Stránka 2 z 2

Re: Preventivna kontrola

Napsal: 03 bře 2013 09:20
od skaza25
Logfile of random's system information tool 1.09 (written by random/random)
Run by jurtan at 2013-03-03 08:19:53
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 22 GB (32%) free of 70 GB
Total RAM: 2815 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 08:19:58, on 03/03/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16464)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\trend micro\jurtan.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [AgentMonitor] C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.4.1.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: WMI_Hook_Service - MICRO-STAR INT'L,.LTD. - C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9062 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\windows\system32\svchost.exe -k RPCSS
"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe"
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\windows\system32\nvvsvc.exe -session -first
/QuitInfo:0000000000000424;0000000000000428; /AddRef;
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe"
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\System32\svchost.exe -k secsvcs
"C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe"
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\wbem\unsecapp.exe -Embedding
"C:\windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-e03a235f-ee88-4cf3-bc00-695f2c7eed79 -SystemEventPortName:HostProcess-adabd466-c11d-4ef6-ac80-e3c78bf69112 -IoCancelEventPortName:HostProcess-b1dd3c25-9327-4a74-81dc-015e692f8be8 -NonStateChangingEventPortName:HostProcess-2314020d-8193-4c38-b9ea-8f145df408af -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7cdf7482-bc99-46c8-aa8f-237533718ad1 -DeviceGroupId:WpdFsGroup
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\windows\system32\SearchIndexer.exe /Embedding
"taskhost.exe"
/QuitInfo:000000000000076C;0000000000000784; /AddRef;
/QuitInfo:0000000000000708;0000000000000790;
/loadhooks /Parent:0000000000000CBC
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe" -servicelaunch=true
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\msi\WMIHookBtnFn\HookKey.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE" /tsr
"C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe"
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" -quickstart
ArcCon.ac 131164 0
"C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe" "-quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\OpenOffice.org 3\\program"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet F4200 series#1355063382" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
"C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe"
"D:\Downloads\RSITx64(1).exe"
C:\windows\system32\wbem\wmiprvse.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\jurtan\AppData\Roaming\Mozilla\Firefox\Profiles\ubkt0ulo.default

prefs.js - "browser.search.useDBForOrder" - "false"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.168 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0]
"Description"=Virtual Earth 3D
"Path"=C:\Program Files (x86)\Virtual Earth 3D\

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.6.602.168 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_11_6_602_168.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0]
"Description"=
"Path"=C:\Program Files (x86)\Virtual Earth 3D\

