011-12-30 17:48:15 ----D---- C:\Users\Gabriela\AppData\Roaming\WinRAR
2011-12-30 10:36:34 ----D---- C:\Záloha 12.2011
2011-12-30 10:31:21 ----D---- C:\Windows\SYSWOW64\Wat
2011-12-30 10:31:21 ----D---- C:\Windows\system32\Wat
2011-12-30 01:33:46 ----A---- C:\Windows\system32\mshtmled.dll
2011-12-30 01:33:45 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-12-30 01:33:45 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-12-30 01:33:45 ----A---- C:\Windows\system32\iertutil.dll
2011-12-30 01:33:44 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-12-30 01:33:44 ----A---- C:\Windows\SYSWOW64\url.dll
2011-12-30 01:33:44 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-12-30 01:33:44 ----A---- C:\Windows\system32\urlmon.dll
2011-12-30 01:33:44 ----A---- C:\Windows\system32\url.dll
2011-12-30 01:33:44 ----A---- C:\Windows\system32\ieui.dll
2011-12-30 01:33:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-12-30 01:33:43 ----A---- C:\Windows\system32\wininet.dll
2011-12-30 01:33:43 ----A---- C:\Windows\system32\jsproxy.dll
2011-12-30 01:33:42 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-12-30 01:33:42 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-12-30 01:33:42 ----A---- C:\Windows\system32\jscript9.dll
2011-12-30 01:33:41 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-12-30 01:33:41 ----A---- C:\Windows\system32\jscript.dll
2011-12-30 01:33:40 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-12-30 01:33:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-12-30 01:33:38 ----A---- C:\Windows\system32\mshtml.dll
2011-12-30 01:33:37 ----A---- C:\Windows\system32\ieframe.dll
2011-12-29 10:22:47 ----A---- C:\Windows\system32\csrsrv.dll
2011-12-29 10:22:42 ----A---- C:\Windows\SYSWOW64\XpsPrint.dll
2011-12-29 10:22:42 ----A---- C:\Windows\system32\XpsPrint.dll
2011-12-29 10:22:38 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-12-29 10:22:28 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-12-29 10:22:28 ----A---- C:\Windows\system32\tzres.dll
2011-12-29 10:22:20 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2011-12-29 10:22:20 ----A---- C:\Windows\system32\psisdecd.dll
2011-12-29 10:19:18 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2011-12-29 10:19:18 ----A---- C:\Windows\system32\EncDec.dll
2011-12-29 10:19:15 ----A---- C:\Windows\system32\win32k.sys
2011-12-29 10:19:13 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-12-29 10:19:13 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2011-12-29 10:19:13 ----A---- C:\Windows\system32\oleaut32.dll
2011-12-29 10:19:13 ----A---- C:\Windows\system32\oleacc.dll
2011-12-29 09:38:26 ----HD---- C:\$AVG
2011-12-28 22:25:54 ----D---- C:\Program Files\Microsoft Office
2011-12-28 22:25:44 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2011-12-28 22:25:29 ----D---- C:\ProgramData\Microsoft Help
2011-12-28 22:25:23 ----RHD---- C:\MSOCache
2011-12-28 21:24:21 ----D---- C:\Users\Gabriela\AppData\Roaming\Apple Computer
2011-12-28 21:24:16 ----A---- C:\Windows\SYSWOW64\GEARAspi.dll
2011-12-28 21:24:16 ----A---- C:\Windows\system32\GEARAspi64.dll
2011-12-28 21:24:16 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2011-12-28 21:23:54 ----D---- C:\Program Files\iPod
2011-12-28 21:23:53 ----D---- C:\ProgramData\Apple Computer
2011-12-28 21:23:53 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-12-28 21:23:53 ----D---- C:\Program Files\iTunes
2011-12-28 21:23:53 ----D---- C:\Program Files (x86)\iTunes
2011-12-28 21:22:56 ----D---- C:\Program Files (x86)\Apple Software Update
2011-12-28 21:22:46 ----D---- C:\Program Files\Common Files\Apple
2011-12-28 21:22:33 ----D---- C:\Program Files\Bonjour
2011-12-28 21:22:33 ----D---- C:\Program Files (x86)\Bonjour
