Stránka 1 z 1

problém s viry v pc

Napsal: 30 led 2013 12:39
od Mikkk
Dobrý den, prosím o rady co mám dělat, na facebooku mě přišla zpráva s virem a teď mám zavirovaný pc
  • 29 1 2013 23:57:17 - ERROR!!! Invalid Entry \??\C:\Program Files (x86)\BurnInTest\DirectIo.sys in HKLM\SYSTEM\CurrentControlSet\Services\DIRECTIO. Action Taken: No Action Taken.
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\ehome\ehRecvr.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\ehome\ehsched.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\es.dll
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    29 1 2013 23:57:17 - Scanning File C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:17 - Scanning File C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    29 1 2013 23:57:18 - Scanning File C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    29 1 2013 23:57:18 - Scanning File C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\hidserv.dll
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\provsvc.dll
    29 1 2013 23:57:18 - Scanning File C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:18 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:19 - Scanning File C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
    29 1 2013 23:57:19 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:19 - Scanning File C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (????)
    29 1 2013 23:57:19 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:19 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:19 - Scanning File C:\Windows\system32\msiexec.exe
    29 1 2013 23:57:20 - Scanning File c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    29 1 2013 23:57:20 - Scanning File c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
    29 1 2013 23:57:20 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:20 - Scanning File C:\Program Files (x86)\Nero\Update\NASvc.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\System32\netprofm.dll
    29 1 2013 23:57:20 - Scanning File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:20 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:20 - Scanning File C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
    29 1 2013 23:57:21 - Scanning File C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\SysWow64\perfhost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\pla.dll
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\PnkBstrA.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:21 - Scanning File c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\system32\qwave.dll
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:21 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\System32\mprdim.dll
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    29 1 2013 23:57:22 - Scanning File C:\Program Files (x86)\WinPcap\rpcapd.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:22 - Scanning File C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    29 1 2013 23:57:23 - Scanning File C:\Users\Administráto\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe (????)
    29 1 2013 23:57:23 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:23 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:23 - Scanning File C:\Windows\System32\sens.dll
    29 1 2013 23:57:23 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:23 - Scanning File C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
    29 1 2013 23:57:23 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:23 - Scanning File C:\Windows\system32\sessenv.dll
    29 1 2013 23:57:23 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:23 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:23 - Scanning File C:\Windows\System32\shsvcs.dll
    29 1 2013 23:57:24 - Scanning File C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
    29 1 2013 23:57:24 - Scanning File c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
    29 1 2013 23:57:24 - Scanning File c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    29 1 2013 23:57:24 - Scanning File c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\tapisrv.dll
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:24 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\WINDOWS\SYSTEM32\DRIVERS\TFSEXDISK.SYS
    29 1 2013 23:57:25 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\servicing\TrustedInstaller.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\PROGRAM FILES (X86)\UNLOCKER\UNLOCKERDRIVER5.SYS (????)
    29 1 2013 23:57:25 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\System32\upnphost.dll
    29 1 2013 23:57:25 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe (????)
    29 1 2013 23:57:25 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:25 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\wcncsvc.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\WcsPlugInService.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\wdi.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\wdi.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\webclnt.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\drivers\wimmount.sys
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Program Files\Windows Defender\mpsvc.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\winhttp.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\WsmSvc.dll
    29 1 2013 23:57:26 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:27 - Scanning File C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
    29 1 2013 23:57:27 - Scanning File C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    29 1 2013 23:57:27 - Scanning File C:\Program Files\Windows Media Player\wmpnetwk.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\System32\wpcsvc.dll
    29 1 2013 23:57:27 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\System32\svchost.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\system32\SearchIndexer.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\system32\svchost.exe
    29 1 2013 23:57:27 - Scanning File C:\Windows\system32\svchost.exe

Re: problém s viry v pc

Napsal: 30 led 2013 12:52
od vyosek
Zdravim a pekny den preji :)

:arrow: Dejte log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=105895

Re: problém s viry v pc

Napsal: 30 led 2013 13:01
od Mikkk
děkuji za reakci a tady je log

Logfile of random's system information tool 1.09 (written by random/random)
Run by Administráto at 2013-01-30 12:53:33
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 7 GB (1%) free of 610 GB
Total RAM: 4086 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:53:54, on 30.1.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Windows\syswow64\svchost.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\Administráto\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Windows\SysWOW64\svchost.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Users\Administráto\6438640620394286720310355\winsvc.exe
C:\Program Files (x86)\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe
C:\Program Files (x86)\lg_fwupdate\fwupdate.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Users\ADMINI~1\AppData\Local\Temp\mexe.com
C:\Users\ADMINI~1\AppData\Local\Temp\90CE.tmp
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Administráto.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\20101127143452\ICQToolBar.dll
R3 - URLSearchHook: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files (x86)\Hot_MP3\tbHot_.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O1 - Hosts: 192.157.56.28 www.google-analytics.com.
O1 - Hosts: 192.157.56.28 ad-emea.doubleclick.net.
O1 - Hosts: 192.157.56.28 www.statcounter.com.
O1 - Hosts: 192.157.56.28 connect.facebook.net.
O1 - Hosts: 192.157.56.28 platform.twitter.com.
O1 - Hosts: 93.115.241.27 www.google-analytics.com.
O1 - Hosts: 93.115.241.27 ad-emea.doubleclick.net.
O1 - Hosts: 93.115.241.27 www.statcounter.com.
O1 - Hosts: 93.115.241.27 connect.facebook.net.
O1 - Hosts: 93.115.241.27 platform.twitter.com.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files (x86)\Hot_MP3\tbHot_.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files (x86)\ICQ6Toolbar\20101127143452\ICQToolBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files (x86)\Hot_MP3\tbHot_.dll
O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [EEventManager] C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files (x86)\lg_fwupdate\lgfw.exe" blrun
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [mwavscan_autoscan] "C:\Users\ADMINI~1\AppData\Local\Temp\mexe.com" /s /AUTORUNBOOT
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [SansaDispatch] C:\Users\Administráto\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Google Update] "C:\Users\Administráto\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [Microsoft Windows Service] C:\Users\Administráto\6438640620394286720310355\winsvc.exe
O4 - HKCU\..\Run: [pdoubrhgfjkxeiqndts] C:\Users\Administr to\AppData\Roaming\pdoubrhgfjkxeiqndts.exe
O4 - HKCU\..\Run: [HotKeysCmds] C:\Users\ADMINI~1\AppData\Local\Temp\B2BF.EXE
O4 - HKLM\..\Policies\Explorer\Run: [87] C:\PROGRA~3\Local Settings\Temp\mslvovx.com
O4 - HKCU\..\Policies\Explorer\Run: [GameSpy] C:\Users\Administráto\AppData\Roaming\EF0057\EF0057.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Adobe Live.lnk = C:\Program Files (x86)\JRE\Folding@home.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files (x86)\ICQ7.0\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SearchAnonymizer - Unknown owner - C:\Users\Administráto\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater14.0.1 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 20645 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\AVG\AVG9\avgnsa.exe"
"C:\Program Files (x86)\AVG\AVG9\avgrsa.exe"
"C:\Program Files (x86)\AVG\AVG9\avgchsva.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe"
/pipeName=53f1a741-f254-4ff9-8fed-e383ca6f47d7 /coreSdkOptions=30 /logConfFile="C:\ProgramData\avg9\temp\b7ee3222-cd49-4d0a-a5cd-5bd4ae415521-980-oopp.tmp" /loggerName=AVG.RS.Core /binaryPath="C:\Program Files (x86)\AVG\AVG9\" /tempPath="C:\ProgramData\avg9\temp\"
"C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe"
"C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
"C:\Users\Administráto\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe"
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\AVG\AVG9\avgemc.exe"
"C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe"
WLIDSvcM.exe 3092
/pipeName=da3bbc7c-e174-45cb-9f00-f4c1cff96f62 /coreSdkOptions=0 /binaryPath="C:\Program Files (x86)\AVG\AVG9\"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c7b45457-1809-4174-9516-d3774d0ab436 -SystemEventPortName:HostProcess-456a5bdf-6575-45b7-83a6-1089ffbdb959 -IoCancelEventPortName:HostProcess-f3e4cb90-aec5-4b70-8572-8303d7b34aea -NonStateChangingEventPortName:HostProcess-4947a090-a7ea-4112-ac94-424d39bcdfa7 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3fb188b0-a286-498e-b44c-adf1e0d5e44e -DeviceGroupId:WpdFsGroup
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
C:\Windows\syswow64\svchost.exe
"C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" -hidden
"C:\Users\Administráto\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe"
"C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
svchost.exe
"C:\Program Files (x86)\Samsung\Kies\Kies.exe" /preload
"C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe"
"C:\Users\Administráto\6438640620394286720310355\winsvc.exe"
"C:\Program Files (x86)\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\AVG\AVG9\avgtray.exe"
"C:\Program Files (x86)\epson\Creativity Suite\Event Manager\EEventManager.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe"
"C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
"C:\Program Files (x86)\AVG Secure Search\vprot.exe"
"C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe"
"C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe"
"C:\Program Files (x86)\lg_fwupdate\fwupdate.exe" blrun
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
{4AAC263D-13F3-4F17-8597-705A1952F23A}
{D9A8FF18-1514-493B-B483-2CB629B7AA10}
{3431F1C2-A470-46D6-BD2A-ABB1E6435036}
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Users\ADMINI~1\AppData\Local\Temp\mexe.com"
"C:\Users\ADMINI~1\AppData\Local\Temp\90CE.tmp"
"taskhost.exe"
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe"
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/8/OneClickSignIn/Standard/Prerender/PrerenderEnabled/SBInterstitial/V2/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --extension-process --renderer-print-preview --channel="3080.0.1935527112\1063618658" /prefetch:3
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3080.1.496994407\1799279746" --supports-dual-gpus=false --skip-gpu-full-info-collection --gpu-vendor-id=0x1002 --gpu-device-id=0x6898 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=9.12.0.0 --ignored=" --type=renderer " /prefetch:12
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\\npsitesafety.dll" --lang=cs --channel="3080.2.27097587\823797039" /prefetch:4
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3080.4.126058831\1005752783" --lang=cs --ignored=" --type=renderer " /prefetch:13
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/8/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="3080.14.1602656866\613195406" /prefetch:3
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/8/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="3080.31.1424370803\75214665" /prefetch:3
"C:\Users\Administráto\AppData\Local\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=CacheSensitivityAnalysis/No/EnableStage3D/enabled/ForceCompositingMode/enabled/GlobalSdch/global_enable_sdch/InfiniteCache/No/NewTabButton/default/OmniboxDisallowInlineHQP/Standard/OmniboxHQPNewScoring/Standard/OmniboxHUPCreateShorterMatch/Standard/OmniboxHUPCullRedirects/Standard/OmniboxSearchSuggestTrialStarted2012Q4/8/OneClickSignIn/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/SBInterstitial/V2/SpdyCwnd/cwndDynamic/SpeculativePrefetching/Disabled/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-1-Percent/group_56/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_14/UMA-Uniformity-Trial-50-Percent/group_01/WarmSocketImpact/last_accessed_socket/ --renderer-print-preview --channel="3080.36.514493846\97849892" /prefetch:3
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe17_ Global\UsGthrCtrlFltPipeMssGthrPipe17 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 536 540 548 65536 544
"C:\Users\Administráto\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\AUDIODG.EXE 0x928

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\COMODO System Cleaner Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1417383624-3162349305-401947947-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1417383624-3162349305-401947947-1000UA.job
C:\Windows\tasks\ROC_JAN2013_TB_rmv.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default

prefs.js - "browser.startup.homepage" - "http://isearch.avg.com/?cid={1C6D8F9E-7 ... 2011-12-12 11:27:33&v=14.0.2.14&pid=avg&sg=&sap=hp"
prefs.js - "extensions.enabledItems" - "DTToolbar@toolbarnet.com:1.1.1.0014, {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.1, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4, {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03, avg@igeared:6.103.018.001, toolbar@ask.com:3.11.3.15590, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.15"
prefs.js - "keyword.URL" - "http://isearch.avg.com/search?cid={1C6D ... 2011-12-12 11:27:33&pid=avg&sg=&v=14.0.2.14&sap=ku&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.0.1\\npsitesafety.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732]
"Description"=6.0.12.732
"Path"=C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.5.502.146 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsJSRealPlayerPlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
npEModelPlugin.dll
NPOFF12.DLL
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
nsEModelPlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
avg-secure-search.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\extensions\
DTToolbar@toolbarnet.com
toolbar@ask.com
{800b5000-a755-47e1-992b-48a1c1357f07}

C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\searchplugins\
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-12.xml
icqplugin-13.xml
icqplugin-14.xml
icqplugin-15.xml
icqplugin-16.xml
icqplugin-17.xml
icqplugin-18.xml
icqplugin-19.xml
icqplugin-2.xml
icqplugin-20.xml
icqplugin-21.xml
icqplugin-22.xml
icqplugin-23.xml
icqplugin-24.xml
icqplugin-25.xml
icqplugin-26.xml
icqplugin-27.xml
icqplugin-28.xml
icqplugin-29.xml
icqplugin-3.xml
icqplugin-30.xml
icqplugin-31.xml
icqplugin-32.xml
icqplugin-33.xml
icqplugin-34.xml
icqplugin-35.xml
icqplugin-36.xml
icqplugin-37.xml
icqplugin-38.xml
icqplugin-39.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml
sweetim.xml
{3DA5AB50-FF2B-4204-9B93-66926F3CB021}.xml
{60B4ACFC-DF24-4435-93BA-9FB99AC305DD}.xml
{73E3B25A-1ED4-46B7-915B-D1192B81FCAF}.xml
{BFA7454B-F309-4F7E-8846-01E7CDCA386F}.xml
{CB4EA28D-1D41-40E0-9665-1F4D556E1C58}.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll [2010-11-24 2334560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-05-12 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files (x86)\AVG\AVG9\avgssie.dll [2010-11-24 1623392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-09-22 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Hot MP3 Toolbar - C:\Program Files (x86)\Hot_MP3\tbHot_.dll [2010-02-22 2353176]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll [2013-01-24 1883824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll [2009-11-24 1536456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files (x86)\ICQ6Toolbar\20101127143452\ICQToolBar.dll [2010-10-04 1049912]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]
{9384bd4c-dd14-4be9-80f7-f6277511e4f5} - Hot MP3 Toolbar - C:\Program Files (x86)\Hot_MP3\tbHot_.dll [2010-02-22 2353176]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Nero Toolbar - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [2011-05-17 1490312]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files (x86)\AVG Secure Search\14.0.2.14\AVG Secure Search_toolbar.dll [2013-01-24 1883824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Ocs_SM"=C:\Users\Administráto\AppData\Roaming\OCS\SM\SearchAnonymizer.exe [2010-05-17 106496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"87"=C:\PROGRA~3\Local Settings\Temp\mslvovx.com [2009-07-14 62976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"RGSC"=C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2010-02-20 306088]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2009-08-20 2363392]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"SansaDispatch"=C:\Users\Administráto\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe [2012-11-05 79872]
"PC Suite Tray"=C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-06-25 1414144]
"Google Update"=C:\Users\Administráto\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-19 136176]
"KiesPDLR"=C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2012-12-20 844296]
"Steam"=C:\Program Files (x86)\Steam\Steam.exe [2012-12-04 1354736]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2012-12-20 1476104]
""=C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2012-12-20 844296]
"Microsoft Windows Service"=C:\Users\Administráto\6438640620394286720310355\winsvc.exe [2013-01-29 66560]
"pdoubrhgfjkxeiqndts"=C:\Users\Administr to\AppData\Roaming\pdoubrhgfjkxeiqndts.exe []
"HotKeysCmds"=C:\Users\ADMINI~1\AppData\Local\Temp\B2BF.EXE []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"GameSpy"=C:\Users\Administráto\AppData\Roaming\EF0057\EF0057.exe [2010-11-20 29696]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ATICustomerCare"=C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [2009-06-14 307200]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2009-06-05 2171904]
"AVG9_TRAY"=C:\PROGRA~2\AVG\AVG9\avgtray.exe [2012-01-26 2077536]
"EEventManager"=C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe [2006-03-17 102400]
"UpdateLBPShortCut"=C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"CLMLServer"=C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2009-06-03 103720]
"UpdateP2GoShortCut"=C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"RemoteControl8"=C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [2009-04-15 91432]
"PDVD8LanguageShortcut"=C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [2009-04-15 50472]
"UpdatePPShortCut"=C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"UCam_Menu"=C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2009-02-17 218408]
"LGODDFU"=C:\Program Files (x86)\lg_fwupdate\lgfw.exe [2012-07-17 27760]
"UpdatePSTShortCut"=C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2009-09-29 210216]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-01-03 843712]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"TkBellExe"=C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe [2010-05-12 202256]
"SunJavaUpdateSched"=C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]
"NBAgent"=C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2010-03-26 1234216]
""= []
"ApnUpdater"=C:\Program Files (x86)\Ask.com\Updater\Updater.exe [2011-05-17 395144]
"vProt"=C:\Program Files (x86)\AVG Secure Search\vprot.exe [2013-01-24 1101488]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2012-12-20 310280]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-12-19 642808]
"UnlockerAssistant"=C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe [2010-03-09 15872]
"mwavscan_autoscan"=C:\Users\ADMINI~1\AppData\Local\Temp\mexe.com [2009-11-06 2329160]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"87"=C:\PROGRA~3\Local Settings\Temp\mslvovx.com [2009-07-14 62976]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
LUMIX Simple Viewer.lnk - C:\Program Files (x86)\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe

C:\Users\Administráto\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Live.lnk - C:\Program Files (x86)\JRE\Folding@home.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe"="C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe:*:Enabled:TriDef 3D Media Player"
"C:\Users\Administráto\6438640620394286720310355\winsvc.exe"="C:\Users\Administráto\6438640620394286720310355\winsvc.exe:*:Enabled:Microsoft Windows Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-01-30 12:53:34 ----D---- C:\Program Files\trend micro
2013-01-30 12:53:33 ----D---- C:\rsit
2013-01-29 23:30:55 ----AD---- C:\Windows\VDLL.DLL
2013-01-29 23:30:55 ----AD---- C:\Windows\SYSWOW64\runouce.exe
2013-01-29 23:30:55 ----AD---- C:\Windows\rundll16.exe
2013-01-29 23:30:55 ----AD---- C:\Windows\RUNDL132.EXE
2013-01-29 23:30:55 ----AD---- C:\Windows\logo1_.exe
2013-01-29 23:30:55 ----AD---- C:\Windows\logo_1.exe
2013-01-29 23:19:56 ----A---- C:\Windows\SYSWOW64\msvcp80.dll
2013-01-29 23:19:55 ----A---- C:\Windows\SYSWOW64\eEmpty.exe
2013-01-29 23:19:47 ----D---- C:\ProgramData\MicroWorld
2013-01-29 21:48:34 ----A---- C:\Users\Administráto\AppData\Roaming\nMNtffsdf5ev.exe
2013-01-29 21:07:14 ----D---- C:\ProgramData\Local Settings
2013-01-29 21:07:09 ----A---- C:\Users\Administráto\AppData\Roaming\nMNtfaARw2l97e30p5ev.exe
2013-01-29 21:07:05 ----AH---- C:\Users\Administráto\AppData\Roaming\winsvcns.sys
2013-01-20 19:05:04 ----D---- C:\ProgramData\ATI
2013-01-20 19:05:00 ----D---- C:\Program Files (x86)\AMD AVT
2013-01-20 19:04:55 ----D---- C:\Program Files (x86)\AMD APP
2013-01-20 19:00:40 ----A---- C:\Windows\system32\drivers\AtihdW76.sys
2013-01-20 19:00:40 ----A---- C:\Windows\system32\coinst_9.012.dll
2013-01-20 19:00:40 ----A---- C:\Windows\system32\ativvaxy_cik_nd.dat
2013-01-20 19:00:39 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2013-01-20 19:00:39 ----A---- C:\Windows\system32\ativvaxy_cik.dat
2013-01-20 19:00:39 ----A---- C:\Windows\system32\ativce02.dat
2013-01-20 19:00:38 ----A---- C:\Windows\system32\atitmm64.dll
2013-01-20 19:00:37 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2013-01-20 19:00:36 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2013-01-20 19:00:36 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atio6axx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atimuixx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atimpc64.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atiicdxx.dat
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atiglpxx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atig6txx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atig6pxx.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atiesrxx.exe
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atiedu64.dll
2013-01-20 19:00:36 ----A---- C:\Windows\system32\atieclxx.exe
2013-01-20 19:00:36 ----A---- C:\Windows\system32\amdpcom64.dll
2013-01-20 19:00:35 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2013-01-20 19:00:35 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2013-01-20 19:00:35 ----A---- C:\Windows\system32\aticalrt64.dll
2013-01-20 19:00:34 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2013-01-20 19:00:34 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2013-01-20 19:00:34 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2013-01-20 19:00:34 ----A---- C:\Windows\SYSWOW64\ati2edxx.dll
2013-01-20 19:00:34 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2013-01-20 19:00:34 ----A---- C:\Windows\system32\aticaldd64.dll
2013-01-20 19:00:34 ----A---- C:\Windows\system32\aticalcl64.dll
2013-01-20 19:00:34 ----A---- C:\Windows\system32\atiapfxx.exe
2013-01-19 11:58:33 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-01-10 01:23:16 ----D---- C:\bbbe4d066e61f4ce11b743a7
2013-01-09 12:34:53 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2013-01-09 12:34:53 ----A---- C:\Windows\system32\win32spl.dll
2013-01-09 12:34:50 ----A---- C:\Windows\system32\msxml6.dll
2013-01-09 12:34:49 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2013-01-09 12:34:49 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2013-01-09 12:34:49 ----A---- C:\Windows\system32\msxml3.dll
2013-01-09 12:34:48 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2013-01-09 12:34:48 ----A---- C:\Windows\system32\ncrypt.dll
2013-01-09 12:34:47 ----A---- C:\Windows\SYSWOW64\usp10.dll
2013-01-09 12:34:47 ----A---- C:\Windows\system32\usp10.dll
2013-01-09 12:34:45 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2013-01-09 12:34:45 ----A---- C:\Windows\SYSWOW64\gameux.dll
2013-01-09 12:34:45 ----A---- C:\Windows\system32\Wpc.dll
2013-01-09 12:34:45 ----A---- C:\Windows\system32\gameux.dll
2013-01-09 12:34:32 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-01-09 12:34:32 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-01-09 12:34:32 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-01-09 12:34:32 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2013-01-09 12:34:32 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\wow64win.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\wow64cpu.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\wow64.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\winsrv.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\ntvdm64.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\KernelBase.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\kernel32.dll
2013-01-09 12:34:32 ----A---- C:\Windows\system32\conhost.exe
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-01-09 12:34:31 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-01-09 12:34:31 ----A---- C:\Windows\SYSWOW64\user.exe
2013-01-09 12:34:31 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-01-09 12:34:31 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-01-09 12:34:25 ----A---- C:\Windows\system32\taskhost.exe
2013-01-09 12:34:24 ----A---- C:\Windows\system32\win32k.sys

======List of files/folders modified in the last 1 month======

2013-01-30 12:53:44 ----D---- C:\Windows\Prefetch
2013-01-30 12:53:34 ----RD---- C:\Program Files
2013-01-30 12:05:02 ----SHD---- C:\Windows\Installer
2013-01-30 11:22:07 ----D---- C:\Windows\system32\drivers\etc
2013-01-30 07:33:31 ----D---- C:\Windows\system32\config
2013-01-30 07:16:10 ----D---- C:\Windows\Temp
2013-01-29 23:52:29 ----D---- C:\Program Files (x86)\lg_fwupdate
2013-01-29 23:52:27 ----A---- C:\Windows\lgfwup.ini
2013-01-29 23:33:12 ----D---- C:\Windows\system32\Tasks
2013-01-29 23:30:55 ----D---- C:\Windows\SysWOW64
2013-01-29 23:30:55 ----D---- C:\Windows
2013-01-29 23:19:51 ----D---- C:\Program Files (x86)\Common Files
2013-01-29 23:19:47 ----HD---- C:\ProgramData
2013-01-29 23:00:33 ----D---- C:\Program Files (x86)\Steam
2013-01-29 22:59:14 ----SHD---- C:\System Volume Information
2013-01-29 22:57:21 ----D---- C:\Windows\system32\wbem
2013-01-29 22:56:03 ----D---- C:\Windows\system32\catroot2
2013-01-29 22:56:02 ----D---- C:\Windows\registration
2013-01-29 21:11:51 ----D---- C:\Windows\Minidump
2013-01-29 21:11:51 ----D---- C:\Windows\debug
2013-01-29 18:26:59 ----D---- C:\Windows\system32\drivers\Avg
2013-01-24 18:41:00 ----D---- C:\Windows\Tasks
2013-01-24 14:27:04 ----D---- C:\Program Files (x86)\AVG Secure Search
2013-01-21 16:20:03 ----D---- C:\Windows\System32
2013-01-21 16:20:03 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-01-21 04:18:51 ----D---- C:\Windows\system32\catroot
2013-01-20 19:09:42 ----RD---- C:\Program Files (x86)
2013-01-20 19:05:01 ----D---- C:\ProgramData\AMD
2013-01-20 19:04:31 ----D---- C:\Program Files\ATI Technologies
2013-01-20 19:02:11 ----D---- C:\Windows\system32\drivers
2013-01-20 19:02:11 ----D---- C:\Windows\inf
2013-01-20 19:02:10 ----D---- C:\Windows\system32\DriverStore
2013-01-12 03:09:00 ----D---- C:\Windows\Microsoft.NET
2013-01-12 03:08:59 ----RSD---- C:\Windows\assembly
2013-01-12 03:02:24 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-01-10 08:08:04 ----D---- C:\Windows\winsxs
2013-01-10 08:04:33 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-01-10 08:04:32 ----D---- C:\Windows\system32\cs-CZ
2013-01-10 08:04:29 ----D---- C:\Windows\AppPatch
2013-01-10 01:33:46 ----D---- C:\ProgramData\Microsoft Help
2013-01-10 01:33:09 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-01-10 01:32:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-01-10 01:23:17 ----A---- C:\Windows\system32\MRT.exe
2013-01-09 02:14:12 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-01-01 12:32:14 ----A---- C:\Windows\NeroDigital.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2011-12-27 276576]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-02-18 834544]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AvgLdx64;AVG Free AVI Loader Driver x64; C:\Windows\System32\Drivers\avgldx64.sys [2013-01-16 282976]
R1 AvgMfx64;AVG Free On-access Scanner Minifilter Driver x64; C:\Windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]
R1 AvgTdiA;AVG Free Network Redirector x64; C:\Windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2013-01-24 37720]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R2 NPF;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2010-06-25 35344]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-12-19 11278336]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-12-19 552960]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-11-06 96256]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-31 15680]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2009-06-02 1207808]
S0 CFRMD;CFRMD; C:\Windows\system32\drivers\CFRMD.sys []
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-09-30 121872]
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-12-19 11278336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2012-09-20 102368]
S3 dgderdrv;dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [2010-05-25 20568]
S3 DIRECTIO;DIRECTIO; \??\C:\Program Files (x86)\BurnInTest\DirectIo.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2008-08-28 25600]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RTL8023x64;Realtek 10/100 NIC Family NDIS x64 Driver; C:\Windows\system32\DRIVERS\Rtnic64.sys [2009-06-10 51712]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\Windows\system32\DRIVERS\sscebus.sys [2010-04-27 127488]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\Windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 18944]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\Windows\system32\DRIVERS\sscemdm.sys [2010-04-27 161280]
S3 ssceserd;SAMSUNG Mobile Modem Diagnostic Serial Port V2 (WDM); C:\Windows\system32\DRIVERS\ssceserd.sys [2010-04-27 129024]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2012-09-20 203104]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudserd.sys [2012-09-20 203104]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TFsExDisk;TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [2010-05-25 16392]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
S4 RsFx0103;RsFx0103 Driver; C:\Windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 311656]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-12-19 240640]
R2 avg9emc;AVG Free E-mail Scanner; C:\Program Files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]
R2 avg9wd;AVG Free WatchDog; C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ICQ Service;ICQ Service; C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2009-08-20 73728]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2009-03-30 57617752]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-03-25 490280]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2012-11-07 76888]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [2009-07-24 189728]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [2009-04-15 271760]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-09-22 249136]
R2 SearchAnonymizer;SearchAnonymizer; C:\Users\Administráto\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe [2010-05-17 40960]
R2 Správce výběru OS;Aktivátor Správce výběru OS Acronis; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-07-07 2156952]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 157720]
R2 vToolbarUpdater14.0.1;vToolbarUpdater14.0.1; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.0.1\ToolbarUpdater.exe [2013-01-24 945328]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2009-06-02 637952]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-09-14 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-09 251400]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files (x86)\AVG\AVG9\Toolbar\ToolbarBroker.exe [2011-11-10 167264]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2009-10-15 87336]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-01-24 1315592]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-01-24 867080]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-09-14 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-01-19 115608]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files (x86)\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2011-01-24 79360]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2011-03-16 407336]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-04-17 1255736]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-22 61976]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 427880]
S4 SQLBrowser;SQL Server Browser; c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2009-03-30 254808]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: problém s viry v pc

Napsal: 30 led 2013 13:06
od vyosek
:arrow: Trvate na antiviru AVG - u nas neni moc obliben - vysoka zatez systemu, slabsi detekce :?:

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
  • Detailni postup vc. obrazku mate zde http://forum.viry.cz/viewtopic.php?f=24&t=120452
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Search
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen na systemovem disku jako AdwCleaner[R?].txt, ten sem vlozte

Re: problém s viry v pc

Napsal: 30 led 2013 13:14
od Mikkk
na AVG netrvám, co bych si měl dát místo něj? hned sem dam i to druhé

RogueKiller V8.4.3 [Jan 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky : http://tigzy.geekstogo.com/roguekiller.php
: http://tigzyrk.blogspot.com/

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : Administráto [Práva správce]
Mód : Kontrola -- Datum : 01/30/2013 13:12:20
| ARK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 23 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : SansaDispatch (C:\Users\Administráto\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe) -> NALEZENO
[RUN][BLACKLIST] HKCU\[...]\Run : Microsoft Windows Service (C:\Users\Administráto\6438640620394286720310355\winsvc.exe) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : pdoubrhgfjkxeiqndts (C:\Users\Administr to\AppData\Roaming\pdoubrhgfjkxeiqndts.exe) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : HotKeysCmds (C:\Users\ADMINI~1\AppData\Local\Temp\B2BF.EXE) -> NALEZENO
[RUN][SUSP PATH] HKLM\[...]\Run : Ocs_SM (C:\Users\Administráto\AppData\Roaming\OCS\SM\SearchAnonymizer.exe) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1417383624-3162349305-401947947-1000[...]\Run : SansaDispatch (C:\Users\Administráto\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe) -> NALEZENO
[RUN][BLACKLIST] HKUS\S-1-5-21-1417383624-3162349305-401947947-1000[...]\Run : Microsoft Windows Service (C:\Users\Administráto\6438640620394286720310355\winsvc.exe) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1417383624-3162349305-401947947-1000[...]\Run : pdoubrhgfjkxeiqndts (C:\Users\Administr to\AppData\Roaming\pdoubrhgfjkxeiqndts.exe) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1417383624-3162349305-401947947-1000[...]\Run : HotKeysCmds (C:\Users\ADMINI~1\AppData\Local\Temp\B2BF.EXE) -> NALEZENO
[RUN][SUSP PATH] HKLM\[...]\Wow6432Node\Run : mwavscan_autoscan ("C:\Users\ADMINI~1\AppData\Local\Temp\mexe.com" /s /AUTORUNBOOT) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Policies\Explorer\\Run : GameSpy (C:\Users\Administráto\AppData\Roaming\EF0057\EF0057.exe) -> NALEZENO
[RUN][ROGUE ST] HKLM\[...]\Policies\Explorer\\Run : 87 (C:\ProgramData\Local Settings\Temp\mslvovx.com) -> NALEZENO
[RUN][SUSP PATH] HKUS\S-1-5-21-1417383624-3162349305-401947947-1000[...]\Policies\Explorer\\Run : GameSpy (C:\Users\Administráto\AppData\Roaming\EF0057\EF0057.exe) -> NALEZENO
[RUN][ROGUE ST] HKLM\[...]\Wow6432Node\Policies\Explorer\\Run : 87 (C:\ProgramData\Local Settings\Temp\mslvovx.com) -> NALEZENO
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> NALEZENO
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
[SERVICES][HIDDEN KEY] HKLM\[...]\ControlSet001\Services\S () -> NALEZENO
[SERVICES][HIDDEN KEY] HKLM\[...]\ControlSet002\Services\S () -> NALEZENO

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
::1 localhost
192.157.56.28 www.google-analytics.com.
192.157.56.28 ad-emea.doubleclick.net.
192.157.56.28 www.statcounter.com.
192.157.56.28 connect.facebook.net.
192.157.56.28 platform.twitter.com.
93.115.241.27 www.google-analytics.com.
93.115.241.27 ad-emea.doubleclick.net.
93.115.241.27 www.statcounter.com.
93.115.241.27 connect.facebook.net.
93.115.241.27 platform.twitter.com.


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: WDC WD6400AAKS-22A7B2 ATA Device +++++
--- User ---
[MBR] 0520cb8fe5cf778bee34e7cd19e51239
[BSP] 8c6a5398912c17a588804a47a5b5e2fa : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 610478 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1]_S_01302013_02d1312.txt >>
RKreport[1]_S_01302013_02d1312.txt

Re: problém s viry v pc

Napsal: 30 led 2013 13:16
od Mikkk
a mám v tom rogue killer smazat ty nálezy?

Re: problém s viry v pc

Napsal: 30 led 2013 13:22
od Mikkk
a tady je ten druhý log, v tom prvním programu jsem ty nálezy dal smazat, snad jsem to neudělal špatně

# AdwCleaner v2.109 - Logfile created 01/30/2013 at 13:20:51
# Updated 26/01/2013 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (64 bits)
# User : Administráto - MICHAL
# Boot Mode : Normal
# Running from : C:\Users\Administráto\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****

Found : ICQ Service

***** [Files / Folders] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\searchplugins\icqplugin.xml
File Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\searchplugins\icqplugin-1.xml
File Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\searchplugins\icqplugin-2.xml
File Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\searchplugins\icqplugin-3.xml
File Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\searchplugins\SweetIm.xml
Folder Found : C:\Program Files (x86)\Ask.com
Folder Found : C:\Program Files (x86)\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\Program Files (x86)\DAEMON Tools Toolbar
Folder Found : C:\Program Files (x86)\Hot_MP3
Folder Found : C:\Program Files (x86)\ICQ6Toolbar
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\AVG Security Toolbar
Folder Found : C:\ProgramData\ICQ\ICQToolbar
Folder Found : C:\Users\ADMINI~1\AppData\Local\Temp\Software
Folder Found : C:\Users\Administráto\AppData\Local\AskToolbar
Folder Found : C:\Users\Administráto\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Administráto\AppData\Local\AVG Security Toolbar
Folder Found : C:\Users\Administráto\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Folder Found : C:\Users\Administráto\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Administráto\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Administráto\AppData\LocalLow\AVG Security Toolbar
Folder Found : C:\Users\Administráto\AppData\LocalLow\Conduit
Folder Found : C:\Users\Administráto\AppData\LocalLow\Hot_MP3
Folder Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
Folder Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\extensions\DTToolbar@toolbarnet.com
Folder Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\extensions\toolbar@ask.com
Folder Found : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\SweetPacksToolbarData
Folder Found : C:\Users\M\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Mik\AppData\Local\AskToolbar
Folder Found : C:\Users\Mik\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Mik\AppData\LocalLow\AskToolbar
Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Found : HKCU\Software\APN
Key Found : HKCU\Software\AppDataLow\AskToolbarInfo
Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
Key Found : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\Hot_MP3
Key Found : HKCU\Software\AppDataLow\Toolbar
Key Found : HKCU\Software\Ask.com
Key Found : HKCU\Software\AskToolbar
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\AVG Security Toolbar
Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\Software\APN
Key Found : HKLM\Software\AskToolbar
Key Found : HKLM\Software\AVG Secure Search
Key Found : HKLM\Software\AVG Security Toolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{5D723752-5899-47E8-99B4-62C824EF9E13}
Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\ICQ Service.exe
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
Key Found : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd
Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1
Key Found : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook
Key Found : HKLM\SOFTWARE\Classes\ICQToolBar.IEHook.1
Key Found : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT1066435
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\Hot_MP3
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6277C905-A304-44B6-B99F-8A926116A6AE}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\Wow6432Node\14919ea49a8f3b4aa3cf1058d9a64cec
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6277C905-A304-44B6-B99F-8A926116A6AE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Hot_MP3 Toolbar
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ICQToolbar
Key Found : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Found : HKU\S-1-5-21-1417383624-3162349305-401947947-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Key Found : HKU\S-1-5-21-1417383624-3162349305-401947947-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKU\S-1-5-21-1417383624-3162349305-401947947-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Value Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Run []
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://start.icq.com/
[HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://www.icq.com/search/results.php?q={searc ... &ch_id=osd

-\\ Mozilla Firefox v18.0.1 (cs)

File : C:\Users\Administráto\AppData\Roaming\Mozilla\Firefox\Profiles\czp311v7.default\prefs.js

Found : user_pref("browser.newtab.url", "hxxp://home.sweetim.com/?src=97&barid={6F686745-0964-11E2-A5D0-90E6[...]
Found : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Found : user_pref("browser.startup.homepage", "hxxp://isearch.avg.com/?cid={1C6D8F9E-780D-4768-9FC9-41C4B4E0[...]
Found : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
Found : user_pref("extensions.asktb.cbid", "EW");
Found : user_pref("extensions.asktb.config-updated", true);
Found : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://eu.ask.com/web?qsrc={qsrc}&o={o}&l={l[...]
Found : user_pref("extensions.asktb.dtid", "YYYYYYYYCZ");
Found : user_pref("extensions.asktb.first-restart-after-config-update", true);
Found : user_pref("extensions.asktb.fresh-install", false);
Found : user_pref("extensions.asktb.guid", "ED7669FF-0011-4EC5-B156-0EFAC7417D5A");
Found : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...]
Found : user_pref("extensions.asktb.if", "su");
Found : user_pref("extensions.asktb.l", "dis");
Found : user_pref("extensions.asktb.last-config-req", "1359456526838");
Found : user_pref("extensions.asktb.last-search-timestamp", "1334509783002");
Found : user_pref("extensions.asktb.locale", "en_EU");
Found : user_pref("extensions.asktb.nero.userName", "");
Found : user_pref("extensions.asktb.new-tab-opt-out", true);
Found : user_pref("extensions.asktb.o", "101913");
Found : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Found : user_pref("extensions.asktb.qsrc", "2871");
Found : user_pref("extensions.asktb.r", "9");
Found : user_pref("extensions.asktb.sa", "NO");
Found : user_pref("extensions.asktb.search-history-queries", "Zákon o vysokých akolách 111/1998 sb.||Filozof[...]
Found : user_pref("extensions.asktb.search-suggestions-enabled", true);
Found : user_pref("extensions.asktb.silent-upgrade", true);
Found : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", true);
Found : user_pref("extensions.asktb.themeid", "");
Found : user_pref("extensions.asktb.v", "3.12.2.100013");
Found : user_pref("extensions.asktb.version", "5.12.2.16749");
Found : user_pref("extensions.enabledAddons", "%7BEEE6C361-6118-11DC-9C72-001320C79847%7D:1.9.0.0,%7B800b500[...]
Found : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid={1C6D8F9E-780D-4768-9FC9-41C4B4E030C8}&m[...]
Found : user_pref("sweetim.toolbar.RevertDialog.enable", "false");
Found : user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
Found : user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "0");
Found : user_pref("sweetim.toolbar.Visibility.enable", "true");
Found : user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
Found : user_pref("sweetim.toolbar.cargo", "3.1010000.10005");
Found : user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
Found : user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
Found : user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
Found : user_pref("sweetim.toolbar.cda.returnValue", "none");
Found : user_pref("sweetim.toolbar.dialogs.0.enable", "true");
Found : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...]
Found : user_pref("sweetim.toolbar.dialogs.0.height", "335");
Found : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
Found : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
Found : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.asp?la[...]
Found : user_pref("sweetim.toolbar.dialogs.0.width", "761");
Found : user_pref("sweetim.toolbar.dialogs.1.enable", "true");
Found : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...]
Found : user_pref("sweetim.toolbar.dialogs.1.height", "300");
Found : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
Found : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
Found : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...]
Found : user_pref("sweetim.toolbar.dialogs.1.width", "500");
Found : user_pref("sweetim.toolbar.dialogs.2.enable", "true");
Found : user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handl[...]
Found : user_pref("sweetim.toolbar.dialogs.2.height", "150");
Found : user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
Found : user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
Found : user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
Found : user_pref("sweetim.toolbar.dialogs.2.width", "530");
Found : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...]
Found : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
Found : user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
Found : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
Found : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
Found : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
Found : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
Found : user_pref("sweetim.toolbar.mode.debug", "false");
Found : user_pref("sweetim.toolbar.newtab.created", "true");
Found : user_pref("sweetim.toolbar.newtab.enable", "true");
Found : user_pref("sweetim.toolbar.previous.browser.newtab.url", "about:newtab");
Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "ICQ Search");
Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Google");
Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://www.seznam.cz/");
Found : user_pref("sweetim.toolbar.previous.keyword.URL", "");
Found : user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolba ... on=$ITEM_V[...]
Found : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
Found : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
Found : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*");
Found : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
Found : user_pref("sweetim.toolbar.scripts.0.enable", "false");
Found : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
Found : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
Found : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "false");
Found : user_pref("sweetim.toolbar.scripts.1.callback", "");
Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...]
Found : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "");
Found : user_pref("sweetim.toolbar.scripts.1.elementid", "id_predict_include_script");
Found : user_pref("sweetim.toolbar.scripts.1.enable", "false");
Found : user_pref("sweetim.toolbar.scripts.1.id", "id_script_prad");
Found : user_pref("sweetim.toolbar.scripts.1.url", "hxxp://cdn1.predictad.com/scripts/publishers/sweetim/pre[...]
Found : user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "true");
Found : user_pref("sweetim.toolbar.scripts.2.callback", "simVerification");
Found : user_pref("sweetim.toolbar.scripts.2.domain-blacklist", "");
Found : user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*");
Found : user_pref("sweetim.toolbar.scripts.2.elementid", "id_script_sim_fb");
Found : user_pref("sweetim.toolbar.scripts.2.enable", "false");
Found : user_pref("sweetim.toolbar.scripts.2.id", "id_script_fb_hxxpS");
Found : user_pref("sweetim.toolbar.scripts.2.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
Found : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...]
Found : user_pref("sweetim.toolbar.search.history.capacity", "10");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "0");
Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", "0");
Found : user_pref("sweetim.toolbar.searchguard.enable", "false");
Found : user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
Found : user_pref("sweetim.toolbar.simapp_id", "{6F686745-0964-11E2-A5D0-90E6BA175D9A}");
Found : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?crg=3.1010000.10005&barid={6F68[...]
Found : user_pref("sweetim.toolbar.version", "1.9.0.0");