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18 66280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2012-10-30 1502288]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-09-30 8123936]
"HookKey"=C:\Program Files\msi\WMIHookBtnFn\HookKey.exe [2010-01-06 24576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-11-06 3673728]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-01-08 18705664]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ArcSoft Connection Service"=C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2010-10-27 207424]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]
"AgentMonitor"=C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [2012-11-05 377800]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Users\jurtan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
OpenOffice.org 3.4.1.lnk - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2013-02-27 10:06:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-02-27 00:27:35 ----A---- C:\windows\SYSWOW64\msmpeg2vdec.dll
2013-02-27 00:27:34 ----A---- C:\windows\SYSWOW64\UIAnimation.dll
2013-02-27 00:27:34 ----A---- C:\windows\system32\UIAnimation.dll
2013-02-27 00:27:34 ----A---- C:\windows\system32\msmpeg2vdec.dll
2013-02-27 00:27:27 ----A---- C:\windows\SYSWOW64\WMPhoto.dll
2013-02-27 00:27:27 ----A---- C:\windows\system32\WMPhoto.dll
2013-02-27 00:27:19 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-02-27 00:27:19 ----AH---- C:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-02-27 00:27:19 ----A---- C:\windows\SYSWOW64\d3d10_1.dll
2013-02-27 00:27:19 ----A---- C:\windows\system32\d3d10_1.dll
2013-02-27 00:27:18 ----A---- C:\windows\SYSWOW64\d3d10warp.dll
2013-02-27 00:27:18 ----A---- C:\windows\system32\XpsGdiConverter.dll
2013-02-27 00:27:18 ----A---- C:\windows\system32\d3d10warp.dll
2013-02-27 00:27:17 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\SYSWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-02-27 00:27:17 ----AH---- C:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-02-27 00:27:17 ----A---- C:\windows\SYSWOW64\XpsGdiConverter.dll
2013-02-27 00:27:17 ----A---- C:\windows\SYSWOW64\dxgi.dll
2013-02-27 00:27:17 ----A---- C:\windows\system32\dxgi.dll
2013-02-27 00:27:16 ----A---- C:\windows\SYSWOW64\d3d11.dll
2013-02-27 00:27:16 ----A---- C:\windows\SYSWOW64\d3d10level9.dll
2013-02-27 00:27:16 ----A---- C:\windows\SYSWOW64\d3d10core.dll
2013-02-27 00:27:16 ----A---- C:\windows\SYSWOW64\d3d10_1core.dll
2013-02-27 00:27:16 ----A---- C:\windows\system32\d3d11.dll
2013-02-27 00:27:16 ----A---- C:\windows\system32\d3d10level9.dll
2013-02-27 00:27:16 ----A---- C:\windows\system32\d3d10core.dll
2013-02-27 00:27:16 ----A---- C:\windows\system32\d3d10_1core.dll
2013-02-27 00:27:15 ----A---- C:\windows\SYSWOW64\XpsPrint.dll
2013-02-27 00:27:15 ----A---- C:\windows\SYSWOW64\DWrite.dll
2013-02-27 00:27:15 ----A---- C:\windows\SYSWOW64\d3d10.dll
2013-02-27 00:27:15 ----A---- C:\windows\system32\XpsPrint.dll
2013-02-27 00:27:15 ----A---- C:\windows\system32\d3d10.dll
2013-02-27 00:27:14 ----A---- C:\windows\SYSWOW64\WindowsCodecsExt.dll
2013-02-27 00:27:14 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2013-02-27 00:27:14 ----A---- C:\windows\system32\WindowsCodecsExt.dll
2013-02-27 00:27:14 ----A---- C:\windows\system32\FntCache.dll
2013-02-27 00:27:14 ----A---- C:\windows\system32\DWrite.dll
2013-02-27 00:27:13 ----A---- C:\windows\system32\WindowsCodecs.dll
2013-02-27 00:27:13 ----A---- C:\windows\system32\d2d1.dll
2013-02-27 00:27:12 ----A---- C:\windows\SYSWOW64\d2d1.dll
2013-02-26 00:24:49 ----A---- C:\AdwCleaner[S1].txt
2013-02-24 19:34:29 ----A---- C:\AdwCleaner[R1].txt
2013-02-14 01:39:01 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2013-02-14 01:39:01 ----A---- C:\windows\system32\mshtmled.dll
2013-02-14 01:39:00 ----A---- C:\windows\SYSWOW64\vbscript.dll
2013-02-14 01:39:00 ----A---- C:\windows\SYSWOW64\ieui.dll
2013-02-14 01:39:00 ----A---- C:\windows\system32\ieui.dll
2013-02-14 01:38:59 ----A---- C:\windows\SYSWOW64\url.dll
2013-02-14 01:38:59 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2013-02-14 01:38:59 ----A---- C:\windows\system32\url.dll
2013-02-14 01:38:59 ----A---- C:\windows\system32\ieUnatt.exe
2013-02-14 01:38:58 ----A---- C:\windows\SYSWOW64\urlmon.dll
2013-02-14 01:38:58 ----A---- C:\windows\system32\urlmon.dll
2013-02-14 01:38:57 ----A---- C:\windows\system32\jscript9.dll
2013-02-14 01:38:56 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2013-02-14 01:38:56 ----A---- C:\windows\system32\msfeeds.dll
2013-02-14 01:38:55 ----A---- C:\windows\SYSWOW64\wininet.dll
2013-02-14 01:38:54 ----A---- C:\windows\SYSWOW64\jscript9.dll
2013-02-14 01:38:54 ----A---- C:\windows\system32\wininet.dll
2013-02-14 01:38:54 ----A---- C:\windows\system32\jsproxy.dll
2013-02-14 01:38:53 ----A---- C:\windows\SYSWOW64\jscript.dll
2013-02-14 01:38:53 ----A---- C:\windows\system32\vbscript.dll
2013-02-14 01:38:53 ----A---- C:\windows\system32\jscript.dll
2013-02-14 01:38:52 ----A---- C:\windows\SYSWOW64\iertutil.dll
2013-02-14 01:38:52 ----A---- C:\windows\system32\iertutil.dll
2013-02-14 01:38:51 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2013-02-14 01:38:50 ----A---- C:\windows\SYSWOW64\mshtml.dll
2013-02-14 01:38:47 ----A---- C:\windows\system32\mshtml.dll
2013-02-14 01:38:45 ----A---- C:\windows\system32\ieframe.dll
2013-02-14 01:38:44 ----A---- C:\windows\SYSWOW64\ieframe.dll
2013-02-13 22:52:50 ----A---- C:\windows\system32\ntoskrnl.exe
2013-02-13 22:52:48 ----A---- C:\windows\SYSWOW64\ntkrnlpa.exe
2013-02-13 22:52:47 ----A---- C:\windows\SYSWOW64\ntoskrnl.exe
2013-02-13 22:52:37 ----A---- C:\windows\system32\win32k.sys
2013-02-13 22:52:32 ----A---- C:\windows\system32\winsrv.dll
2013-02-13 22:52:31 ----A---- C:\windows\SYSWOW64\setup16.exe
2013-02-13 22:52:30 ----A---- C:\windows\SYSWOW64\wow32.dll
2013-02-13 22:52:30 ----A---- C:\windows\SYSWOW64\ntvdm64.dll
2013-02-13 22:52:30 ----A---- C:\windows\SYSWOW64\instnm.exe
2013-02-13 22:52:28 ----A---- C:\windows\SYSWOW64\user.exe
2013-02-13 22:52:23 ----A---- C:\windows\system32\drivers\tcpip.sys
2013-02-13 22:52:22 ----A---- C:\windows\system32\drivers\FWPKCLNT.SYS

======List of files/folders modified in the last 1 month======

2013-03-03 08:19:58 ----D---- C:\windows\Prefetch
2013-03-03 08:19:56 ----D---- C:\windows\Temp
2013-03-03 08:19:56 ----D---- C:\Program Files\trend micro
2013-03-03 08:06:05 ----D---- C:\Users\jurtan\AppData\Roaming\Skype
2013-03-03 08:05:56 ----SHD---- C:\windows\Installer
2013-03-03 08:05:51 ----D---- C:\windows\system32\config
2013-03-03 08:01:51 ----D---- C:\ProgramData\NVIDIA
2013-02-27 18:35:26 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-02-27 13:17:08 ----RD---- C:\Program Files (x86)
2013-02-27 11:31:08 ----D---- C:\windows\rescache
2013-02-27 05:32:33 ----D---- C:\windows\Tasks
2013-02-27 05:32:33 ----D---- C:\windows\system32\Tasks
2013-02-27 05:32:21 ----D---- C:\windows\system32\drivers\etc
2013-02-27 05:21:56 ----D---- C:\windows\winsxs
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\zh-HK
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\pt-PT
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\pt-BR
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\pl-PL
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\nl-NL
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\ko-KR
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\it-IT
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\hu-HU
2013-02-27 05:20:30 ----D---- C:\windows\SYSWOW64\el-GR
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\zh-TW
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\zh-CN
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\tr-TR
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\sv-SE
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\ru-RU
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\nb-NO
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\ja-JP
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\fr-FR
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\fi-FI
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\es-ES
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\en-US
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\de-DE
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\da-DK
2013-02-27 05:20:29 ----D---- C:\windows\SYSWOW64\cs-CZ
2013-02-27 05:20:29 ----D---- C:\windows\SysWOW64
2013-02-27 05:20:28 ----D---- C:\windows\system32\zh-HK
2013-02-27 05:20:28 ----D---- C:\windows\system32\pt-PT
2013-02-27 05:20:28 ----D---- C:\windows\system32\pt-BR
2013-02-27 05:20:28 ----D---- C:\windows\system32\pl-PL
2013-02-27 05:20:28 ----D---- C:\windows\system32\nl-NL
2013-02-27 05:20:28 ----D---- C:\windows\system32\ko-KR
2013-02-27 05:20:28 ----D---- C:\windows\system32\it-IT
2013-02-27 05:20:28 ----D---- C:\windows\system32\hu-HU
2013-02-27 05:20:28 ----D---- C:\windows\system32\fr-FR
2013-02-27 05:20:28 ----D---- C:\windows\system32\el-GR
2013-02-27 05:20:27 ----D---- C:\windows\system32\zh-TW
2013-02-27 05:20:27 ----D---- C:\windows\system32\zh-CN
2013-02-27 05:20:27 ----D---- C:\windows\system32\tr-TR
2013-02-27 05:20:27 ----D---- C:\windows\system32\sv-SE
2013-02-27 05:20:27 ----D---- C:\windows\system32\ru-RU
2013-02-27 05:20:27 ----D---- C:\windows\system32\nb-NO
2013-02-27 05:20:27 ----D---- C:\windows\system32\ja-JP
2013-02-27 05:20:27 ----D---- C:\windows\system32\fi-FI
2013-02-27 05:20:27 ----D---- C:\windows\system32\es-ES
2013-02-27 05:20:27 ----D---- C:\windows\system32\en-US
2013-02-27 05:20:27 ----D---- C:\windows\system32\de-DE
2013-02-27 05:20:27 ----D---- C:\windows\system32\da-DK
2013-02-27 05:20:27 ----D---- C:\windows\system32\cs-CZ
2013-02-27 05:20:27 ----D---- C:\windows\System32
2013-02-27 00:28:46 ----D---- C:\windows\system32\catroot
2013-02-27 00:28:45 ----D---- C:\windows\system32\catroot2
2013-02-27 00:27:07 ----SHD---- C:\System Volume Information
2013-02-27 00:19:42 ----D---- C:\windows\system32\drivers
2013-02-26 00:24:53 ----D---- C:\ProgramData
2013-02-25 05:49:19 ----D---- C:\ProgramData\Adobe
2013-02-25 05:49:06 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2013-02-23 15:42:31 ----HD---- C:\Config.Msi
2013-02-23 09:33:21 ----D---- C:\windows\system32\wdi
2013-02-23 00:19:03 ----D---- C:\windows\system32\wfp
2013-02-23 00:19:03 ----D---- C:\windows\system32\DriverStore
2013-02-23 00:19:03 ----D---- C:\windows\system32\CodeIntegrity
2013-02-23 00:19:03 ----D---- C:\windows\AppCompat
2013-02-23 00:19:03 ----D---- C:\Windows
2013-02-23 00:19:03 ----D---- C:\Users\jurtan\AppData\Roaming\LangSoft
2013-02-23 00:19:03 ----D---- C:\Program Files (x86)\Internet Explorer
2013-02-23 00:18:42 ----D---- C:\windows\system32\wbem
2013-02-23 00:18:42 ----D---- C:\windows\registration
2013-02-23 00:18:37 ----D---- C:\Users\jurtan\AppData\Roaming\ArcSoft
2013-02-23 00:15:06 ----D---- C:\windows\system32\LogFiles
2013-02-16 17:32:09 ----D---- C:\windows\inf
2013-02-16 17:32:09 ----A---- C:\windows\system32\PerfStringBackup.INI
2013-02-14 16:36:16 ----RSD---- C:\windows\assembly
2013-02-14 16:36:16 ----D---- C:\windows\Microsoft.NET
2013-02-14 08:41:31 ----D---- C:\windows\SYSWOW64\migration
2013-02-14 08:41:31 ----D---- C:\windows\AppPatch
2013-02-14 08:41:30 ----D---- C:\windows\system32\migration
2013-02-14 08:41:30 ----D---- C:\Program Files\Internet Explorer
2013-02-14 01:48:46 ----D---- C:\ProgramData\Microsoft Help
2013-02-14 01:45:30 ----A---- C:\windows\system32\MRT.exe
2013-02-04 21:49:37 ----D---- C:\windows\system32\NDF

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 nvamacpi;NVIDIA Away Mode System; C:\windows\system32\DRIVERS\NVAMACPI.sys [2009-07-17 28192]
R0 nvstor64;nvstor64; C:\windows\system32\DRIVERS\nvstor64.sys [2009-08-05 241696]
R0 RapportKE64;RapportKE64; C:\windows\System32\Drivers\RapportKE64.sys [2013-02-06 101688]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; C:\windows\System32\Drivers\aswrdr2.sys [2012-10-15 54072]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2012-10-30 984144]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2012-10-30 370288]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2012-10-30 59728]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-11-28 283200]
R1 RapportCerberus_43926;RapportCerberus_43926; \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys [2012-10-19 505720]
R1 RapportEI64;RapportEI64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2013-02-06 55096]
R1 RapportPG64;RapportPG64; \??\C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2013-02-06 297240]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2012-10-30 25232]
R2 aswMonFlt;aswMonFlt; \??\C:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2009-05-26 19968]
R3 enecir;ENE CIR Receiver; C:\windows\system32\DRIVERS\enecir.sys [2009-06-29 70656]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2009-09-30 2005024]
R3 nvsmu;nvsmu; C:\windows\system32\DRIVERS\nvsmu.sys [2009-06-29 28704]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2009-11-11 231968]
R3 RTL8167;Realtek 8167 NT Driver; C:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-21 239616]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver; C:\windows\system32\DRIVERS\rtl8192se.sys [2009-10-02 946688]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 Dot4;MS IEEE-1284.4 Driver; C:\windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 enecirhid;ENE CIR HID Receiver; C:\windows\system32\DRIVERS\enecirhid.sys [2009-05-20 14848]
S3 enecirhidma;ENE CIR HIDmini Filter; C:\windows\system32\DRIVERS\enecirhidma.sys [2008-04-25 6656]
S3 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;USB Scanner Driver; C:\windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\windows\system32\svchost.exe [2009-07-14 27136]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 nvsvc;NVIDIA Display Driver Service; C:\windows\system32\nvvsvc.exe [2012-10-02 891240]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-06-22 625816]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\windows\System32\svchost.exe [2009-07-14 27136]
R2 RapportMgmtService;Rapport Management Service; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2013-02-06 976728]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-15 226656]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
R2 WMI_Hook_Service;WMI_Hook_Service; C:\Program Files\msi\WMIHookBtnFn\WMI_Hook_Service.exe [2010-01-07 105472]
R3 hpqcxs08;hpqcxs08; C:\windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-08-30 1258856]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2012-09-13 647680]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-02-27 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2012-09-14 1255736]

-----------------EOF-----------------

Re: Preventivna kontrola

Napsal: 03 bře 2013 09:46
od Márty84
:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Najdete tento soubor C:\Program Files\trend micro\jurtan.exe , kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Kliknete na Main menu a na Do a system scan only
U techto radku dejte vlevo zatrzitko

Kód: Vybrat vše

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
Kliknete na nápis Fix checked a potvrdte



:!: Vsechny tyto programy - vcetne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)
:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.

:arrow: Stahnete TFC http://oldtimer.geekstogo.com/TFC.exe , ulozte a spustte
Kliknete na START a pote OK - Po uklidu dojde k restartu pc.
Po pouziti muzete programek smazat

:arrow: Stahnete CCleaner http://www.stahuj.centrum.cz/utility_a_ ... /ccleaner/ a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!

:arrow: Defragmentujte disk(y)
Stahnete program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.



:arrow: Pak dejte vedet, zda je vse v poradku. A pokud ano, bude to vse :)



31.3.2013 pro neaktivitu :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975