2011-12-28 21:22:25 ----D---- C:\ProgramData\Apple
2011-12-28 21:05:09 ----D---- C:\Users\Gabriela\AppData\Roaming\Skype
2011-12-28 21:05:00 ----RD---- C:\Program Files (x86)\Skype
2011-12-28 21:04:52 ----D---- C:\ProgramData\Skype
2011-12-28 20:54:23 ----D---- C:\Program Files (x86)\AVG
2011-12-28 20:46:42 ----HD---- C:\ProgramData\Common Files
2011-12-28 20:45:22 ----D---- C:\ProgramData\MFAData
2011-12-28 20:42:56 ----D---- C:\Users\Gabriela\AppData\Roaming\Zoner
2011-12-28 20:42:32 ----D---- C:\Program Files (x86)\Zoner
2011-12-28 20:40:06 ----D---- C:\Users\Gabriela\AppData\Roaming\FLEXnet
2011-12-28 20:40:05 ----D---- C:\Users\Gabriela\AppData\Roaming\Nuance
2011-12-28 20:40:04 ----D---- C:\Users\Gabriela\AppData\Roaming\Zeon
2011-12-28 20:35:08 ----D---- C:\Users\Gabriela\AppData\Roaming\ASUS WebStorage
2011-12-28 20:34:29 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-12-28 20:32:34 ----D---- C:\Users\Gabriela\AppData\Roaming\Macromedia
2011-12-28 20:31:26 ----D---- C:\Users\Gabriela\AppData\Roaming\Adobe
2011-12-28 20:28:36 ----D---- C:\Users\Gabriela\AppData\Roaming\Atheros
2011-12-28 20:27:22 ----D---- C:\Users\Gabriela\AppData\Roaming\Identities
2011-12-28 20:27:12 ----D---- C:\ProgramData\FolderView
2011-12-28 20:27:10 ----A---- C:\Windows\SYSWOW64\acovcnt.exe
2011-12-28 20:27:07 ----SD---- C:\Users\Gabriela\AppData\Roaming\Microsoft
2011-12-28 20:27:07 ----D---- C:\Users\Gabriela\AppData\Roaming\Media Center Programs
2011-12-09 10:37:30 ----D---- C:\eSupport
2011-12-09 10:36:23 ----A---- C:\Windows\AsToolCDVer.txt
2011-12-09 09:57:44 ----A---- C:\Pass.txt
2011-12-09 09:56:52 ----A---- C:\devlist.txt
2011-12-09 09:49:47 ----A---- C:\Windows\AsChkDev.txt
2011-12-09 09:48:46 ----D---- C:\Program Files\Intel
2011-12-09 09:48:35 ----A---- C:\Windows\SYSWOW64\ACEngSvr.exe
2011-12-09 09:47:43 ----A---- C:\Windows\system32\drivers\assd.sys
2011-12-09 09:47:42 ----D---- C:\Program Files\ASUS
2011-12-09 09:47:35 ----D---- C:\ProgramData\P4G
2011-12-09 09:47:35 ----D---- C:\Program Files\P4G
2011-12-09 09:47:17 ----D---- C:\ProgramData\USBChargerPlus
2011-12-09 09:47:16 ----D---- C:\ProgramData\Atheros
2011-12-09 09:46:26 ----A---- C:\Windows\system32\drivers\AiCharger.sys
2011-12-09 09:44:38 ----D---- C:\Program Files (x86)\Bluetooth Suite
2011-12-09 09:44:06 ----D---- C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation
2011-12-09 09:44:06 ----A---- C:\Windows\system32\drivers\athrx.sys
2011-12-09 09:44:06 ----A---- C:\Windows\system32\athrx.sys
2011-12-09 09:43:48 ----D---- C:\ProgramData\Qualcomm Atheros
2011-12-09 09:43:37 ----D---- C:\Program Files (x86)\ASIX Electronics Corporation
2011-12-09 09:43:32 ----D---- C:\Windows\SYSWOW64\sda
2011-12-09 09:43:30 ----N---- C:\Windows\system32\drivers\diskperf64.sys
2011-12-09 09:43:30 ----A---- C:\Windows\SYSWOW64\RtsUVStoricon.dll
2011-12-09 09:43:30 ----A---- C:\Windows\system32\drivers\rtsuvstor.sys
2011-12-09 09:43:18 ----D---- C:\Windows\SYSWOW64\RTCOM
2011-12-09 09:43:18 ----D---- C:\Program Files\Realtek
2011-12-09 09:43:05 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\WavesGUILib.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\tosade.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\tepeqapo64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\tadefxapo264.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\tadefxapo.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SRSWOW64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SRSTSX64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SRSTSH64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SRSHP64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SFSS_APO.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SFNHK64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SFCOM64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\SFAPO64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RtPgEx64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RtkCfg64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RtkAPO64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RtkApi64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RTEEP64A.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RTEEL64A.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RTEEG64A.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RTEED64A.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RTCOM64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RP3DHT64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RP3DAA64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RCoRes64.dat
2011-12-09 09:43:05 ----A---- C:\Windows\system32\RCoInst64.dll
2011-12-09 09:43:05 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2011-12-09 09:43:04 ----A---- C:\Windows\system32\R4EEP64A.dll
2011-12-09 09:43:04 ----A---- C:\Windows\system32\R4EEL64A.dll
2011-12-09 09:43:04 ----A---- C:\Windows\system32\R4EEG64A.dll
2011-12-09 09:43:04 ----A---- C:\Windows\system32\R4EED64A.dll
2011-12-09 09:43:04 ----A---- C:\Windows\system32\R4EEA64A.dll
2011-12-09 09:43:04 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\MaxxAudioRealtek.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\MaxxAudioEQ.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\KAAPORT64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\FMAPO64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2011-12-09 09:43:02 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2011-12-09 09:43:01 ----N---- C:\Windows\RtlExUpd.dll
2011-12-09 09:43:01 ----HD---- C:\Program Files (x86)\Temp
2011-12-09 09:43:01 ----D---- C:\Program Files (x86)\Realtek
2011-12-09 09:43:01 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2011-12-09 09:43:01 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2011-12-09 09:43:01 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2011-12-09 09:43:01 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2011-12-09 09:43:01 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2011-12-09 09:43:01 ----A---- C:\Windows\system32\AERTAR64.dll
2011-12-09 09:43:01 ----A---- C:\Windows\system32\AERTAC64.dll
2011-12-09 09:42:58 ----D---- C:\ProgramData\Intel
2011-12-09 09:41:57 ----D---- C:\Program Files\Elantech
2011-12-09 09:41:52 ----SHD---- C:\Windows\SYSWOW64\AI_RecycleBin
2011-12-09 09:41:47 ----D---- C:\Program Files\Fresco Logic
2011-12-09 09:41:40 ----D---- C:\Program Files\Common Files\Intel
2011-12-09 09:41:13 ----A---- C:\Windows\system32\drivers\IntelMEFWVer.dll
2011-12-09 09:41:11 ----A---- C:\Windows\SYSWOW64\log.txt
2011-12-09 09:41:07 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-12-09 09:41:07 ----A---- C:\Windows\system32\drivers\HECIx64.sys
2011-12-09 09:40:53 ----D---- C:\Program Files (x86)\Intel
2011-12-09 09:40:53 ----A---- C:\Windows\SYSWOW64\CSVer.dll
2011-12-09 09:40:50 ----D---- C:\Intel
2011-12-09 09:39:59 ----A---- C:\Windows\SYSWOW64\ifsutil.dll
2011-12-09 09:39:59 ----A---- C:\Windows\system32\ifsutil.dll
2011-12-09 09:39:45 ----A---- C:\Windows\system32\drivers\ndis.sys
2011-12-09 09:39:42 ----D---- C:\Windows\SoftwareDistribution
2011-12-09 09:38:15 ----D---- C:\Windows\CSC
2011-12-09 09:38:05 ----SHD---- C:\System Volume Information
2011-12-09 09:38:05 ----ASH---- C:\pagefile.sys
2011-12-09 09:38:05 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2012-01-03 21:16:58 ----RD---- C:\Program Files
2012-01-03 21:15:07 ----D---- C:\Windows\Temp
2012-01-03 21:14:33 ----D---- C:\Windows\system32\config
2012-01-03 21:14:32 ----D---- C:\Windows\system32\Tasks
2012-01-03 21:13:34 ----D---- C:\Windows\System32
2012-01-03 21:13:34 ----D---- C:\Windows\inf
2012-01-03 21:13:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-03 20:35:52 ----D---- C:\Windows\system32\drivers\etc
2012-01-03 16:37:53 ----HD---- C:\ProgramData
2012-01-03 16:36:03 ----D---- C:\Windows\system32\drivers
2012-01-03 16:36:02 ----D---- C:\Windows\SysWOW64
2012-01-03 16:36:00 ----SHD---- C:\Windows\Installer
2012-01-03 16:35:53 ----D---- C:\Windows
2012-01-03 16:26:26 ----D---- C:\Windows\SYSWOW64\drivers
2012-01-02 23:42:22 ----RD---- C:\Program Files (x86)
2012-01-02 22:40:21 ----D---- C:\Windows\system32\catroot
2012-01-02 22:40:19 ----D---- C:\Windows\system32\DriverStore
2012-01-02 22:34:49 ----D---- C:\Windows\Logs
2012-01-02 15:20:55 ----SD---- C:\ProgramData\Microsoft
2012-01-02 15:20:55 ----D---- C:\Program Files (x86)\Microsoft
2012-01-02 15:18:30 ----D---- C:\ProgramData\Trend Micro
2012-01-01 19:15:54 ----D---- C:\Windows\debug
2011-12-31 22:15:11 ----D---- C:\Windows\system32\drivers\UMDF
2011-12-31 18:28:28 ----D---- C:\Windows\system32\NDF
2011-12-31 13:36:21 ----D---- C:\Windows\winsxs
2011-12-31 13:33:31 ----D---- C:\Windows\system32\catroot2
2011-12-31 13:09:49 ----SHD---- C:\Boot
2011-12-31 12:12:38 ----D---- C:\Windows\Prefetch
2011-12-31 12:04:50 ----D---- C:\Windows\rescache
2011-12-31 12:03:50 ----D---- C:\Windows\Tasks
2011-12-31 12:03:50 ----D---- C:\Windows\system32\wfp
2011-12-31 12:03:48 ----D---- C:\Windows\system32\wbem
2011-12-31 11:55:29 ----D---- C:\Windows\system32\CodeIntegrity
2011-12-31 11:54:49 ----D---- C:\Windows\en-US
2011-12-31 11:54:16 ----D---- C:\Windows\system32\en
2011-12-31 11:54:03 ----D---- C:\Windows\SYSWOW64\en
2011-12-31 11:54:03 ----D---- C:\Windows\SYSWOW64\drivers\en-US
2011-12-31 11:49:45 ----D---- C:\Windows\registration
2011-12-31 11:42:32 ----D---- C:\Windows\SYSWOW64\migration
2011-12-31 11:42:31 ----D---- C:\Windows\system32\migration
2011-12-31 11:41:50 ----D---- C:\Windows\servicing
2011-12-31 11:41:48 ----D---- C:\Windows\ehome
2011-12-31 11:41:43 ----D---- C:\Program Files\Windows Sidebar
2011-12-31 11:41:43 ----D---- C:\Program Files\Common Files\System
2011-12-31 11:41:43 ----D---- C:\Program Files (x86)\Windows Sidebar
2011-12-30 20:01:52 ----D---- C:\Windows\system32\wdi
2011-12-30 19:59:19 ----D---- C:\Program Files\Windows Media Player
2011-12-30 19:59:19 ----D---- C:\Program Files\Windows Defender
2011-12-30 19:59:19 ----D---- C:\Program Files (x86)\Windows Mail
2011-12-30 19:59:18 ----D---- C:\Program Files (x86)\Windows Media Player
2011-12-30 19:59:17 ----D---- C:\Windows\SYSWOW64\winrm
2011-12-30 19:59:17 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS
2011-12-30 19:59:17 ----D---- C:\Windows\SYSWOW64\slmgr
2011-12-30 19:59:17 ----D---- C:\Program Files (x86)\Windows Defender
2011-12-30 19:59:14 ----D---- C:\Windows\SYSWOW64\en-US
2011-12-30 19:59:06 ----D---- C:\Windows\SYSWOW64\Printing_Admin_Scripts
2011-12-30 19:59:06 ----D---- C:\Windows\SYSWOW64\DriverStore
2011-12-30 19:59:06 ----D---- C:\Windows\SYSWOW64\Dism
2011-12-30 19:59:06 ----D---- C:\Windows\sr-Latn-CS
2011-12-30 19:59:04 ----D---- C:\Windows\system32\winrm
2011-12-30 19:59:04 ----D---- C:\Windows\system32\sysprep
2011-12-30 19:59:04 ----D---- C:\Windows\system32\sr-Latn-CS
2011-12-30 19:59:04 ----D---- C:\Windows\system32\slmgr
2011-12-30 19:59:04 ----D---- C:\Windows\system32\oobe
2011-12-30 19:59:04 ----D---- C:\Windows\system32\Boot
2011-12-30 19:58:57 ----D---- C:\Windows\system32\en-US
2011-12-30 19:58:57 ----D---- C:\Windows\system32\drivers\en-US
2011-12-30 19:58:53 ----D---- C:\Windows\system32\Dism
2011-12-30 19:58:50 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2011-12-30 19:58:38 ----D---- C:\Program Files\Windows Photo Viewer
2011-12-30 19:58:38 ----D---- C:\Program Files\Windows Mail
2011-12-30 19:58:38 ----D---- C:\Program Files\Windows Journal
2011-12-30 19:58:37 ----D---- C:\Windows\SYSWOW64\sl-SI
2011-12-30 19:58:37 ----D---- C:\Windows\SYSWOW64\migwiz
2011-12-30 19:58:37 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-12-30 19:58:33 ----D---- C:\Windows\SYSWOW64\WCN
2011-12-30 19:58:33 ----D---- C:\Windows\system32\migwiz
2011-12-30 19:58:32 ----D---- C:\Windows\system32\sl-SI
2011-12-30 19:58:26 ----D---- C:\Windows\system32\WCN
2011-12-30 19:58:16 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-12-30 19:58:11 ----D---- C:\Windows\system32\sk-SK
2011-12-30 19:57:55 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-12-30 19:57:48 ----D---- C:\Windows\system32\ro-RO
2011-12-30 19:57:23 ----D---- C:\Windows\SYSWOW64\XPSViewer
2011-12-30 19:57:23 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-12-30 19:57:23 ----D---- C:\Windows\SYSWOW64\MUI
2011-12-30 19:57:14 ----D---- C:\Windows\SYSWOW64\com
2011-12-30 19:57:14 ----D---- C:\Windows\IME
2011-12-30 19:57:11 ----D---- C:\Windows\system32\MUI
2011-12-30 19:57:09 ----D---- C:\Windows\system32\pl-PL
2011-12-30 19:56:59 ----D---- C:\Windows\system32\com
2011-12-30 19:56:59 ----D---- C:\Windows\AppPatch
2011-12-30 19:56:37 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-12-30 19:56:20 ----D---- C:\Windows\system32\hu-HU
2011-12-30 19:55:50 ----D---- C:\Windows\SYSWOW64\lv-LV
2011-12-30 19:55:45 ----D---- C:\Windows\system32\lv-LV
2011-12-30 19:55:28 ----D---- C:\Windows\SYSWOW64\lt-LT
2011-12-30 19:55:23 ----D---- C:\Windows\system32\lt-LT
2011-12-30 19:55:05 ----D---- C:\Windows\SYSWOW64\hr-HR
2011-12-30 19:55:00 ----D---- C:\Windows\system32\hr-HR
2011-12-30 19:54:43 ----D---- C:\Windows\SYSWOW64\et-EE
2011-12-30 19:54:37 ----D---- C:\Windows\system32\et-EE
2011-12-30 19:54:17 ----D---- C:\Windows\SYSWOW64\bg-BG
2011-12-30 19:54:11 ----D---- C:\Windows\system32\bg-BG
2011-12-30 17:10:12 ----D---- C:\Program Files\DVD Maker
2011-12-30 15:08:39 ----RSD---- C:\Windows\assembly
2011-12-30 15:08:39 ----D---- C:\Windows\Microsoft.NET
2011-12-30 10:31:20 ----D---- C:\Program Files\Internet Explorer
2011-12-30 10:31:20 ----D---- C:\Program Files (x86)\Internet Explorer
2011-12-30 02:01:48 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-12-30 01:58:05 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-12-30 01:57:14 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-12-30 01:20:27 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-12-30 01:20:27 ----D---- C:\Windows\system32\cs-CZ
2011-12-30 00:03:54 ----D---- C:\Program Files (x86)\ASUS
2011-12-29 09:52:02 ----D---- C:\Windows\system32\LogFiles
2011-12-28 22:28:30 ----RSD---- C:\Windows\Fonts
2011-12-28 22:28:07 ----D---- C:\Program Files (x86)\Common Files
2011-12-28 22:28:01 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-12-28 22:28:01 ----D---- C:\Program Files (x86)\Microsoft Office
2011-12-28 22:25:52 ----D---- C:\Windows\ShellNew
2011-12-28 21:24:16 ----DC---- C:\Windows\system32\DRVSTORE
2011-12-28 21:22:46 ----D---- C:\Program Files\Common Files
2011-12-28 20:53:40 ----D---- C:\Windows\system32\restore
2011-12-28 20:40:05 ----D---- C:\ProgramData\Nuance
2011-12-28 20:30:12 ----D---- C:\ProgramData\ChangeFolderView
2011-12-28 20:27:20 ----SHD---- C:\$Recycle.Bin
2011-12-28 20:27:07 ----RD---- C:\Users
2011-12-28 20:26:29 ----SHD---- C:\Recovery
2011-12-09 11:43:56 ----D---- C:\Windows\Log
2011-12-09 10:37:39 ----D---- C:\Windows\ASUS
2011-12-09 09:57:02 ----D---- C:\Windows\Panther

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 assd;assd; C:\Windows\system32\drivers\assd.sys [2010-04-28 27264]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-11-28 42328]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-11-28 591192]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-11-28 304472]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-11-28 58712]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-11-28 24408]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-11-28 66904]
R2 TurboB;Turbo Boost UI Monitor driver; C:\Windows\system32\DRIVERS\TurboB.sys [2010-11-30 16120]
R3 AiCharger;ASUS Charger Driver; C:\Windows\system32\DRIVERS\AiCharger.sys [2011-02-26 16768]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2011-08-02 36000]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-11-23 2796544]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2011-08-02 330912]
R3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2011-08-02 110240]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2011-08-02 30368]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2011-08-02 167584]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2011-08-02 68256]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2011-08-02 280992]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2011-08-02 511136]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-10-18 80384]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2011-10-18 198448]
R3 FLxHCIc;Fresco Logic xHCI (USB3) Device Driver; C:\Windows\system32\DRIVERS\FLxHCIc.sys [2011-10-17 202496]
R3 FLxHCIh;Fresco Logic xHCI (USB3) Hub Device Driver; C:\Windows\system32\DRIVERS\FLxHCIh.sys [2011-10-17 69888]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-09-16 12289472]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2011-08-26 3064936]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2011-09-16 317440]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2011-12-10 23152]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2011-03-15 311400]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2011-10-18 552960]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-20 71168]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
S3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 34152]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-06-10 57344]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2011-08-02 51712]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-23 154168]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-24 55144]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2009-06-16 84536]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe [2011-09-29 92800]
R2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-08-02 146592]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2011-08-02 103584]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2009-12-15 96896]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-11-28 44768]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-12-08 934760]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-19 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0; C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-30 149504]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-12-30 1255736]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

-----------------EOF-----------------

Re: omezený přístup na internet

Napsal: 03 led 2012 21:38
od chodnik74
Vše vypadá fajn, ale i tak údržbu vřele mohu jen doporučit ;-) Mohu pro vás v tuto chvíli ještě něco udělat? :oops:

Re: omezený přístup na internet

Napsal: 03 led 2012 21:42
od MAT
Doufám že vše již bude OK, moc děkuji za cenné rady.

Re: omezený přístup na internet

Napsal: 03 led 2012 21:47
od chodnik74
Rádo se stalo :) Dobrou noc přeji...