File : C:\Users\Mik\AppData\Roaming\Mozilla\Firefox\Profiles\a28ud50r.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v24.0.1312.56

File : C:\Users\Administráto\AppData\Local\Google\Chrome\User Data\Default\Preferences

Found [l.9] : homepage = "hxxp://isearch.avg.com/?cid={1C6D8F9E-780D-4768-9FC9-41C4B4E030C8}&mid=5a372aa66e4833c97fb7b4115f51e4bc-92361cc1288eb62f09c8ca5c5382f716e7a78e1b&lang=cz&ds=AVG&pr=fr&d=2011-12-12 11:27:33&v=14.0.2.14&pid=avg&sg=&sap=hp",
Found [l.13] : urls_to_restore_on_startup = [ "hxxp://isearch.avg.com/?cid={1C6D8F9E-780D-4768-9FC9-41C4B4E030C8}&mid=5a372aa66e4833c97fb7b4115f51e4bc-92361cc1288eb62f09c8ca5c5382f716e7a78e1b&lang=cz&ds=AVG&pr=fr&d=2011-12-12 11:27:33&v=14.0.2.14&pid=avg&sg=&sap=hp" ]
Found [l.1693] : homepage = "hxxp://isearch.avg.com/?cid={1C6D8F9E-780D-4768-9FC9-41C4B4E030C8}&mid=5a372aa66e4833c97fb7b4115f51e4bc-92361cc1288eb62f09c8ca5c5382f716e7a78e1b&lang=cz&ds=AVG&pr=fr&d=2011-12-12 11:27:33&v=14.0.2.14&pid=avg&sg=&sap=hp",
Found [l.2974] : urls_to_restore_on_startup = [ "hxxp://isearch.avg.com/?cid={1C6D8F9E-780D-4768-9FC9-41C4B4E030C8}&mid=5a372aa66e4833c97fb7b4115f51e4bc-92361cc1288eb62f09c8ca5c5382f716e7a78e1b&lang=cz&ds=AVG&pr=fr&d=2011-12-12 11:27:33&v=14.0.2.14&pid=avg&sg=&sap=hp" ]

*************************

AdwCleaner[R1].txt - [26407 octets] - [30/01/2013 13:20:51]

########## EOF - C:\AdwCleaner[R1].txt - [26468 octets] ##########

Re: problém s viry v pc

Napsal: 30 led 2013 14:13
od Mikkk
našel jsme tu stejný problém, tak jsem udělal co tam bylo popsáno v programu regue killer jsem dal scan poté smazat a opravit host, v adwacleaner scan a delete pak se pc restartoval, mám udělat ještě něco?

Re: problém s viry v pc

Napsal: 30 led 2013 16:54
od Mikkk
pak jsme ještě použil combo fix a ten našel a odstranil ještě něco, teď snad už to je ok, musel jsme přeinstalovat nakažené programy, byly nefunkční

Re: problém s viry v pc

Napsal: 30 led 2013 20:45
od vyosek
:arrow: Kdyz si to hodlate lecit sam, tak si lecte, ale s mou pomoci nepocitejte

:arrow: Pravidla fora http://forum.viry.cz/viewtopic.php?f=12&t=5601
2. Před položením dotazu použijte tlačítko Hledat. Možná již někdo problém podobným Vašemu řešil. Pokud ale ve vyřešeném tématu budou aplikovány různé utility\aplikace, nespouštějte je. Utility se používají až na pokyn rádce, jelikož mohou mazat stopy po havěti a v rukou ne-oborníka může mít jejich použití nedozírné následky.

3. Zvláště utilitu ComboFix nespouštějte i když Vám mi poradil kamarád\nějaký rádoby odborný web. Naše fórum je jediné z CZ-SK antivirových fór, která mají právo luštit logy z ComboFixu a mámě též plnou podporu autora této utility a přístup k nejaktuálnějším informacím a návodům.
:arrow: licencni podminky hovori jasne "Nikdy by nemel byt pouzit v prostredi bez dozoru zkusene osoby"
Obrázek

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal

:arrow: tim bych to z me strany ukoncil, nehodlam dokoncovat co jste si buh vi jak rozrypal a rozdelal

:arrow: Pokud budete zadat priste o pomoc a nebudete respektovat pokyny a pravidla, bude opet pomoc odmitnuta...


:closed:

Re: problém s viry v pc

Napsal: 31 led 2013 15:41
od Mikkk
Tak to sorry, už jsem si myslel že se odpovědi nedočkám a tak jsme to začal řešit sám.

Re: problém s viry v pc

Napsal: 31 led 2013 15:45
od vyosek
Tak si reste, ja vam v tom nebranim...

My jsme tu zdarma a ve svem VOLNEM case, pokud jste chtel urgentni reseni, mel jste si zaplatit servis, kde se se mohl domahat okamziteho reseni...Byla tam necele dve hodiny prodlevy nez jsem prisel k PC - i my mame svuj rodinny, pracovni a soukromy zivot...

Jak jsem psal, udelal jste tam dost kroku, ktere nehodlam zkoumat, probirat se zalohami a vsim moznym, abych zjistil, co jste tam vse napachal...

Re: problém s viry v pc

Napsal: 31 led 2013 16:25
od Mikkk
ano, děkuji :)

Re: problém s viry v pc

Napsal: 31 led 2013 20:39
od vyosek
Nemate zac :)

A na zaklade Pravidla o zamykani temat :lock: