Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o preventivní kontrolu

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#31 Příspěvek od xtractorek »

Ano přesně tak. Když vytáhnu ze zásuvky tak kapacita klesá a když vložím do nabíječky, tak se zase začne nabíjet, ale jak dosáhne 56-60%, tak se nabíjení zastaví.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#32 Příspěvek od Márty84 »

Jelikoz ja mam notas temer neustale v zasuvce a baterii temer nevyuzivam, notas mi sam doporucil nastaveni, ktere je nejlepsi pro dlouhou zivotnost baterie a ta se mi ted taky nabiji jen na 60%. Zkuste si tedy pohrat s nastavenim, jestli se tam nahodou neco nepreplo.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#33 Příspěvek od xtractorek »

Stáhnul jsem nějaký Lenovo energy management a provedl pomocí něj reset ukazatele baterie, nyní je na 100% takže problém vyřešen :) Díky vám za radu.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#34 Příspěvek od Márty84 »

Neni vubec zac! :)

Cili je ted vse v poradku a muzem tema uzavrit?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#35 Příspěvek od xtractorek »

Baterka je v pořádku, ovšem jinak mám v pc pořád asi nějakou havěť :( Avast mi našel Neurowise, nechápu proč, když spustím prohlížeč, tak se mi automaticky otevře několik oken s hrami nebo nějakými divnými reklamami (a ani nemusím otevřít počítač :(

Obrázek

EDIT: Týden nebudu u PC, napište co mám provést a udělám vše, jakmile budu zpět :)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#36 Příspěvek od Márty84 »

To uz jste stihl zase chytit neco noveho? :shock:

Toz dejte novy log z RSIT.

Ktery prohlizec to dela? Idealni by bylo odinstalovat jej pomoci CCleaneru, pak vycistit pc CCleanerem a ADWCleanerem a pak znovu prohlizec nainstalovat.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#37 Příspěvek od xtractorek »

Omlouvám se za delší pauzu, už jsem zpět a zde je log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Honza at 2014-10-18 10:15:56
Microsoft Windows 8.1
System drive C: has 581 GB (64%) free of 905 GB
Total RAM: 8048 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:15:59, on 18. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17278)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Users\Honza\AppData\Local\FluxSoftware\Flux\flux.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Honza.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Translat\WebIE.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [f.lux] "C:\Users\Honza\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - Startup: Sledovat výstrahy inkoustu - HP Deskjet 3050 J610 series.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - (no file)
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - (no file)
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Translat\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Translat\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Translat\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Translat\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Translat\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Translat\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Translat\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Translat\WebIE.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll, C:\WINDOWS\SysWOW64\nvinit.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Service_KAir (ServiceKAirModule) - Unknown owner - C:\Program Files (x86)\KMPConnect\KMPConnectService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Handy Safe WP7 Connectivity Service (WP7CommSvc) - Paragon Software Group - C:\Program Files (x86)\Epocware\Handy Safe Desktop Professional 3.01\WP7CommSvc.exe
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 11708 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\AVAST Software\Avast\afwServ.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
dashost.exe {d8bafeb8-8936-4894-a482df6a7bc0be62}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files (x86)\KMPConnect\KMPConnectService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Epocware\Handy Safe Desktop Professional 3.01\WP7CommSvc.exe"
"C:\Program Files (x86)\KMPConnect\KMPConnectCore.exe" KMP
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-2eb57dbb-754c-4176-b201-9db2aba80917 -SystemEventPortName:HostProcess-628ed74c-83df-45ce-a605-2bb17be3687b -IoCancelEventPortName:HostProcess-b7555170-b49d-4354-8e02-616b9f9b9266 -NonStateChangingEventPortName:HostProcess-ae3c208b-1862-4866-b386-e6131f9adde8 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:cab60f47-1c50-4caa-b666-0a820727f196 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-cd665352-7510-4f9c-8581-f345a6b474b7 -SystemEventPortName:HostProcess-5ced60ba-f1da-4920-8213-cc30af63421d -IoCancelEventPortName:HostProcess-78ee5190-bf22-4724-8070-63eecff1a1c5 -NonStateChangingEventPortName:HostProcess-d0951504-c49d-4f70-af02-fda05028abfd -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0fd32346-8abf-4cd6-9176-1ceafaaf9db3 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"\Program Files\Synaptics\SynTP\SynTPEnh.exe"
taskhostex.exe
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Windows\RTFTrack.exe"
"C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m
"C:\Program Files (x86)\Bluetooth Suite\BtTray.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Users\Honza\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
"C:\WINDOWS\system32\RunDll32.exe" "C:\Program Files\HP\HP Deskjet 3050 J610 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN14T3D3ZC05HX;CONNECTION=USB;MONITOR=1;
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe20_ Global\UsGthrCtrlFltPipeMssGthrPipe20 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 576 580 588 65536 584

"C:\Users\Honza\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\b7xsa7w0.default

prefs.js - "browser.startup.homepage" - "http://www.google.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.152 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2014-09-21 218776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-08-11 64640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-09-05 612248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-09-21 2334416]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-09-07 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-09-05 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-09-07 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Translat\WebIE.dll [2014-09-09 643072]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-08-10 13191824]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2012-08-06 1215632]
"RtsFT"=C:\WINDOWS\RTFTrack.exe [2012-08-27 6334096]
"SynLenovoGestureMgr"=C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [2012-08-16 665400]
"BtTray"=C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [2012-08-11 764032]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2012-08-11 127616]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-07-25 2403104]
"ShadowPlay"=C:\windows\system32\nvspcap64.dll [2014-07-25 1283136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-08-16 2916152]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2012-12-19 172168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2012-12-19 400008]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2012-12-19 441992]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2014-10-11 17080376]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2014-10-11 191544]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"f.lux"=C:\Users\Honza\AppData\Local\FluxSoftware\Flux\flux.exe [2013-10-24 1017224]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-09-26 6482200]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-09-05 4085896]

C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Sledovat výstrahy inkoustu - HP Deskjet 3050 J610 series.lnk - C:\WINDOWS\system32\RunDll32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\windows\system32\nvinitx.dll, C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2012-12-13 442880]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-18 10:15:56 ----D---- C:\rsit
2014-10-12 23:25:16 ----D---- C:\AdwCleaner
2014-10-12 21:11:08 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2014-10-12 21:10:50 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2014-10-12 21:10:50 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2014-10-12 21:10:50 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2014-10-12 21:10:49 ----D---- C:\ProgramData\Malwarebytes
2014-10-12 21:10:49 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-09 09:28:28 ----D---- C:\Users\Honza\AppData\Roaming\com.rovio.AngryBirdsBreakfast2
2014-10-09 08:34:52 ----D---- C:\Users\Honza\AppData\Roaming\com.rovio.AngryBirdsBreakfast1
2014-10-07 18:28:20 ----D---- C:\Program Files (x86)\Google
2014-10-06 23:57:10 ----SHD---- C:\ProgramData\SecuROM
2014-10-06 23:48:52 ----D---- C:\Program Files\Defraggler
2014-10-06 18:26:39 ----D---- C:\WINDOWS\SYSWOW64\xlive
2014-10-06 18:26:26 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2014-10-04 23:12:01 ----A---- C:\WINDOWS\SYSWOW64\AngryBirdsStarWarsInstaller.exe
2014-10-04 21:52:30 ----A---- C:\WINDOWS\SYSWOW64\AngryBirdsSeasonsInstaller.exe
2014-10-04 21:49:10 ----A---- C:\WINDOWS\SYSWOW64\AngryBirdsRioInstaller.exe
2014-10-04 08:28:28 ----D---- C:\Users\Honza\AppData\Roaming\Rovio
2014-10-03 17:06:00 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-10-03 17:06:00 ----A---- C:\WINDOWS\system32\shell32.dll
2014-10-03 17:05:59 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-10-03 17:05:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-10-03 17:05:58 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-10-03 17:05:57 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-10-03 17:05:57 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-10-03 17:05:57 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-10-03 17:05:56 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-10-03 17:05:56 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-10-03 17:05:56 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-10-03 17:05:55 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-10-03 17:05:55 ----A---- C:\WINDOWS\system32\propsys.dll
2014-10-03 17:05:55 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-10-03 17:05:53 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-10-03 17:05:53 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-10-03 17:05:52 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-10-03 17:05:52 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-10-03 17:05:52 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-10-03 17:05:52 ----A---- C:\WINDOWS\system32\Wldap32.dll
2014-10-03 17:05:52 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-10-03 17:05:51 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2014-10-03 17:05:51 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-10-03 17:05:51 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-10-03 17:05:50 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-10-03 17:05:50 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-10-03 17:05:50 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-10-03 17:05:50 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-10-03 17:05:50 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-10-03 17:05:49 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-10-03 17:05:49 ----A---- C:\WINDOWS\system32\pcsvDevice.dll
2014-10-03 17:05:49 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-10-03 17:05:48 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-10-03 17:05:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-03 17:05:46 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-03 17:05:46 ----A---- C:\WINDOWS\system32\ProximityService.dll
2014-10-03 17:02:24 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2014-10-03 17:02:24 ----A---- C:\WINDOWS\system32\authui.dll
2014-10-03 17:02:23 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-10-03 17:02:23 ----A---- C:\WINDOWS\system32\msi.dll
2014-10-03 17:02:23 ----A---- C:\WINDOWS\system32\appinfo.dll
2014-10-03 17:02:09 ----A---- C:\WINDOWS\system32\win32k.sys
2014-10-03 13:37:48 ----RHD---- C:\Users\Honza\AppData\Roaming\SecuROM
2014-10-03 13:37:46 ----A---- C:\WINDOWS\SYSWOW64\CmdLineExt_x64.dll
2014-10-01 15:56:39 ----D---- C:\NVIDIA Corporation
2014-09-30 21:13:56 ----D---- C:\Program Files\trend micro
2014-09-29 10:15:30 ----A---- C:\WINDOWS\yowindow.scr
2014-09-24 23:32:10 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-09-24 11:02:40 ----D---- C:\Users\Honza\AppData\Roaming\Kingosoft
2014-09-24 11:02:30 ----D---- C:\Program Files (x86)\Kingo ROOT
2014-09-23 08:23:54 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2014-09-23 08:23:46 ----D---- C:\WINDOWS\SYSWOW64\NV
2014-09-23 08:23:46 ----D---- C:\WINDOWS\system32\NV
2014-09-23 08:19:48 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2014-09-23 08:19:48 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\system32\nvopencl.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2014-09-23 08:19:47 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2014-09-23 08:19:46 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\nvdispgenco6434411.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\nvdispco6434411.dll
2014-09-23 08:19:46 ----A---- C:\WINDOWS\system32\drivers\nvlddmkm.sys
2014-09-23 08:19:45 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2014-09-23 08:19:45 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2014-09-23 08:19:45 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2014-09-23 08:19:45 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2014-09-23 08:19:45 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2014-09-23 08:19:45 ----A---- C:\WINDOWS\system32\nvcuda.dll
2014-09-23 08:19:44 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2014-09-23 08:14:07 ----D---- C:\Users\Honza\AppData\Roaming\avidemux
2014-09-22 18:37:51 ----D---- C:\Program Files\Avidemux 2.6 - 64bits
2014-09-21 21:18:36 ----D---- C:\Program Files\iPod
2014-09-21 21:18:35 ----D---- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-09-21 21:18:35 ----D---- C:\Program Files\iTunes
2014-09-21 21:18:35 ----D---- C:\Program Files (x86)\iTunes

======List of files/folders modified in the last 1 month======

2014-10-18 10:15:59 ----D---- C:\WINDOWS\Prefetch
2014-10-18 10:15:32 ----D---- C:\WINDOWS\system32\config
2014-10-18 10:06:09 ----D---- C:\WINDOWS\Temp
2014-10-18 10:00:01 ----D---- C:\WINDOWS\system32\sru
2014-10-18 09:59:53 ----RD---- C:\WINDOWS\System32
2014-10-18 09:59:53 ----D---- C:\WINDOWS\Inf
2014-10-18 09:59:53 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-16 21:47:48 ----D---- C:\WINDOWS\debug
2014-10-16 20:09:46 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-16 20:04:17 ----D---- C:\WINDOWS\AppReadiness
2014-10-12 23:31:04 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-10-12 23:28:54 ----D---- C:\Program Files (x86)\KMPConnect
2014-10-12 23:28:39 ----D---- C:\ProgramData\NVIDIA
2014-10-12 23:27:45 ----RD---- C:\Program Files
2014-10-12 23:06:10 ----D---- C:\Windows
2014-10-12 23:06:06 ----RD---- C:\Program Files (x86)
2014-10-12 23:06:06 ----D---- C:\WINDOWS\vpnplugins
2014-10-12 23:06:06 ----D---- C:\WINDOWS\system32\drivers
2014-10-12 23:05:03 ----A---- C:\WINDOWS\win.ini
2014-10-12 22:45:48 ----D---- C:\WINDOWS\SoftwareDistribution
2014-10-12 21:10:49 ----HD---- C:\ProgramData
2014-10-11 23:10:04 ----D---- C:\The KMPlayer
2014-10-11 07:09:06 ----D---- C:\WINDOWS\system32\drivers\UMDF
2014-10-11 07:08:56 ----SHD---- C:\WINDOWS\Installer
2014-10-11 07:08:56 ----D---- C:\WINDOWS\SYSWOW64\drivers
2014-10-11 07:08:28 ----SHD---- C:\System Volume Information
2014-10-11 07:07:16 ----A---- C:\WINDOWS\system32\LenovoSDKEmSubSystem.dll
2014-10-11 07:06:54 ----D---- C:\drivers
2014-10-10 18:30:03 ----HD---- C:\Program Files\WindowsApps
2014-10-09 22:10:43 ----D---- C:\Program Files\MPC-HC
2014-10-09 20:08:10 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-09 20:08:10 ----D---- C:\Program Files (x86)\Lenovo
2014-10-09 10:34:34 ----D---- C:\WINDOWS\system32\DriverStore
2014-10-09 09:55:44 ----D---- C:\Users\Honza\AppData\Roaming\Rovio Entertainment Ltd
2014-10-09 09:55:24 ----D---- C:\Users\Honza\AppData\Roaming\NVIDIA
2014-10-09 09:28:23 ----D---- C:\Hry
2014-10-08 15:01:28 ----D---- C:\Program Files (x86)\FastShare
2014-10-07 21:29:58 ----SD---- C:\Users\Honza\AppData\Roaming\Microsoft
2014-10-07 18:28:22 ----D---- C:\WINDOWS\Tasks
2014-10-07 18:28:22 ----D---- C:\WINDOWS\system32\Tasks
2014-10-07 06:42:40 ----D---- C:\WINDOWS\rescache
2014-10-06 23:51:13 ----D---- C:\Users\Honza\AppData\Roaming\DAEMON Tools Lite
2014-10-06 23:50:58 ----DC---- C:\WINDOWS\Panther
2014-10-06 23:50:57 ----D---- C:\WINDOWS\Logs
2014-10-06 18:56:34 ----D---- C:\WINDOWS\WinSxS
2014-10-06 18:51:57 ----RD---- C:\WINDOWS\ToastData
2014-10-06 18:51:57 ----D---- C:\WINDOWS\SysWOW64
2014-10-06 18:51:55 ----D---- C:\WINDOWS\WinStore
2014-10-06 18:32:10 ----D---- C:\Program Files\CCleaner
2014-10-06 18:25:49 ----SD---- C:\ProgramData\Microsoft
2014-10-06 18:02:29 ----SHD---- C:\$Recycle.Bin
2014-10-06 17:52:59 ----D---- C:\Users\Honza\AppData\Roaming\vlc
2014-10-04 08:32:50 ----D---- C:\Zálohy
2014-10-04 01:18:07 ----RSD---- C:\WINDOWS\assembly
2014-10-03 17:06:57 ----D---- C:\WINDOWS\CbsTemp
2014-10-03 17:06:43 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2014-10-03 17:06:43 ----D---- C:\WINDOWS\SYSWOW64\en-US
2014-10-03 17:06:43 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-10-03 17:06:42 ----D---- C:\WINDOWS\system32\ru-RU
2014-10-03 17:06:42 ----D---- C:\WINDOWS\system32\en-US
2014-10-03 17:06:42 ----D---- C:\WINDOWS\system32\cs-CZ
2014-10-03 09:35:20 ----D---- C:\WINDOWS\system32\wdi
2014-10-03 09:30:17 ----D---- C:\WINDOWS\L2Schemas
2014-10-01 15:57:41 ----D---- C:\Program Files\WinRAR
2014-10-01 15:57:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-01 15:56:43 ----D---- C:\WINDOWS\system32\catroot
2014-10-01 15:56:18 ----D---- C:\Program Files (x86)\Amazon
2014-09-29 19:05:20 ----D---- C:\WINDOWS\LiveKernelReports
2014-09-28 21:36:41 ----D---- C:\Program Files (x86)\Common Files
2014-09-24 10:54:34 ----D---- C:\FFOutput
2014-09-23 08:24:03 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-09-23 08:21:18 ----D---- C:\WINDOWS\system32\catroot2
2014-09-21 22:06:53 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-09-21 22:05:17 ----D---- C:\Program Files\Microsoft Office 15
2014-09-21 21:12:02 ----D---- C:\Users\Honza\AppData\Roaming\HpUpdate

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswNdisFlt;@oem71.inf,%AfwDescriptionFree%;Avast! Firewall Driver; C:\WINDOWS\system32\DRIVERS\aswNdisFlt.sys [2014-09-05 448400]
R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-09-05 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-09-05 224896]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-07-09 645952]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2014-10-11 39008]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2014-09-14 32576]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2014-09-05 28184]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-09-05 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-09-05 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-09-05 427360]
R1 dtsoftbus01;@oem66.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-09-04 283064]
R1 Eve;@oem79.inf,%EVE_Desc%;EVE Protocol Driver; C:\WINDOWS\system32\DRIVERS\eve.sys [2014-01-23 41304]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-09-05 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-09-05 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-09-05 92008]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-07-16 35344]
R3 ACPIVPC;@oem47.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2012-11-04 33560]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-04-28 599240]
R3 BthA2DP;@wdma_bt.inf,%BthA2DP.SvcDesc%;Bluetooth stereo; C:\WINDOWS\system32\drivers\BthA2DP.sys [2013-08-22 131584]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-03-18 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-03-18 81920]
R3 clwvd;@oem53.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2012-06-26 36336]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2012-12-13 5353888]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-08-10 4102928]
R3 IntcDAud;@oem35.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem63.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-05-07 27032]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2014-05-12 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2014-10-18 122584]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2014-05-12 64216]
R3 MEIx64;@oem58.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-03 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-09-14 13157696]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-07-25 20256]
R3 nvvad_WaveExtensible;@oem55.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-03-18 167424]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 rtsuvc;@oem6.inf,%rtsuvc.DeviceDesc%;Lenovo EasyCamera; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [2012-08-27 8227216]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2012-08-16 43832]
R3 SynTP;@oem38.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2012-08-16 447800]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BTATH_LWFLT;@oem52.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys []
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem68.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 intaud_WaveExtensible;@oem62.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2014-05-07 38296]
S3 RSUSBVSTOR;@oem57.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2012-06-13 315536]
S3 ssudmdm;@oem70.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 USBAAPL64;@oem84.inf,%USBAAPL64.SvcDesc%;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl64.sys [2014-07-28 54784]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-08-28 43336]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2012-08-11 211584]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-09-05 50344]
R2 avast! Firewall;avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [2014-09-05 106488]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-08-12 2428088]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-05-21 314696]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-05-12 860472]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-05-12 1809720]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-07-25 1720608]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-07-25 18956064]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-09-13 934216]
R2 ServiceKAirModule;Service_KAir; C:\Program Files (x86)\KMPConnect\KMPConnectService.exe [2014-05-19 389232]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-09-13 411968]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-07 116648]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2012-12-19 277640]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-07 116648]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-09-01 640840]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-24 114288]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-08-14 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-09-23 833728]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#38 Příspěvek od Márty84 »

:arrow: Zopakujte krok s ADWCleanerem.


:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte


:arrow: Postupujte podle navodu kolegy
vyosek píše: :arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#39 Příspěvek od xtractorek »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 8.1 x64
Ran by Honza on so 18. 10. 2014 at 15:56:04,28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 18. 10. 2014 at 16:04:49,31
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Zoek:

Zoek.exe v5.0.0.0 Updated 20-September-2014
Tool run by Honza on so 18. 10. 2014 at 16:10:36,39.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Honza\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

18. 10. 2014 16:11:49 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\b7xsa7w0.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.cz/");

Added to C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\b7xsa7w0.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

==== Deleting Files \ Folders ======================

C:\MRDownloader.exe deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [05. 09. 2014 00:11]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\b7xsa7w0.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Speed Dial - %ProfilePath%\extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\b7xsa7w0.default
63F8C13F269B10BC9363B007DAAACAE6 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll - Shockwave Flash
D6ED6EB98E759460AD8C66DE23070132 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll - Microsoft Office 2013
18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Microsoft Office\Office15\NPSPWRAP.DLL - Microsoft Office 2013


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[05. 09. 2014 00:11]

Angry Birds - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Photo Zoom for Facebook - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi
AdBlock - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
avast Online Security - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Downloads - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfchnphgogjhineanplmfkofljiagjfb
Speed Dial 2 - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik
Save to foursquare - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcpkpffnipnldeicdmdidbodfdjmloep
Any.do Extension - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdadialhpiikehpdeejjeiikopddkjem
Spockholm Mafia Toolbar - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmnlgpakocffbjcgfibfdmgmfhjgepni

==== Chromium Fix ======================

C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik deleted successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage deleted successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage-journal deleted successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0 deleted successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmnlgpakocffbjcgfibfdmgmfhjgepni deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=139 folders=21 2387873 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Honza\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Honza\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on so 18. 10. 2014 at 19:21:03,91 ======================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#40 Příspěvek od Márty84 »

Jak to vypada? Zmenilo se neco?
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#41 Příspěvek od xtractorek »

Těžko říct, na virus to nevypadá, ale asi zanechal nějaké pozůstatky nebo spíš něco poškodil, co nevýlečí ani antivir nebo nějaký nástroj.

Nefunguje totiž žádný program, který se připojuje k internetu. Připojení mám normálně aktivní, internetovou stránku otevřu bez problémů, ale Outlook na poštu se nedokáže připojit a stáhnout maily,
program na počasí nestáhne předpověď, Windows store ve Windows 8.1 nelze spustit :( hned spadne na začátku.
Nefunguje ani příkaz wsreset.exe, když ho chci provést, vypíše se chybová hláška
ms-windows-store:PurgeCaches

Aplikace nebyla spuštěna.


Díval jsem se na Avast firewall jestli není někde problém, zkusil jsem ho vypnout a zkusil jsem i vypnout Firewall ve Windows, ale nepomohlo to, ty programy se nepřipojí (Outlook, počasí) a nedokážou
stáhnout data, i když připojen k internetu počítač je.

Holt asi nezbývá nic jiného, než zformátovat disk a přeinstalovat systém. Tohle se mi ještě nikdy nestalo a nesmím příště nechávat počítač mladšímu sourozenci, nebo ho nechat bez dozoru. Počítač mám na práci a takhle to zničit :(

Pokud vás ještě cokoliv napadne, dejte vědět, ale asi sám uznáte, že v tomhle případě už moc možností asi nezbývá.
Každopádně vám moc děkuji za vaši trpělivost a cené rady :)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#42 Příspěvek od Márty84 »

Vzdyt to potom prvnim vycisteni fungovalo :?: Co jste tam pak provadeli? :shock:

Zkuste, jak se pc chova v nouzovem rezimu s praci v siti.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Uživatelský avatar
xtractorek
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 173
Registrován: 01 čer 2007 16:39
Bydliště: Praha
Kontaktovat uživatele:

Re: Prosím o preventivní kontrolu

#43 Příspěvek od xtractorek »

Netuším jak se dostat do toho nouzového režimu, zkusil jsem 3x restart a mačkal při tom DEL nebo F8 a stejně PC najel klasicky jako vždy. Po dalším restartu se objevil nějaký error, že počítač byl neočekávaně ukončen a že dojde k obnovení systému. Nějak se to obnovilo a celý počítač najel zase klasicky do Windows, ovšem vypadal jakoby se přeinstaloval systém, ale disk byl stále zaplněn stejně, navíc stále nefungovala řada věcí jako předtím.

Nechtělo se mi do toho, ale došla mi trpělivost, zazálohoval jsem důležité data a provedl kompletní formát disku a reinstal systému. Počítač mám teď nastaven heslem a budu si ho více hlídat.

Vám moc děkuji za váš čas a veškerou pomoc, pomohl jste mi i tak a nikdo nemohl tušit, že to skončí takhle. Asi by mi ani nic nezbývalo. Takže toto téma asi můžete zamknout :)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o preventivní kontrolu

#44 Příspěvek od Márty84 »

No reinstal je taky moznost a nekdy i rychlejsi :) Ale taky to neni vselek, nektera havet prezije i format :boxed:

Nemate tedy zac! ;-)

Jinak kdyby nahodou, tak do nouzoveho rezimu se dostanete i takto http://forum.viry.cz/viewtopic.php?f=46&t=7554

Mejte se a treba zase nekdy :bye:

:closed:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno