Stránka 2 z 2

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 10:59
od feraf
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by Admin (administrator) on FERAF-NB on 08-11-2013 10:55:24
Running from C:\Users\Admin\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Atheros) C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Atheros\Bluetooth Suite\adminservice.exe
() C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
() C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\seksmdb.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
() C:\ExpressGateUtil\VAWinService.exe
(WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
(Memeo) C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
(Microsoft Corp.) C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Atheros\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Atheros\Bluetooth Suite\AthBtTray.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(LW-WORKS Software) C:\Program Files (x86)\LW-WORKS Software\Clipboard Recorder\clipboard_recorder.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Igor Gottwald - OKsoftware) C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Singer's Creations) C:\Program Files (x86)\Weather Watcher Live\ww.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe
(BitTorrent Inc.) C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(WDC) C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
() C:\ExpressGateUtil\VAWinAgent.exe
(Western Digital) C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON_P2B\Printer Software\Launcher\selaunch.exe
() C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\seksmpl.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
() C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\seksmW.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
(forum.viry.cz) C:\Users\Admin\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] - C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs [4156 2010-04-16] ()
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Atheros\Bluetooth Suite\BtvStack.exe [613536 2010-11-26] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Atheros\Bluetooth Suite\AthBtTray.exe [379040 2010-11-26] (Atheros Commnucations)
HKLM\...\Run: [ETDWare] - C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Clipboard Recorder] - C:\Program Files (x86)\LW-WORKS Software\Clipboard Recorder\clipboard_recorder.exe [1843200 2007-07-09] (LW-WORKS Software)
HKCU\...\Run: [Thunderbird] - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe [390256 2013-10-30] (Mozilla Corporation)
HKCU\...\Run: [Svátky a výročí] - C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [1019904 2006-04-28] (Igor Gottwald - OKsoftware)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-04-29] ()
HKCU\...\Run: [WeatherWatcherLive] - C:\Program Files (x86)\Weather Watcher Live\ww.exe [1968296 2013-06-05] (Singer's Creations)
HKCU\...\Run: [DAEMON Tools Pro Agent] - C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3111744 2012-04-26] (DT Soft Ltd)
HKCU\...\Run: [ShowBatteryBar] - C:\Program Files\BatteryBar\ShowBatteryBar.exe [89600 2013-04-11] ()
HKCU\...\Run: [NERO] - C:\Users\Admin\VVETC\PJMOCCCWLE-XUEWZ-FRDXYTBRCM.vbe [1713162 2013-10-14] ()
HKCU\...\Run: [uTorrent] - C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [802136 2013-11-07] (BitTorrent Inc.)
HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] ()
HKLM-x32\...\Run: [VAWinAgent] - C:\ExpressGateUtil\VAWinAgent.exe [45448 2011-04-08] ()
HKLM-x32\...\Run: [UpdatePSTShortCut] - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [222504 2010-11-24] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [SonicMasterTray] - C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [RemoteControl11] - C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [230696 2011-08-24] (CyberLink Corp.)
HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [FLxHCIm] - C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe [43008 2011-04-08] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [ASUSWebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\aprp.exe [2018032 2011-03-31] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM-x32\...\Run: [LauncherM200DN] - C:\Program Files (x86)\EPSON_P2B\Printer Software\Launcher\selaunch.exe [2587056 2012-09-13] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [M200DN RUN] - C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\seksmRun.exe [362928 2012-09-13] ()
HKLM-x32\...\Run: [StatusAutoRunM200DN] - C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\seksmpl.exe [4277680 2012-09-13] ()
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-10-17] (Adobe Systems Incorporated)
HKU\Administrator\...\Run: [Clipboard Recorder] - C:\Program Files (x86)\LW-WORKS Software\Clipboard Recorder\clipboard_recorder.exe [1843200 2007-07-09] (LW-WORKS Software)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=UP22&ocid=univskyhp
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {399a1442-7377-49e7-8d77-6dc9ed5968c1} URL = http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826
SearchScopes: HKCU - {4CA1898A-36D3-465B-B4EE-82C392903BEC} URL = http://www.google.com/search?q={sear
SearchScopes: HKCU - {5cf5d387-d87c-4408-9a6b-301b0713d62a} URL = http://www.mapy.cz/?query={searchTerms} ... earch_6826
SearchScopes: HKCU - {8172f457-818d-46db-941f-2bbe53e156af} URL = http://isearch.avg.com/search?cid={B171 ... 2011-12-07 20:34:17&v=8.0.0.34&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {eb97f7df-1773-4916-aae6-5af74da8c69d} URL = http://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Atheros\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Toolbar: HKCU - No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No File
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.2

FireFox:
========
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894
FF Homepage: about:newtab
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wolfram.com/Mathematica - C:\Program Files (x86)\Common Files\Wolfram Research\Browser\8.0.1.2063897\npmathplugin.dll (Wolfram Research, Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @autodesk.com/DWF - C:\Program Files (x86)\Autodesk\Autodesk Design Review Browser Add-on v1.2\npADRdwf.dll (Autodesk)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Xmarks - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\foxmarks@kei.com
FF Extension: MinimizeToTray revived (MinTrayR) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\mintrayr@tn123.ath.cx
FF Extension: Forecastfox - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF Extension: customizenewtab - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\customizenewtab@alejandrobrizuela.com.ar.xpi
FF Extension: Noia4Options - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\Noia4Options@ArisT2.xpi
FF Extension: testpilot - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\testpilot@labs.mozilla.com.xpi
FF Extension: b2tprefs - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\{3C9A65A6-9563-4485-BA4A-4BCD698BCFB4}.xpi
FF Extension: Adblock Plus - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: greasemonkey - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
FF Extension: prefs - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}.xpi
FF Extension: No Name - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\l0kb9nzi.default-1345666384894\Extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: () - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj\1.4_0

==================== Services (Whitelisted) =================

R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Atheros\Ath_CoexAgent.exe [151552 2010-05-24] (Atheros)
R2 AtherosSvc; C:\Program Files (x86)\Atheros\Bluetooth Suite\adminservice.exe [52896 2010-11-26] (Atheros Commnucations)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] ()
R2 CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [83240 2011-08-24] ()
R2 CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [75048 2011-08-26] (CyberLink)
R2 CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [292136 2011-08-26] (CyberLink)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-09-03] (Nero AG)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] ()
R2 mitsijm2012; C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe [848704 2011-08-03] (Autodesk, Inc.)
R2 MSSQL$ECSQLEXPRESS; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2012-11-29] (Nitro PDF Software)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2011-12-20] ()
S3 Remote Solver for Flow Simulation 2012; C:\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [109624 2011-08-17] (Mentor Graphics Corporation)
S3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-04-17] ()
R2 SENADB; C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\seksmdb.exe [137648 2012-09-13] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2099512 2013-09-09] (AVG)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [42808 2013-09-09] (AVG)
R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-26] ()
S4 wlcrasvc; C:\Program Files (x86)\Windows Live\Mesh\wlcrasvc.exe [57184 2010-09-22] (Microsoft Corporation)
R2 wlidsvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2286976 2010-09-21] (Microsoft Corp.)

==================== Drivers (Whitelisted) ====================

R3 DlinkUDSMBus; C:\Windows\SysWow64\Drivers\DlinkUDSMBus.sys [66656 2010-04-07] (Windows (R) Codename Longhorn DDK provider)
S3 DlinkUDSTcpBus; C:\Windows\SysWow64\Drivers\DlinkUDSTcpBus.sys [85600 2010-04-07] (Windows (R) Codename Longhorn DDK provider)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-07-20] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [56320 2011-04-08] (Fresco Logic)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2012-12-02] (GFI Software)
S2 Hardlock; C:\Windows\SysWow64\drivers\hardlock.sys [676864 2004-07-14] (Aladdin Knowledge Systems)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-21] ( )
R2 ntk_PowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [75248 2011-08-24] (Cyberlink Corp.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
S2 Sentinel; C:\Windows\SysWow64\Drivers\SENTINEL.SYS [76288 2009-10-05] (Rainbow Technologies, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-04-19] (Duplex Secure Ltd.)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2013-11-06] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] ()
R1 VD_FileDisk; C:\Windows\System32\Drivers\VD_FileDisk.sys [30312 2011-01-26] (CaptainFlint Software)
R2 {329F96B6-DF1E-4328-BFDA-39EA953C1312}; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl [148976 2011-08-25] (CyberLink Corp.)
U3 ae5nmaot; C:\Windows\System32\Drivers\ae5nmaot.sys [0 ] (Intel Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-09-17] (ESET)
S3 gHidPnp; System32\Drivers\gHidPnp.Sys [x]
S3 gMouUsb; system32\DRIVERS\gMouUsb.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-08 10:54 - 2013-11-08 10:54 - 00000000 ____D C:\FRST
2013-11-08 10:52 - 2013-11-08 10:52 - 01957098 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2013-11-08 10:52 - 2013-11-08 10:52 - 00112128 _____ (forum.viry.cz) C:\Users\Admin\Desktop\FRSTLauncher.exe
2013-11-08 09:41 - 2013-11-08 09:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG
2013-11-07 17:07 - 2013-11-07 17:07 - 00000873 _____ C:\Users\Public\Desktop\µTorrent.lnk
2013-11-07 16:49 - 2013-11-07 16:49 - 00000000 ____D C:\ProgramData\ESET
2013-11-07 11:47 - 2013-11-07 11:49 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\clipboard_recorder
2013-11-07 11:47 - 2013-11-07 11:47 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2013-11-07 11:47 - 2013-11-07 11:47 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
2013-11-06 19:29 - 2013-11-06 19:29 - 00033828 _____ C:\ComboFix.txt
2013-11-06 19:01 - 2013-11-06 19:29 - 00000000 ____D C:\Qoobox
2013-11-06 19:01 - 2013-11-06 19:29 - 00000000 ____D C:\ComboFix
2013-11-06 19:01 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-06 19:01 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-06 19:01 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-06 19:01 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-06 19:01 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-06 19:01 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-06 19:01 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-06 19:01 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-06 18:51 - 2013-11-06 18:52 - 00003752 _____ C:\Users\Admin\Desktop\Rkill.txt
2013-11-06 18:47 - 2013-11-06 18:47 - 05144303 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2013-11-06 18:46 - 2013-11-06 18:50 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Admin\Desktop\rkill.com
2013-11-06 18:35 - 2013-11-06 18:35 - 00055518 _____ C:\Users\Admin\Desktop\MbrScan.log
2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd1_DR1.mbr
2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd0_DR0.mbr
2013-11-06 18:34 - 2013-11-06 18:34 - 00147456 _____ (Eric_71) C:\Users\Admin\Desktop\MbrScan.exe
2013-11-06 18:02 - 2000-01-01 01:00 - 19490816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2013-11-06 18:02 - 2000-01-01 01:00 - 14021912 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 03686472 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 03338952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2013-11-06 18:02 - 2000-01-01 01:00 - 02785864 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 02730016 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 02099480 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 02032408 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 01900824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 01659464 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2013-11-06 18:02 - 2000-01-01 01:00 - 01284680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00991816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00910104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00613448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00429985 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2013-11-06 18:02 - 2000-01-01 01:00 - 00395208 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00204864 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00132168 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2013-11-06 18:02 - 2000-01-01 01:00 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2013-11-06 17:55 - 2013-11-06 17:55 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e
2013-11-06 17:54 - 2000-01-01 01:00 - 00104048 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\L1C62x64.sys
2013-11-06 17:52 - 2013-11-06 17:52 - 00000000 ____D C:\Intel
2013-11-06 17:52 - 2000-01-01 01:00 - 13030912 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 12615680 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 10811904 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 05905904 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 05358016 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
2013-11-06 17:52 - 2000-01-01 01:00 - 03511296 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 03121152 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 01040384 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00931840 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00575488 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00542720 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00515568 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00442880 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00442352 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00439296 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00437760 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc
2013-11-06 17:52 - 2000-01-01 01:00 - 00410624 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00399856 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00384512 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00330752 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00279024 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00254960 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00223664 _____ C:\Windows\system32\Gfxres.th-TH.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00210106 _____ C:\Windows\system32\Gfxres.el-GR.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00194245 _____ C:\Windows\system32\Gfxres.ru-RU.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00185840 _____ (Intel Corporation) C:\Windows\system32\difx64.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00175104 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00172016 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe
2013-11-06 17:52 - 2000-01-01 01:00 - 00166170 _____ C:\Windows\system32\Gfxres.ar-SA.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00163421 _____ C:\Windows\system32\Gfxres.ja-JP.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00159008 _____ C:\Windows\system32\Gfxres.he-IL.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00149682 _____ C:\Windows\system32\Gfxres.it-IT.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00148042 _____ C:\Windows\system32\Gfxres.ko-KR.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00147393 _____ C:\Windows\system32\Gfxres.de-DE.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00147288 _____ C:\Windows\system32\Gfxres.es-ES.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00146004 _____ C:\Windows\system32\Gfxres.ro-RO.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00145491 _____ C:\Windows\system32\Gfxres.fr-FR.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00144645 _____ C:\Windows\system32\Gfxres.tr-TR.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00144260 _____ C:\Windows\system32\Gfxres.pt-BR.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00144020 _____ C:\Windows\system32\Gfxres.nl-NL.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00143932 _____ C:\Windows\system32\Gfxres.hu-HU.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00142882 _____ C:\Windows\system32\Gfxres.sv-SE.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00142877 _____ C:\Windows\system32\Gfxres.pt-PT.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00142717 _____ C:\Windows\system32\Gfxres.pl-PL.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00142289 _____ C:\Windows\system32\Gfxres.cs-CZ.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00142008 _____ C:\Windows\system32\Gfxres.fi-FI.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00141838 _____ C:\Windows\system32\Gfxres.sk-SK.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00141049 _____ C:\Windows\system32\Gfxres.hr-HR.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00137889 _____ C:\Windows\system32\Gfxres.sl-SI.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00137784 _____ C:\Windows\system32\Gfxres.nb-NO.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00137141 _____ C:\Windows\system32\Gfxres.da-DK.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00126300 _____ C:\Windows\system32\Gfxres.zh-TW.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00124650 _____ C:\Windows\system32\Gfxres.zh-CN.resources
2013-11-06 17:52 - 2000-01-01 01:00 - 00116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v3062.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00080384 _____ C:\Windows\system32\igdde64.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00064512 _____ C:\Windows\SysWOW64\igdde32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00025088 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
2013-11-06 17:52 - 2000-01-01 01:00 - 00017078 _____ C:\Windows\system32\iglhxs64.vp
2013-11-06 17:52 - 2000-01-01 01:00 - 00009728 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll
2013-11-06 17:51 - 2000-01-01 01:00 - 00440320 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00439808 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00438784 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00438272 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00437248 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00435712 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00432128 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00431104 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00429056 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00428544 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00286208 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc
2013-11-06 17:51 - 2000-01-01 01:00 - 00126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl
2013-11-06 15:15 - 2013-11-06 15:39 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-06 15:15 - 2013-11-06 15:15 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-11-06 15:15 - 2013-11-06 15:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-06 14:37 - 2013-11-06 15:05 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-06 14:36 - 2013-11-06 15:39 - 00000000 ____D C:\Users\Admin\Desktop\mbar
2013-11-06 14:35 - 2013-11-06 14:35 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Admin\Desktop\mbar-1.07.0.1007.exe
2013-11-06 13:58 - 2013-11-06 13:58 - 00001168 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
2013-11-06 13:57 - 2013-11-06 13:57 - 00000000 ____D C:\Users\Admin\Desktop\OpenOffice.org 3.4.1 (cs) Installation Files
2013-11-06 13:57 - 2013-11-06 13:57 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-11-06 13:52 - 2013-11-06 13:52 - 00000000 ____D C:\rsit
2013-11-06 11:16 - 2013-11-06 11:16 - 00000000 ____D C:\Program Files (x86)\ESET
2013-11-06 11:15 - 2013-11-06 11:15 - 02347384 _____ (ESET) C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe
2013-11-06 11:05 - 2013-11-06 11:05 - 00002737 _____ C:\Users\Public\Desktop\Nero Burning ROM 2014.lnk
2013-11-06 10:56 - 2013-11-06 22:25 - 00000000 ____D C:\Users\Admin\TUFRI
2013-11-06 10:32 - 2013-11-06 10:32 - 00001040 _____ C:\Users\Admin\Desktop\Adobe Audition CC.lnk
2013-11-04 22:56 - 2013-11-05 09:55 - 00000000 ____D C:\Users\Admin\Documents\Adobe
2013-11-04 22:56 - 2013-11-04 22:56 - 00003502 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-FERAF-NB-Admin
2013-11-04 22:56 - 2013-11-04 22:56 - 00000000 ____D C:\Users\Public\Documents\Adobe
2013-11-04 22:55 - 2013-11-04 22:56 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-11-04 22:42 - 2013-11-04 22:44 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-04 22:42 - 2013-11-04 22:42 - 00000000 ____D C:\Program Files\Adobe
2013-11-04 22:41 - 2013-11-04 22:41 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-11-04 22:41 - 2012-06-22 03:01 - 00056336 ____N (Corel Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys
2013-11-04 22:41 - 2012-04-24 03:01 - 00011376 ____N (Corel Corporation) C:\Windows\system32\Drivers\cdralw2k.sys
2013-11-04 22:41 - 2012-04-24 03:01 - 00010864 ____N (Corel Corporation) C:\Windows\system32\Drivers\cdr4_xp.sys
2013-11-04 22:11 - 2013-11-04 22:11 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity
2013-11-04 21:59 - 2013-11-04 22:23 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Audacity
2013-11-02 21:45 - 2013-11-02 21:45 - 00000000 ____D C:\ProgramData\regid.1995-09.com.example
2013-11-02 21:45 - 2013-11-02 21:45 - 00000000 ____D C:\Program Files (x86)\TV Online
2013-11-02 21:43 - 2013-11-02 21:43 - 00001068 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-01 09:30 - 2013-11-01 09:30 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-11-01 09:25 - 2013-11-01 09:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-31 16:39 - 2013-11-06 14:57 - 00231496 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2013-10-31 16:37 - 2013-11-08 08:27 - 00003994 _____ C:\Windows\setupact.log
2013-10-31 16:37 - 2013-11-06 14:56 - 00743016 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-31 16:37 - 2013-10-31 16:37 - 00000000 _____ C:\Windows\setuperr.log
2013-10-31 16:36 - 2013-11-06 19:32 - 00243188 _____ C:\Windows\PFRO.log
2013-10-31 10:19 - 2013-10-31 10:19 - 00001508 _____ C:\Users\Admin\Desktop\MKVExtractGUI2.lnk
2013-10-31 10:17 - 2013-10-31 10:18 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-10-31 10:17 - 2013-10-31 10:17 - 00001864 _____ C:\Users\Public\Desktop\mkvmerge GUI.lnk
2013-10-31 10:01 - 2013-10-31 10:01 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Media Player Classic
2013-10-30 18:53 - 2013-08-14 19:00 - 00127488 _____ C:\Windows\system32\ff_vfw.dll
2013-10-30 18:53 - 2013-08-14 19:00 - 00112640 _____ C:\Windows\SysWOW64\ff_vfw.dll
2013-10-30 18:53 - 2013-08-02 18:29 - 00256088 _____ C:\Windows\system32\unrar64.dll
2013-10-30 18:53 - 2013-03-17 18:22 - 03554304 _____ (x264vfw project) C:\Windows\system32\x264vfw64.dll
2013-10-30 18:53 - 2013-03-17 17:21 - 03649536 _____ (x264vfw project) C:\Windows\SysWOW64\x264vfw.dll
2013-10-30 18:53 - 2012-07-21 11:55 - 00180736 _____ (fccHandler) C:\Windows\system32\ac3acm.acm
2013-10-30 18:53 - 2012-07-21 11:54 - 00122880 _____ (fccHandler) C:\Windows\SysWOW64\ac3acm.acm
2013-10-30 18:53 - 2011-12-07 18:37 - 00148992 _____ ( ) C:\Windows\system32\lagarith.dll
2013-10-30 18:53 - 2011-12-07 18:32 - 00216064 _____ ( ) C:\Windows\SysWOW64\lagarith.dll
2013-10-30 18:53 - 2011-06-24 15:45 - 00258560 _____ C:\Windows\system32\xvidvfw.dll
2013-10-30 18:53 - 2011-06-24 15:44 - 00243200 _____ C:\Windows\SysWOW64\xvidvfw.dll
2013-10-30 18:53 - 2011-06-24 15:31 - 00703488 _____ C:\Windows\system32\xvidcore.dll
2013-10-30 18:53 - 2011-06-24 15:28 - 00650752 _____ C:\Windows\SysWOW64\xvidcore.dll
2013-10-25 11:55 - 2013-10-25 11:55 - 00000000 ____D C:\Users\Public\Epson
2013-10-25 11:55 - 2013-10-25 11:55 - 00000000 ____D C:\Program Files (x86)\EPSON_P2B
2013-10-25 11:55 - 2012-07-09 14:24 - 00021504 _____ C:\Windows\system32\seapn1mLM.DLL
2013-10-25 11:55 - 2012-06-21 15:06 - 00021504 _____ C:\Windows\system32\sea6n1mlm.dll
2013-10-25 11:53 - 2013-10-25 11:53 - 00003806 _____ C:\Windows\SysWOW64\CommonSetting.ini
2013-10-25 11:53 - 2013-10-25 11:53 - 00003806 _____ C:\Windows\CommonSetting.ini
2013-10-21 16:21 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-21 16:21 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-21 16:21 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-21 16:21 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-21 16:20 - 2013-10-21 16:21 - 00004154 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-18 14:27 - 2013-10-18 14:27 - 00000000 ____D C:\ProgramData\CanonIJ
2013-10-14 17:38 - 2013-10-30 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-09 09:31 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-09 09:31 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-09 09:31 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-09 09:31 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-09 09:31 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-09 09:31 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-09 09:31 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-09 09:31 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-09 09:31 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-09 09:31 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-09 09:31 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-09 09:31 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-09 09:17 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-09 09:17 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-09 09:17 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-09 09:17 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-09 09:17 - 2013-08-29 02:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2013-10-09 09:17 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 09:17 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-09 09:17 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 09:17 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-09 09:17 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 09:17 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-09 09:17 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-09 09:17 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-09 09:17 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 09:17 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-09 09:17 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 09:17 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 09:17 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 09:17 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-09 09:17 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-09 09:17 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-09 09:17 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 09:17 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-09 09:17 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-09 09:17 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-09 09:17 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 09:17 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 09:17 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-09 09:16 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-09 09:16 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-09 09:16 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-09 09:16 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-09 09:16 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-09 09:16 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-09 09:16 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-09 09:16 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-09 09:16 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-09 09:16 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-09 09:16 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-09 09:16 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-09 09:16 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-09 09:16 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-09 09:16 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-09 09:16 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-09 09:16 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-09 09:16 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 09:16 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 09:15 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-09 09:15 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-09 09:15 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-09 09:15 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-09 09:15 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-09 09:15 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-09 09:15 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys

==================== One Month Modified Files and Folders =======

2013-11-08 10:56 - 2013-04-28 20:44 - 00000000 ____D C:\Users\Admin\AppData\Local\PMB Files
2013-11-08 10:56 - 2011-12-07 23:17 - 00000000 ____D C:\Users\Admin\AppData\Roaming\uTorrent
2013-11-08 10:54 - 2013-11-08 10:54 - 00000000 ____D C:\FRST
2013-11-08 10:52 - 2013-11-08 10:52 - 01957098 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe
2013-11-08 10:52 - 2013-11-08 10:52 - 00112128 _____ (forum.viry.cz) C:\Users\Admin\Desktop\FRSTLauncher.exe
2013-11-08 10:47 - 2013-06-05 22:04 - 00000000 ____D C:\Users\Admin\AppData\Roaming\WeatherWatcherLive
2013-11-08 10:39 - 2013-04-17 06:55 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-08 10:34 - 2011-12-07 23:57 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Skype
2013-11-08 10:33 - 2012-11-08 15:04 - 00000000 ____D C:\Program Files\trend micro
2013-11-08 10:32 - 2012-12-24 11:59 - 00000000 ___HD C:\Users\Admin\Desktop\.picasaoriginals
2013-11-08 10:30 - 2013-10-08 20:50 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec45facc60b31.job
2013-11-08 10:30 - 2011-08-14 02:40 - 00045056 _____ C:\Windows\system32\acovcnt.exe
2013-11-08 10:30 - 2011-08-14 02:33 - 00000035 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2013-11-08 09:41 - 2013-11-08 09:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG
2013-11-08 08:32 - 2009-07-14 05:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-08 08:32 - 2009-07-14 05:45 - 00021680 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-08 08:30 - 2011-08-14 02:17 - 02055226 _____ C:\Windows\WindowsUpdate.log
2013-11-08 08:29 - 2011-09-02 15:01 - 00000000 ____D C:\Users\Admin\Documents\Bluetooth Folder
2013-11-08 08:27 - 2013-10-31 16:37 - 00003994 _____ C:\Windows\setupact.log
2013-11-08 08:27 - 2013-09-18 17:37 - 00000000 ____D C:\Users\Admin\AppData\Local\HTC MediaHub
2013-11-08 08:27 - 2013-08-31 18:06 - 00002896 _____ C:\Windows\System32\Tasks\AutoKMS
2013-11-08 08:27 - 2013-08-31 18:06 - 00000266 _____ C:\Windows\Tasks\AutoKMS.job
2013-11-08 08:27 - 2012-02-04 12:40 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-08 08:27 - 2012-01-28 19:55 - 00000435 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2013-11-08 08:27 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-08 05:37 - 2013-08-30 19:28 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-11-08 02:02 - 2011-12-12 16:53 - 00000000 ____D C:\Users\Admin\AppData\Local\Adobe
2013-11-07 17:07 - 2013-11-07 17:07 - 00000873 _____ C:\Users\Public\Desktop\µTorrent.lnk
2013-11-07 16:49 - 2013-11-07 16:49 - 00000000 ____D C:\ProgramData\ESET
2013-11-07 16:47 - 2011-12-07 19:00 - 00000000 ____D C:\Users\Admin\AppData\Local\CrashDumps
2013-11-07 11:49 - 2013-11-07 11:47 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\clipboard_recorder
2013-11-07 11:47 - 2013-11-07 11:47 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2013-11-07 11:47 - 2013-11-07 11:47 - 00000000 ____D C:\Users\Administrator\AppData\Local\Adobe
2013-11-07 11:47 - 2013-04-28 18:59 - 00228728 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-07 11:47 - 2013-04-28 18:59 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2013-11-07 11:46 - 2013-04-28 18:59 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-11-07 11:46 - 2013-04-28 18:59 - 00000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-11-07 11:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-11-07 06:29 - 2011-02-19 11:21 - 00727252 _____ C:\Windows\system32\perfh005.dat
2013-11-07 06:29 - 2011-02-19 11:21 - 00163274 _____ C:\Windows\system32\perfc005.dat
2013-11-07 06:29 - 2009-07-14 06:13 - 01747048 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-07 02:42 - 2012-12-29 17:39 - 00000410 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2013-11-07 02:42 - 2011-12-07 20:31 - 00002838 _____ C:\Windows\System32\Tasks\SlimDrivers Startup
2013-11-06 22:25 - 2013-11-06 10:56 - 00000000 ____D C:\Users\Admin\TUFRI
2013-11-06 19:36 - 2011-12-07 20:31 - 00016152 _____ C:\Windows\system32\Drivers\SWDUMon.sys
2013-11-06 19:36 - 2011-08-14 02:27 - 00018670 _____ C:\Windows\system32\results.xml
2013-11-06 19:35 - 2011-08-14 02:36 - 00002076 _____ C:\Windows\system32\ServiceFilter.ini
2013-11-06 19:34 - 2013-07-06 14:29 - 00000000 ____D C:\Windows\SysWOW64\NV
2013-11-06 19:34 - 2013-07-06 14:29 - 00000000 ____D C:\Windows\system32\NV
2013-11-06 19:32 - 2013-10-31 16:36 - 00243188 _____ C:\Windows\PFRO.log
2013-11-06 19:29 - 2013-11-06 19:29 - 00033828 _____ C:\ComboFix.txt
2013-11-06 19:29 - 2013-11-06 19:01 - 00000000 ____D C:\Qoobox
2013-11-06 19:29 - 2013-11-06 19:01 - 00000000 ____D C:\ComboFix
2013-11-06 19:26 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-11-06 19:00 - 2012-11-08 12:28 - 00000000 ____D C:\Windows\erdnt
2013-11-06 18:52 - 2013-11-06 18:51 - 00003752 _____ C:\Users\Admin\Desktop\Rkill.txt
2013-11-06 18:50 - 2013-11-06 18:46 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Admin\Desktop\rkill.com
2013-11-06 18:47 - 2013-11-06 18:47 - 05144303 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe
2013-11-06 18:35 - 2013-11-06 18:35 - 00055518 _____ C:\Users\Admin\Desktop\MbrScan.log
2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd1_DR1.mbr
2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd0_DR0.mbr
2013-11-06 18:34 - 2013-11-06 18:34 - 00147456 _____ (Eric_71) C:\Users\Admin\Desktop\MbrScan.exe
2013-11-06 18:03 - 2012-01-18 22:20 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2013-11-06 17:55 - 2013-11-06 17:55 - 00000000 ____D C:\Windows\SysWOW64\Atheros_L1e
2013-11-06 17:55 - 2011-08-14 02:27 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-11-06 17:53 - 2011-08-14 02:20 - 00000000 ____D C:\Program Files (x86)\Intel
2013-11-06 17:52 - 2013-11-06 17:52 - 00000000 ____D C:\Intel
2013-11-06 17:45 - 2012-03-17 18:26 - 00000000 ____D C:\Users\Public\Documents\Downloaded Installers
2013-11-06 17:45 - 2011-12-07 20:31 - 00002467 _____ C:\Users\Public\Desktop\SlimDrivers.lnk
2013-11-06 15:39 - 2013-11-06 15:15 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-11-06 15:39 - 2013-11-06 14:36 - 00000000 ____D C:\Users\Admin\Desktop\mbar
2013-11-06 15:15 - 2013-11-06 15:15 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2013-11-06 15:15 - 2013-11-06 15:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-11-06 15:05 - 2013-11-06 14:37 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2013-11-06 14:57 - 2013-10-31 16:39 - 00231496 _____ C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT
2013-11-06 14:56 - 2013-10-31 16:37 - 00743016 _____ C:\Windows\system32\FNTCACHE.DAT
2013-11-06 14:53 - 2011-12-07 21:41 - 01722698 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-11-06 14:35 - 2013-11-06 14:35 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Admin\Desktop\mbar-1.07.0.1007.exe
2013-11-06 13:58 - 2013-11-06 13:58 - 00001168 _____ C:\Users\Public\Desktop\OpenOffice.org 3.4.1.lnk
2013-11-06 13:57 - 2013-11-06 13:57 - 00000000 ____D C:\Users\Admin\Desktop\OpenOffice.org 3.4.1 (cs) Installation Files
2013-11-06 13:57 - 2013-11-06 13:57 - 00000000 ____D C:\Program Files (x86)\OpenOffice.org 3
2013-11-06 13:53 - 2011-12-07 22:55 - 00000000 ____D C:\Windows\system32\appmgmt
2013-11-06 13:52 - 2013-11-06 13:52 - 00000000 ____D C:\rsit
2013-11-06 13:49 - 2011-12-07 23:34 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-06 13:47 - 2009-07-14 08:46 - 00000000 ____D C:\Windows\ShellNew
2013-11-06 13:47 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
2013-11-06 13:47 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-11-06 13:34 - 2011-08-14 02:36 - 00003782 _____ C:\Windows\system32\AutoRunFilter.ini
2013-11-06 12:07 - 2011-12-07 22:12 - 00000000 ____D C:\Program Files (x86)\Nero
2013-11-06 11:37 - 2011-12-07 22:28 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Nero
2013-11-06 11:16 - 2013-11-06 11:16 - 00000000 ____D C:\Program Files (x86)\ESET
2013-11-06 11:15 - 2013-11-06 11:15 - 02347384 _____ (ESET) C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe
2013-11-06 11:05 - 2013-11-06 11:05 - 00002737 _____ C:\Users\Public\Desktop\Nero Burning ROM 2014.lnk
2013-11-06 11:05 - 2011-12-07 22:13 - 00000000 ____D C:\ProgramData\Nero
2013-11-06 10:56 - 2011-09-02 14:59 - 00000000 ____D C:\Users\Admin
2013-11-06 10:32 - 2013-11-06 10:32 - 00001040 _____ C:\Users\Admin\Desktop\Adobe Audition CC.lnk
2013-11-05 09:55 - 2013-11-04 22:56 - 00000000 ____D C:\Users\Admin\Documents\Adobe
2013-11-05 02:08 - 2013-07-06 15:01 - 00000000 ____D C:\Users\Admin\AppData\Local\JDownloader v2.0
2013-11-04 22:56 - 2013-11-04 22:56 - 00003502 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-FERAF-NB-Admin
2013-11-04 22:56 - 2013-11-04 22:56 - 00000000 ____D C:\Users\Public\Documents\Adobe
2013-11-04 22:56 - 2013-11-04 22:55 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2013-11-04 22:56 - 2011-12-07 23:06 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Adobe
2013-11-04 22:44 - 2013-11-04 22:42 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-11-04 22:42 - 2013-11-04 22:42 - 00000000 ____D C:\Program Files\Adobe
2013-11-04 22:42 - 2011-12-07 19:09 - 00000000 ____D C:\ProgramData\Adobe
2013-11-04 22:41 - 2013-11-04 22:41 - 00000000 ____D C:\Program Files (x86)\My Company Name
2013-11-04 22:29 - 2012-10-20 14:44 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-04 22:23 - 2013-11-04 21:59 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Audacity
2013-11-04 22:11 - 2013-11-04 22:11 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity
2013-11-02 21:45 - 2013-11-02 21:45 - 00000000 ____D C:\ProgramData\regid.1995-09.com.example
2013-11-02 21:45 - 2013-11-02 21:45 - 00000000 ____D C:\Program Files (x86)\TV Online
2013-11-02 21:45 - 2013-08-10 22:31 - 00001109 _____ C:\Users\Public\Desktop\TV Online.lnk
2013-11-02 21:45 - 2013-08-10 22:31 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2013-11-02 21:44 - 2013-08-10 22:30 - 00000000 ____D C:\Users\Admin\AppData\Roaming\TV Online
2013-11-02 21:43 - 2013-11-02 21:43 - 00001068 _____ C:\Users\Public\Desktop\VLC media player.lnk
2013-11-02 21:42 - 2012-10-04 19:58 - 00000000 ____D C:\Users\Admin\AppData\Roaming\vlc
2013-11-02 07:21 - 2012-04-24 17:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-01 09:30 - 2013-11-01 09:30 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-11-01 09:30 - 2013-11-01 09:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-31 16:37 - 2013-10-31 16:37 - 00000000 _____ C:\Windows\setuperr.log
2013-10-31 10:52 - 2012-05-31 12:43 - 00000000 ____D C:\Windows\Minidump
2013-10-31 10:52 - 2009-07-29 07:52 - 00000000 ____D C:\Windows\Panther
2013-10-31 10:19 - 2013-10-31 10:19 - 00001508 _____ C:\Users\Admin\Desktop\MKVExtractGUI2.lnk
2013-10-31 10:18 - 2013-10-31 10:17 - 00000000 ____D C:\Program Files (x86)\MKVToolNix
2013-10-31 10:17 - 2013-10-31 10:17 - 00001864 _____ C:\Users\Public\Desktop\mkvmerge GUI.lnk
2013-10-31 10:01 - 2013-10-31 10:01 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Media Player Classic
2013-10-31 09:40 - 2013-09-16 19:37 - 00000000 ____D C:\Program Files\WinRAR
2013-10-30 18:53 - 2011-12-07 18:23 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2013-10-30 16:58 - 2013-09-16 19:37 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2013-10-30 13:46 - 2013-10-14 17:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-10-26 12:03 - 2012-02-18 18:01 - 00003704 _____ C:\Windows\System32\Tasks\Java Update Scheduler
2013-10-25 11:55 - 2013-10-25 11:55 - 00000000 ____D C:\Users\Public\Epson
2013-10-25 11:55 - 2013-10-25 11:55 - 00000000 ____D C:\Program Files (x86)\EPSON_P2B
2013-10-25 11:53 - 2013-10-25 11:53 - 00003806 _____ C:\Windows\SysWOW64\CommonSetting.ini
2013-10-25 11:53 - 2013-10-25 11:53 - 00003806 _____ C:\Windows\CommonSetting.ini
2013-10-21 16:21 - 2013-10-21 16:20 - 00004154 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-21 16:21 - 2013-09-25 09:12 - 00000000 ____D C:\ProgramData\Oracle
2013-10-21 16:21 - 2013-07-15 09:08 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-18 14:27 - 2013-10-18 14:27 - 00000000 ____D C:\ProgramData\CanonIJ
2013-10-18 14:26 - 2012-11-04 20:23 - 00000000 ___HD C:\ProgramData\CanonIJScan
2013-10-18 14:26 - 2012-11-04 20:22 - 00000000 ____D C:\Users\Admin\AppData\Roaming\Canon
2013-10-16 20:56 - 2012-11-08 16:50 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-16 20:56 - 2011-12-07 23:56 - 00000000 ____D C:\ProgramData\Skype
2013-10-11 13:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-10-09 09:26 - 2013-07-12 15:49 - 00000000 ____D C:\Windows\system32\MRT
2013-10-09 09:23 - 2011-12-07 19:14 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe
[2011-12-07 19:05] - [2011-02-26 07:26] - 2870784 ____A (Microsoft Corporation) E38899074D4951D31B4040E994DD7C8D

C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (OS) (Fixed) (Total:305.67 GB) (Free:26.27 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DOKUMENTY) (Fixed) (Total:367.96 GB) (Free:36.87 GB) NTFS
Drive e: (DATA) (Fixed) (Total:698.63 GB) (Free:12.4 GB) NTFS
Drive f: (M.D. House sezo) (CDROM) (Total:4.1 GB) (Free:0 GB) UDF
Drive g: (EPSON) (CDROM) (Total:0.65 GB) (Free:0 GB) CDFS

Available physical RAM: 4496.93 MB
Total physical RAM: 8102.72 MB
Percentage of memory in use: 44%

==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec45facc60b31.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cec45fad956c2a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe
Task: C:\Windows\Tasks\ParetoLogic Update Version3.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe
Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:52DBE86F
AlternateDataStreams: C:\ProgramData\Temp:5D458568

==================== Security Center ==================

AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 28_09_2013 (06)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Admin\Desktop" je 171 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector
C:\Windows\AsScrPro.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 11:00
od feraf
tady je ten rar

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 13:07
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
    HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
    HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-04-29] ()
    HKCU\...\Run: [DAEMON Tools Pro Agent] - C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3111744 2012-04-26] (DT Soft Ltd)
    HKCU\...\Run: [NERO] - C:\Users\Admin\VVETC\PJMOCCCWLE-XUEWZ-FRDXYTBRCM.vbe [1713162 2013-10-14] ()
    HKCU\...\Run: [uTorrent] - C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [802136 2013-11-07] (BitTorrent Inc.)
    HKLM-x32\...\Run: [UpdatePSTShortCut] - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [222504 2010-11-24] (CyberLink Corp.)
    HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
    HKLM-x32\...\Run: [RemoteControl11] - C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [230696 2011-08-24] (CyberLink Corp.)
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=UP22&ocid=univskyhp
    SearchScopes: HKLM - DefaultScope value is missing.
    SearchScopes: HKCU - {399a1442-7377-49e7-8d77-6dc9ed5968c1} URL = http://www.zbozi.cz/?q={searchTerms}&sourceid=quicksearch_6826
    SearchScopes: HKCU - {4CA1898A-36D3-465B-B4EE-82C392903BEC} URL = http://www.google.com/search?q={sear
    SearchScopes: HKCU - {5cf5d387-d87c-4408-9a6b-301b0713d62a} URL = http://www.mapy.cz/?query={searchTerms}&sourceid=quicksearch_6826
    SearchScopes: HKCU - {8172f457-818d-46db-941f-2bbe53e156af} URL = http://isearch.avg.com/search?cid={B171CE2D-AA15-4D9E-AF3A-C6A0DC2F08EB}&mid=a7b10e50171947d18c5fa5662e8d09f5-2e816600742c47ff4ae1a84a08962bf4fe5c42d1&lang=cs&ds=ts024&pr=&d=2011-12-07 20:34:17&v=8.0.0.34&sap=dsp&q={searchTerms}
    SearchScopes: HKCU - {eb97f7df-1773-4916-aae6-5af74da8c69d} URL = http://www.firmy.cz/phr/{searchTerms}
    SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
    
    Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
    CHR Extension: () - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj\1.4_0
    
    2013-11-08 09:41 - 2013-11-08 09:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG
    2013-11-06 18:46 - 2013-11-06 18:50 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Admin\Desktop\rkill.com
    2013-11-06 18:35 - 2013-11-06 18:35 - 00055518 _____ C:\Users\Admin\Desktop\MbrScan.log
    2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd1_DR1.mbr
    2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd0_DR0.mbr
    2013-11-06 18:34 - 2013-11-06 18:34 - 00147456 _____ (Eric_71) C:\Users\Admin\Desktop\MbrScan.exe
    2013-11-06 18:51 - 2013-11-06 18:52 - 00003752 _____ C:\Users\Admin\Desktop\Rkill.txt
    C:\Windows\AutoKMS
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec45facc60b31.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cec45fad956c2a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe
    Task: C:\Windows\Tasks\ParetoLogic Update Version3.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe
    Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
    
    AlternateDataStreams: C:\Windows:nlsPreferences
    AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
    AlternateDataStreams: C:\ProgramData\Temp:52DBE86F
    AlternateDataStreams: C:\ProgramData\Temp:5D458568
    
    Hosts:
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 18:19
od feraf
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 31-10-2013
Ran by Admin at 2013-11-08 18:18:13 Run:1
Running from C:\Users\Admin\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20472992 2013-10-02] (Skype Technologies S.A.)
HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2013-04-29] ()
HKCU\...\Run: [DAEMON Tools Pro Agent] - C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe [3111744 2012-04-26] (DT Soft Ltd)
HKCU\...\Run: [NERO] - C:\Users\Admin\VVETC\PJMOCCCWLE-XUEWZ-FRDXYTBRCM.vbe [1713162 2013-10-14] ()
HKCU\...\Run: [uTorrent] - C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [802136 2013-11-07] (BitTorrent Inc.)
HKLM-x32\...\Run: [UpdatePSTShortCut] - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [222504 2010-11-24] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl11] - C:\Program Files (x86)\CyberLink\PowerDVD11\PDVD11Serv.exe [230696 2011-08-24] (CyberLink Corp.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=UP22&ocid=univskyhp
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {399a1442-7377-49e7-8d77-6dc9ed5968c1} URL = http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826
SearchScopes: HKCU - {4CA1898A-36D3-465B-B4EE-82C392903BEC} URL = http://www.google.com/search?q={sear
SearchScopes: HKCU - {5cf5d387-d87c-4408-9a6b-301b0713d62a} URL = http://www.mapy.cz/?query={searchTerms} ... earch_6826
SearchScopes: HKCU - {8172f457-818d-46db-941f-2bbe53e156af} URL = http://isearch.avg.com/search?cid={B171 ... 2011-12-07 20:34:17&v=8.0.0.34&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {eb97f7df-1773-4916-aae6-5af74da8c69d} URL = http://www.firmy.cz/phr/{searchTerms}
SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = http://go.mail.ru/search?q={searchTerms ... =1&fr=ietb

Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: () - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj\1.4_0

2013-11-08 09:41 - 2013-11-08 09:41 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\AVG
2013-11-06 18:46 - 2013-11-06 18:50 - 01898232 _____ (Bleeping Computer, LLC) C:\Users\Admin\Desktop\rkill.com
2013-11-06 18:35 - 2013-11-06 18:35 - 00055518 _____ C:\Users\Admin\Desktop\MbrScan.log
2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd1_DR1.mbr
2013-11-06 18:35 - 2013-11-06 18:35 - 00000512 _____ C:\Users\Admin\Desktop\Dump_Hdd0_DR0.mbr
2013-11-06 18:34 - 2013-11-06 18:34 - 00147456 _____ (Eric_71) C:\Users\Admin\Desktop\MbrScan.exe
2013-11-06 18:51 - 2013-11-06 18:52 - 00003752 _____ C:\Users\Admin\Desktop\Rkill.txt
C:\Windows\AutoKMS

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec45facc60b31.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cec45fad956c2a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe
Task: C:\Windows\Tasks\ParetoLogic Update Version3.job => C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe
Task: C:\Windows\Tasks\SlimDrivers Startup.job => C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:3E7393FC
AlternateDataStreams: C:\ProgramData\Temp:52DBE86F
AlternateDataStreams: C:\ProgramData\Temp:5D458568

Hosts:

End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Nvtmru => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Pando Media Booster => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Pro Agent => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\NERO => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\uTorrent => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdatePSTShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateLBPShortCut => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RemoteControl11 => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{399a1442-7377-49e7-8d77-6dc9ed5968c1} => Key deleted successfully.
HKCR\CLSID\{399a1442-7377-49e7-8d77-6dc9ed5968c1} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4CA1898A-36D3-465B-B4EE-82C392903BEC} => Key deleted successfully.
HKCR\CLSID\{4CA1898A-36D3-465B-B4EE-82C392903BEC} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5cf5d387-d87c-4408-9a6b-301b0713d62a} => Key deleted successfully.
HKCR\CLSID\{5cf5d387-d87c-4408-9a6b-301b0713d62a} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8172f457-818d-46db-941f-2bbe53e156af} => Key deleted successfully.
HKCR\CLSID\{8172f457-818d-46db-941f-2bbe53e156af} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{eb97f7df-1773-4916-aae6-5af74da8c69d} => Key deleted successfully.
HKCR\CLSID\{eb97f7df-1773-4916-aae6-5af74da8c69d} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} => Key deleted successfully.
HKCR\CLSID\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} => Key not found.
C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\olakgnkoldmagdblaalodobkmeokmgjj => Moved successfully.
C:\Users\Administrator\AppData\Roaming\AVG => Moved successfully.
C:\Users\Admin\Desktop\rkill.com => Moved successfully.
C:\Users\Admin\Desktop\MbrScan.log => Moved successfully.
C:\Users\Admin\Desktop\Dump_Hdd1_DR1.mbr => Moved successfully.
C:\Users\Admin\Desktop\Dump_Hdd0_DR0.mbr => Moved successfully.
C:\Users\Admin\Desktop\MbrScan.exe => Moved successfully.
C:\Users\Admin\Desktop\Rkill.txt => Moved successfully.
C:\Windows\AutoKMS => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\AutoKMS.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cec45facc60b31.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cec45fad956c2a.job => Moved successfully.
C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job => Moved successfully.
C:\Windows\Tasks\ParetoLogic Update Version3.job => Moved successfully.
C:\Windows\Tasks\SlimDrivers Startup.job => Moved successfully.
C:\Windows => ":nlsPreferences" ADS removed successfully.
C:\ProgramData\Temp => ":3E7393FC" ADS removed successfully.
C:\ProgramData\Temp => ":52DBE86F" ADS removed successfully.
C:\ProgramData\Temp => ":5D458568" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

==== End of Fixlog ====

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 20:11
od vyosek
Jak se chova PC :???:

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 23:05
od feraf
už jede normálně děkuji

Re: Eset hlásí trojáka v operační paměti

Napsal: 08 lis 2013 23:59
od vyosek
Tak jeste uklidime :James008:

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|