Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Google-hláška

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Google-hláška

#1 Příspěvek od civrs »

Zdravím při vyhledávání mi stríček Google píše:
Sorry...
We're sorry...
... but your computer or network may be sending automated queries. To protect our users, we can't process your request right now.
See Google Help for more information.
Když napíšu do hlavního okna celou adresu http://www.atd.atd. tak se normálně stránka otevře ale pakliže napíši třeba:problémy s pc tak to hodí tuto chybu.
Předem děkuji

Logfile of random's system information tool 1.09 (written by random/random)
Run by Admin at 2013-09-08 16:16:01
Microsoft Windows XP Home Edition Service Pack 3
System drive E: has 45 GB (64%) free of 70 GB
Total RAM: 3070 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:16:09, on 8.9.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\AVAST Software\Avast\AvastSvc.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\RTHDCPL.EXE
E:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
E:\Program Files\Cyberlink\Shared files\brs.exe
E:\Program Files\AVAST Software\Avast\avastUI.exe
E:\WINDOWS\system32\MSTMON_Q.EXE
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
E:\Program Files\Skype\Phone\Skype.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\Program Files\Java\jre7\bin\jqs.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\System32\PAStiSvc.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
E:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
E:\Program Files\Mozilla Firefox\plugin-container.exe
D:\PROGRAMY INSTAL\Steam\steam.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Documents and Settings\Admin\Dokumenty\Stažené soubory\RSIT(1).exe
E:\Program Files\trend micro\Admin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bsplayer.com/bsplayer/thank- ... 20%28CZ%29
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RemoteControl10] "E:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [BDRegion] E:\Program Files\Cyberlink\Shared files\brs.exe
O4 - HKLM\..\Run: [avast] "E:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [BCSSync] "E:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [KONICA MINOLTA PagePro 1350WStatusDisplay] E:\WINDOWS\system32\MSTMON_Q.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "E:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [OfficeSyncProcess] "E:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
O4 - HKCU\..\Run: [EADM] D:\PROGRAMY INSTAL\Origin\Origin.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://E:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - E:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 3978607934
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - E:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - E:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - E:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - E:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - E:\Program Files\Skype\Updater\Updater.exe
O23 - Service: STI Simulator - Unknown owner - E:\WINDOWS\System32\PAStiSvc.exe

--
End of file - 8536 bytes

======Scheduled tasks folder======

E:\WINDOWS\tasks\Adobe Flash Player Updater.job
E:\WINDOWS\tasks\avast! Emergency Update.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
E:\WINDOWS\tasks\User_Feed_Synchronization-{B2C153F0-FBDB-4EE1-9E14-848BD117B08E}.job

=========Mozilla firefox=========

ProfilePath - E:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\jg34juu3.default

"wrc@avast.com"=E:\Program Files\AVAST Software\Avast\WebRep\FF
"{20a82645-c095-46ed-80e3-08825760534b}"=E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.8.800.94 Plugin
"Path"=E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=E:\WINDOWS\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=E:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=E:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=E:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

E:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - E:\PROG [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - E:\Prog [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - E:\Prog [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - E:\PROG [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Prog [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! Online Security - E:\Prog [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=E:\WINDOWS\RTHDCPL.EXE [2012-06-06 20065936]
"NeroFilterCheck"=E:\Prog [2013-05-09 6583664]
"NBKeyScan"=E:\Prog [2013-05-09 6583664]
"RemoteControl10"=E:\Prog [2013-05-09 6583664]
"BDRegion"=E:\Prog [2013-05-09 6583664]
"avast"=E:\Prog [2013-05-09 6583664]
"StartCCC"=E:\Prog [2013-05-09 6583664]
"BCSSync"=E:\Prog [2013-05-09 6583664]
"KONICA MINOLTA PagePro 1350WStatusDisplay"=E:\WINDOWS\system32\MSTMON_Q.EXE [2004-11-26 167936]
"SunJavaUpdateSched"=E:\Prog [2013-05-09 6583664]
"Adobe ARM"=E:\Prog [2013-05-09 6583664]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=E:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=E:\Prog [2013-05-09 6583664]
"Skype"=E:\Prog [2013-05-09 6583664]
"OfficeSyncProcess"=E:\Prog [2013-05-09 6583664]
"EADM"=D:\PROGRAMY INSTAL\Origin\Origin.exe [2013-09-04 3549528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
E:\WINDOWS\system32\Ati2evxx.dll [2012-11-16 192512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=E:\PROG [2013-05-09 6583664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\Program Files\Nero\Nero8\Nero ShowTime\ShowTime.exe"="E:\Program Files\Nero\Nero8\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime"
"E:\Program Files\Skype\Phone\Skype.exe"="E:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Program Files\Microsoft Office\Office14\GROOVE.EXE"="E:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"E:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="E:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"E:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"="E:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Warframe\Warframe.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Warframe\Warframe.exe:*:Enabled:Warframe Steam Game 32"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Warframe\Warframe.x64.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Warframe\Warframe.x64.exe:*:Enabled:Warframe Steam Game 64"
"E:\Program Files\Java\jre7\bin\javaw.exe"="E:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Torchlight II\Torchlight2.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Torchlight II\Torchlight2.exe:*:Enabled:Torchlight II"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Borderlands2.exe:*:Enabled:borderlands game"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\regnum\LiveServer\ROClientGame.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\regnum\LiveServer\ROClientGame.exe:*:Enabled:champions of regnum"
"D:\hry instal\World_of_Warplanes\WOWpLauncher.exe"="D:\hry instal\World_of_Warplanes\WOWpLauncher.exe:*:Enabled:World of Warplanes Launcher"
"D:\hry instal\CO4\iw3mp.exe"="D:\hry instal\CO4\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Global Agenda Live\Binaries\GlobalAgenda.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Global Agenda Live\Binaries\GlobalAgenda.exe:*:Enabled:TgGame Client"
"D:\PROGRAMY INSTAL\Steam\Steam.exe"="D:\PROGRAMY INSTAL\Steam\Steam.exe:*:Enabled:Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)"
"D:\hry instal\Panzar\start.exe"="D:\hry instal\Panzar\start.exe:*:Enabled:FBC Update Client"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Team Fortress 2\hl2.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Team Fortress 2\hl2.exe:*:Enabled:Team Fortress 2"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\dota 2 beta\dota.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\dota 2 beta\dota.exe:*:Enabled:Dota 2"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Magicka\Magicka.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Magicka\Magicka.exe:*:Enabled:Magicka"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Torchlight II\ModLauncher.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Torchlight II\ModLauncher.exe:*:Enabled:Torchlight II"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\PlanetSide 2\LaunchPad.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\PlanetSide 2\LaunchPad.exe:*:Enabled:PlanetSide 2"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Warframe\Tools\Launcher.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Warframe\Tools\Launcher.exe:*:Enabled:Warframe"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Crysis 2 Game of the Year\bin32\Crysis2Launcher.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Crysis 2 Game of the Year\bin32\Crysis2Launcher.exe:*:Enabled:Crysis 2 Maximum Edition"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Borderlands 2\Binaries\Win32\Launcher.exe:*:Enabled:Borderlands 2"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Crysis 2 Game of the Year\bin32\Crysis2.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Crysis 2 Game of the Year\bin32\Crysis2.exe:*:Enabled:Crysis2"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4mp.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4sp.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\MarchOfWar\game.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\MarchOfWar\game.exe:*:Enabled:March of War"
"E:\Program Files\Pando Networks\Media Booster\PMB.exe"="E:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\MarchOfWar\MarchOfWar.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\MarchOfWar\MarchOfWar.exe:*:Enabled:MarchOfWar"
"D:\PROGRAMY INSTAL\Steam\steamapps\common\Marvel Heroes\UnrealEngine3\Binaries\Win32\MarvelGame.exe"="D:\PROGRAMY INSTAL\Steam\steamapps\common\Marvel Heroes\UnrealEngine3\Binaries\Win32\MarvelGame.exe:*:Enabled:Marvel Heroes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\Program Files\Pando Networks\Media Booster\PMB.exe"="E:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=E:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=E:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======List of files/folders created in the last 1 month======

2013-09-06 15:41:28 ----D---- E:\Documents and Settings\Admin\Data aplikací\.mono
2013-09-06 15:27:25 ----SHD---- E:\WINDOWS\system32\AI_RecycleBin
2013-09-06 15:26:53 ----D---- E:\Documents and Settings\All Users\Data aplikací\PMB Files
2013-09-06 15:26:41 ----D---- E:\Program Files\Pando Networks
2013-09-06 15:25:37 ----D---- E:\Documents and Settings\Admin\Data aplikací\Riot Games
2013-09-05 14:08:19 ----D---- E:\Documents and Settings\All Users\Data aplikací\EA Core
2013-09-04 20:35:54 ----D---- E:\Documents and Settings\Admin\Data aplikací\Hamachi
2013-09-04 20:35:31 ----A---- E:\WINDOWS\system32\drivers\hamachi.sys
2013-09-04 20:35:30 ----D---- E:\Program Files\Hamachi
2013-09-04 19:49:36 ----D---- E:\Documents and Settings\Admin\Data aplikací\Origin
2013-09-03 14:48:48 ----D---- E:\Program Files\Convar
2013-09-02 16:49:55 ----D---- E:\Program Files\Western Digital Corporation
2013-08-28 19:47:37 ----D---- E:\Documents and Settings\All Users\Data aplikací\Origin
2013-08-28 19:45:53 ----D---- E:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2013-08-28 12:03:02 ----HDC---- E:\WINDOWS\$NtUninstallKB2834902-v2_WM10$
2013-08-25 20:28:34 ----A---- E:\WINDOWS\system32\drivers\mbamswissarmy.sys
2013-08-25 20:16:19 ----D---- E:\Avenger
2013-08-25 20:15:12 ----A---- E:\cleanup.exe
2013-08-25 20:15:10 ----A---- E:\zip.exe
2013-08-25 20:14:46 ----A---- E:\avenger.txt
2013-08-25 12:04:47 ----D---- E:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2013-08-25 12:04:41 ----D---- E:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2013-08-25 11:58:36 ----D---- E:\Program Files\7-Zip
2013-08-24 19:12:25 ----D---- E:\rsit
2013-08-24 19:12:25 ----D---- E:\Program Files\trend micro
2013-08-24 19:04:21 ----D---- E:\Program Files\Absolute Uninstaller
2013-08-24 19:04:18 ----D---- E:\Program Files\CCleaner
2013-08-24 19:03:26 ----D---- E:\WINDOWS\Sun
2013-08-24 14:33:25 ----D---- E:\Documents and Settings\Admin\Data aplikací\GlarySoft
2013-08-24 14:24:14 ----D---- E:\Program Files\ESET
2013-08-22 12:58:39 ----D---- E:\Program Files\Minecraft-1.4.6
2013-08-17 09:41:02 ----D---- E:\Documents and Settings\All Users\Data aplikací\WarThunder
2013-08-17 09:16:07 ----D---- E:\Program Files\Mozilla Firefox
2013-08-16 17:53:56 ----D---- E:\WINDOWS\Minidump
2013-08-14 12:14:02 ----D---- E:\WINDOWS\system32\MRT
2013-08-14 12:09:14 ----HDC---- E:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 12:09:06 ----HDC---- E:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 12:08:55 ----HDC---- E:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 12:08:44 ----HDC---- E:\WINDOWS\$NtUninstallKB2849470$
2013-08-11 21:10:51 ----D---- E:\Documents and Settings\Admin\Data aplikací\Hi-Rez Studios
2013-08-11 21:04:58 ----D---- E:\WINDOWS\system32\AGEIA
2013-08-11 21:04:58 ----D---- E:\Program Files\AGEIA Technologies
2013-08-11 21:04:49 ----D---- E:\Program Files\Common Files\Wise Installation Wizard
2013-08-11 10:41:39 ----D---- E:\Documents and Settings\Admin\Data aplikací\.mnaucraft
2013-08-10 18:44:03 ----D---- E:\Documents and Settings\All Users\Data aplikací\InstallMate
2013-08-10 11:12:24 ----D---- E:\Documents and Settings\Admin\Data aplikací\.techniclauncher

======List of files/folders modified in the last 1 month======

2013-09-08 16:16:08 ----D---- E:\WINDOWS\Prefetch
2013-09-08 16:08:04 ----D---- E:\Documents and Settings\Admin\Data aplikací\Skype
2013-09-08 15:13:10 ----D---- E:\WINDOWS\Temp
2013-09-08 11:34:47 ----D---- E:\WINDOWS\system32\CatRoot2
2013-09-08 10:12:40 ----A---- E:\WINDOWS\SchedLgU.Txt
2013-09-07 07:14:36 ----D---- E:\WINDOWS
2013-09-06 15:27:45 ----SD---- E:\WINDOWS\Tasks
2013-09-06 15:27:35 ----HD---- E:\WINDOWS\inf
2013-09-06 15:27:35 ----D---- E:\WINDOWS\system32
2013-09-06 15:27:30 ----D---- E:\WINDOWS\system32\DirectX
2013-09-06 15:27:26 ----SHD---- E:\WINDOWS\Installer
2013-09-06 15:27:25 ----SHD---- E:\Config.Msi
2013-09-06 15:26:41 ----RD---- E:\Program Files
2013-09-05 14:07:43 ----D---- E:\WINDOWS\Logs
2013-09-05 14:07:41 ----D---- E:\WINDOWS\WinSxS
2013-09-04 20:39:57 ----D---- E:\Documents and Settings\Admin\Data aplikací\.technic
2013-09-04 20:35:35 ----D---- E:\WINDOWS\system32\drivers
2013-08-28 12:03:04 ----RSHDC---- E:\WINDOWS\system32\dllcache
2013-08-28 12:02:56 ----D---- E:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2013-08-27 19:14:00 ----D---- E:\WINDOWS\system32\config
2013-08-25 18:46:27 ----HDC---- E:\WINDOWS\$NtUninstallKB971657$
2013-08-25 09:42:29 ----A---- E:\WINDOWS\win.ini
2013-08-24 19:03:30 ----D---- E:\Documents and Settings\Admin\Data aplikací\.minecraft
2013-08-24 14:16:55 ----D---- E:\WINDOWS\Debug
2013-08-24 11:39:43 ----D---- E:\Documents and Settings\Admin\Data aplikací\Awesomium
2013-08-23 08:22:39 ----RSD---- E:\WINDOWS\assembly
2013-08-23 08:22:39 ----D---- E:\WINDOWS\Microsoft.NET
2013-08-22 18:39:48 ----A---- E:\WINDOWS\system32\PerfStringBackup.INI
2013-08-17 21:26:15 ----D---- E:\Program Files\Mozilla Maintenance Service
2013-08-14 12:16:33 ----D---- E:\Program Files\Internet Explorer
2013-08-14 12:16:20 ----D---- E:\WINDOWS\ie8updates
2013-08-14 12:13:53 ----A---- E:\WINDOWS\system32\MRT.exe
2013-08-11 21:10:53 ----D---- E:\WINDOWS\system32\CatRoot
2013-08-11 21:09:33 ----D---- E:\WINDOWS\system32\XPSViewer
2013-08-11 21:09:32 ----RSD---- E:\WINDOWS\Fonts
2013-08-11 21:04:49 ----D---- E:\Program Files\Common Files
2013-08-11 12:39:26 ----HD---- E:\Program Files\InstallShield Installation Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;aswRvrt; E:\WINDOWS\system32\drivers\aswRvrt.sys [2013-05-09 49376]
R0 aswVmm;aswVmm; E:\WINDOWS\system32\drivers\aswVmm.sys [2013-07-16 175176]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; E:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R1 AswRdr;aswRdr; E:\WINDOWS\system32\drivers\AswRdr.sys [2013-05-09 49760]
R1 aswSnx;aswSnx; E:\WINDOWS\system32\drivers\aswSnx.sys [2013-07-16 770344]
R1 aswSP;aswSP; E:\WINDOWS\system32\drivers\aswSP.sys [2013-07-16 369584]
R1 aswTdi;avast! Network Shield Support; E:\WINDOWS\system32\drivers\aswTdi.sys [2013-05-09 56080]
R1 kbdhid;Ovladač klávesnice standardu HID; E:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2013/07/16 15:07:43]; \??\E:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl []
R2 aswFsBlk;aswFsBlk; E:\WINDOWS\system32\drivers\aswFsBlk.sys [2013-05-09 29816]
R2 aswMonFlt;aswMonFlt; \??\E:\WINDOWS\system32\drivers\aswMonFlt.sys []
R2 MLPTDR_Q;MLPTDR_Q; \??\E:\WINDOWS\system32\MLPTDR_Q.SYS []
R3 Arp1394;Protokol 1394 ARP Client; E:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ati2mtag;ati2mtag; E:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2012-11-16 7874560]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; E:\WINDOWS\system32\drivers\AtihdXP3.sys [2012-05-14 103040]
R3 hamachi;Hamachi Network Interface; E:\WINDOWS\system32\DRIVERS\hamachi.sys [2013-09-04 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; E:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; E:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); E:\WINDOWS\system32\drivers\RtkHDAud.sys [2012-06-19 6141584]
R3 mouhid;Ovladač myši standardu HID; E:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; E:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; E:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-06-28 45824]
R3 nvnetbus;NVIDIA Network Bus Enumerator; E:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-06-28 20480]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; E:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S1 AmdK8;Ovladač procesoru AMD; E:\WINDOWS\system32\DRIVERS\AmdK8.sys []
S1 AmdPPM;Ovladač procesoru HwPState AMD; E:\WINDOWS\system32\DRIVERS\AmdPPM.sys []
S3 Ambfilt;Ambfilt; E:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 CCDECODE;Dekodér Closed Caption; E:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 Monfilt;Monfilt; E:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; E:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; E:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 PAC207;VideoCAM GF112; E:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
S3 RTHDMIAzAudService;Service for HDMI; E:\WINDOWS\system32\drivers\RtKHDMI.sys [2011-12-02 4125352]
S3 SLIP;BDA Slip De-Framer; E:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; E:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Třída USB Printer; E:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; E:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; E:\WINDOWS\system32\Ati2evxx.exe [2012-11-16 643072]
R2 avast! Antivirus;avast! Antivirus; E:\Prog [2013-05-09 6583664]
R2 JavaQuickStarterService;Java Quick Starter; E:\Prog [2013-05-09 6583664]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; E:\Prog [2013-05-09 6583664]
R2 STI Simulator;STI Simulator; E:\WINDOWS\System32\PAStiSvc.exe [2005-01-14 53248]
R2 UMWdf;Windows User Mode Driver Framework; E:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R3 NMIndexingService;NMIndexingService; E:\Prog [2013-05-09 6583664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); E:\Prog [2013-05-09 6583664]
S2 SkypeUpdate;Skype Updater; E:\Prog [2013-05-09 6583664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; E:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-17 257416]
S3 aspnet_state;ASP.NET State Service; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); E:\Prog [2013-05-09 6583664]
S3 idsvc;Windows CardSpace; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; E:\Prog [2013-05-09 6583664]
S3 MozillaMaintenance;Mozilla Maintenance Service; E:\Prog [2013-05-09 6583664]
S3 ose;Office Source Engine; E:\Prog [2013-05-09 6583664]
S3 osppsvc;Office Software Protection Platform; E:\Prog [2013-05-09 6583664]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-04-18 754856]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; E:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Google-hláška

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Ono to nemusi byt chyba primo na vasem PC, ale z IP adresy a pripojeni muze byt vice PC a jeden z nich muze byt nakazeny ci mit nejakou vetsi aktivitu. Ale proverime i vase...

:arrow: Dejte log z FRSTL http://forum.viry.cz/viewtopic.php?f=24&t=132509

:arrow: Stahnete Malwarebytes' Anti-Malware (zkracene MBAM) http://forum.viry.cz/viewtopic.php?f=29&t=115222
  • Provedte aktualizaci
  • Provedte uplny sken - nic nemazte :!:
  • MBAM miva obcas falesne detekce, proto vlozte log do prispevku a pockejte na posouzeni
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Google-hláška

#3 Příspěvek od civrs »

Mockrát děkuji,je fakt že tem problém mám i na tabletu.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013
Ran by Admin (administrator) on ADMIN-260F498AE on 09-09-2013 16:38:18
Running from E:\Documents and Settings\Admin\Plocha
Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(ATI Technologies Inc.) E:\WINDOWS\system32\Ati2evxx.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ATI Technologies Inc.) E:\WINDOWS\system32\Ati2evxx.exe
(Realtek Semiconductor Corp.) E:\WINDOWS\RTHDCPL.EXE
(CyberLink Corp.) E:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
(cyberlink) E:\Program Files\Cyberlink\Shared files\brs.exe
(AVAST Software) E:\Program Files\AVAST Software\Avast\avastUI.exe
(KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) E:\WINDOWS\system32\MSTMON_Q.EXE
(Oracle Corporation) E:\Program Files\Common Files\Java\Java Update\jusched.exe
(Nero AG) E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
(Advanced Micro Devices Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Skype Technologies S.A.) E:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) E:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(ATI Technologies Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
(Oracle Corporation) E:\Program Files\Java\jre7\bin\jqs.exe
(Nero AG) E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
() E:\WINDOWS\system32\PnkBstrA.exe
() E:\WINDOWS\System32\PAStiSvc.exe
(Nero AG) E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
(Nero AG) E:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Mozilla Corporation) E:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) E:\Program Files\Mozilla Firefox\plugin-container.exe
(Valve Corporation) D:\PROGRAMY INSTAL\Steam\steam.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDCPL] - E:\Windows\RTHDCPL.EXE [20065936 2012-06-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [NeroFilterCheck] - E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [NBKeyScan] - E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl10] - E:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
HKLM\...\Run: [BDRegion] - E:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink)
HKLM\...\Run: [avast] - E:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM\...\Run: [StartCCC] - E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [BCSSync] - E:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [KONICA MINOLTA PagePro 1350WStatusDisplay] - E:\WINDOWS\system32\MSTMON_Q.EXE [167936 2004-11-26] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
HKLM\...\Run: [SunJavaUpdateSched] - E:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-10] (Adobe Systems Incorporated)
Winlogon\Notify\AtiExtEvent: Ati2evxx.dll (ATI Technologies Inc.)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-09-20] (Nero AG)
HKCU\...\Run: [Skype] - E:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [OfficeSyncProcess] - E:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [719672 2012-01-20] (Microsoft Corporation)
HKCU\...\Run: [EADM] - D:\PROGRAMY INSTAL\Origin\Origin.exe [3549528 2013-09-04] (Electronic Arts)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - E:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - E:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU -&Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - E:\Windows\system32\browseui.dll (Společnost Microsoft)
Toolbar: HKCU -&Odkazy - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - E:\Windows\system32\SHELL32.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)

FireFox:
========
FF ProfilePath: E:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\jg34juu3.default
FF Plugin: @adobe.com/FlashPlayer - E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - E:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - E:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - E:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - E:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - E:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @tools.google.com/Google Update;version=3 - E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - E:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - E:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: E:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: E:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: E:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: E:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] E:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - E:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

Chrome:
=======
CHR HomePage: hxxp://www.microsoft.com/isapi/redir.dll?prd=i ... ar=msnhome
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - E:\Program Files\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - E:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - E:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - E:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE DRM) - E:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - E:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Microsoft\u00AE DRM) - E:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Google Update) - E:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Windows Presentation Foundation) - E:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
CHR Extension: (Google Docs) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Don't Starve) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\hiledapehlkhdehbhppgmekfalnlfajc\1.0.0.37_0
CHR Extension: (Chrome In-App Payments service) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Falling Sand Game) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\pdknckljjbdpkhgmcokoahffbdinafbo\1.3_0
CHR Extension: (BattleForge) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\pfedpidpkhdoiiobikjnligdgkkkkcha\1.0.0_0
CHR Extension: (Akinator Web Genius) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\phjbcelanfbmkoghofajgepjabdbgncf\1_0
CHR Extension: (Gmail) - E:\DOCUME~1\Admin\LOCALS~1\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0

========================== Services (Whitelisted) =================

R2 avast! Antivirus; E:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 PnkBstrA; E:\WINDOWS\system32\PnkBstrA.exe [66872 2013-09-08] ()
R2 STI Simulator; E:\WINDOWS\System32\PAStiSvc.exe [53248 2005-01-14] ()
R2 JavaQuickStarterService; "E:\Program Files\Java\jre7\bin\jqs.exe" -service -config "E:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" [x]

==================== Drivers (Whitelisted) ====================

S3 Ambfilt; E:\Windows\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R2 aswFsBlk; E:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software)
R2 aswMonFlt; E:\WINDOWS\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software)
R1 AswRdr; E:\Windows\System32\Drivers\AswRdr.sys [49760 2013-05-09] (AVAST Software)
R0 aswRvrt; E:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] ()
R1 aswSnx; E:\Windows\System32\Drivers\aswSnx.sys [770344 2013-07-16] (AVAST Software)
R1 aswSP; E:\Windows\System32\Drivers\aswSP.sys [369584 2013-07-16] (AVAST Software)
R1 aswTdi; E:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software)
R0 aswVmm; E:\Windows\System32\Drivers\aswVmm.sys [175176 2013-07-16] ()
R3 AtiHDAudioService; E:\Windows\System32\drivers\AtihdXP3.sys [103040 2012-05-14] (Advanced Micro Devices)
R3 hamachi; E:\Windows\System32\DRIVERS\hamachi.sys [25280 2013-09-04] (LogMeIn, Inc.)
R2 MLPTDR_Q; E:\WINDOWS\system32\MLPTDR_Q.SYS [18848 2003-07-22] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
S3 Monfilt; E:\Windows\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
S3 NdisIP; E:\Windows\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
R3 NVENETFD; E:\Windows\System32\DRIVERS\NVENETFD.sys [45824 2007-06-28] (NVIDIA Corporation)
R3 nvnetbus; E:\Windows\System32\DRIVERS\nvnetbus.sys [20480 2007-06-28] (NVIDIA Corporation)
S3 PAC207; E:\Windows\System32\DRIVERS\pfc027.sys [162176 2005-04-08] ()
S3 RTHDMIAzAudService; E:\Windows\System32\drivers\RtKHDMI.sys [4125352 2011-12-02] (Realtek Semiconductor Corp.)
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}; E:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl [87536 2010-03-13] (CyberLink Corp.)
S1 AmdK8; system32\DRIVERS\AmdK8.sys [x]
S1 AmdPPM; system32\DRIVERS\AmdPPM.sys [x]
S4 IntelIde; No ImagePath
U1 WS2IFSL;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-09 16:37 - 2013-09-09 16:37 - 00000000 ____D E:\FRST
2013-09-09 16:37 - 2013-09-08 23:29 - 01082207 _____ (Farbar) E:\Documents and Settings\Admin\Plocha\FRST.exe
2013-09-09 14:00 - 2013-09-09 14:00 - 00000217 _____ E:\Documents and Settings\Admin\Plocha\Call of Duty Modern Warfare 2 - Multiplayer.url
2013-09-08 21:48 - 2013-09-08 21:48 - 00001508 _____ E:\Documents and Settings\Admin\Plocha\GamePark.lnk
2013-09-08 21:39 - 2013-09-08 21:39 - 00000000 __SHD E:\WINDOWS\ftpcache
2013-09-08 21:38 - 2013-09-08 21:39 - 00124380 _____ E:\WINDOWS\DirectX.log
2013-09-08 21:23 - 2013-09-08 22:02 - 00022328 _____ E:\WINDOWS\system32\Drivers\PnkBstrK.sys
2013-09-08 21:23 - 2013-09-08 21:23 - 00022328 _____ E:\Documents and Settings\Admin\Data aplikací\PnkBstrK.sys
2013-09-08 21:22 - 2013-09-08 22:02 - 00103736 _____ E:\WINDOWS\system32\PnkBstrB.exe
2013-09-08 21:22 - 2013-09-08 21:53 - 00066872 _____ E:\WINDOWS\system32\PnkBstrA.exe
2013-09-08 21:22 - 2013-09-08 21:22 - 00000278 _____ E:\WINDOWS\game.ini
2013-09-08 21:22 - 2013-09-08 21:22 - 00000000 ____D E:\WINDOWS\system32\LogFiles
2013-09-06 15:41 - 2013-09-06 15:41 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.mono
2013-09-06 15:27 - 2013-09-06 15:27 - 00000000 __SHD E:\WINDOWS\system32\AI_RecycleBin
2013-09-06 15:26 - 2013-09-06 15:26 - 00000000 ____D E:\Program Files\Pando Networks
2013-09-06 15:26 - 2013-09-06 15:26 - 00000000 ____D E:\Documents and Settings\All Users\Data aplikac
2013-09-06 15:25 - 2013-09-06 15:26 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Riot Games
2013-09-05 16:05 - 2013-09-05 16:05 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\Mimibazar
2013-09-05 14:08 - 2013-09-05 15:10 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\Crysis2
2013-09-04 20:35 - 2013-09-04 20:55 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Hamachi
2013-09-04 20:35 - 2013-09-04 20:35 - 00025280 _____ (LogMeIn, Inc.) E:\WINDOWS\system32\Drivers\hamachi.sys
2013-09-04 20:35 - 2013-09-04 20:35 - 00000000 ____D E:\Program Files\Hamachi
2013-09-04 19:49 - 2013-09-04 19:54 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Origin
2013-09-03 14:48 - 2013-09-03 14:48 - 00000975 _____ E:\Documents and Settings\Admin\Plocha\PC Inspector File Recovery.lnk
2013-09-03 14:48 - 2013-09-03 14:48 - 00000000 ____D E:\Program Files\Convar
2013-09-03 14:48 - 2013-09-03 14:48 - 00000000 ____D E:\Documents and Settings\Admin\Nabídka Start\Programy\Convar
2013-09-02 16:49 - 2013-09-02 16:49 - 00000000 ____D E:\Program Files\Western Digital Corporation
2013-09-02 16:49 - 2013-09-02 16:49 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\Nová složka
2013-08-28 12:03 - 2013-08-28 12:03 - 00006182 _____ E:\WINDOWS\FaxSetup.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00004377 _____ E:\WINDOWS\KB2834902-v2.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00002956 _____ E:\WINDOWS\ocgen.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00002359 _____ E:\WINDOWS\tsoc.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00002024 _____ E:\WINDOWS\comsetup.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00001374 _____ E:\WINDOWS\imsins.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00001229 _____ E:\WINDOWS\ntdtcsetup.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000968 _____ E:\WINDOWS\iis6.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000386 _____ E:\WINDOWS\ocmsn.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000309 _____ E:\WINDOWS\msgsocm.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2834902-v2_WM10$
2013-08-27 12:24 - 2013-09-04 19:38 - 00000348 _____ E:\WINDOWS\setupact.log
2013-08-27 12:24 - 2013-08-27 12:24 - 00000000 _____ E:\WINDOWS\setuperr.log
2013-08-27 12:23 - 2013-09-08 21:39 - 00078872 _____ E:\WINDOWS\setupapi.log
2013-08-25 20:28 - 2013-08-25 20:29 - 00040776 _____ (Malwarebytes Corporation) E:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2013-08-25 20:16 - 2013-08-25 20:19 - 00000000 ____D E:\Avenger
2013-08-25 20:15 - 2013-08-25 20:15 - 00135168 _____ E:\zip.exe
2013-08-25 20:15 - 2013-08-25 20:15 - 00019286 _____ E:\cleanup.exe
2013-08-25 20:14 - 2013-08-25 20:16 - 00001780 _____ E:\avenger.txt
2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2013-08-25 11:58 - 2013-08-25 11:58 - 00000000 ____D E:\Program Files\7-Zip
2013-08-24 19:12 - 2013-09-08 16:16 - 00000000 ____D E:\Program Files\trend micro
2013-08-24 19:12 - 2013-08-24 19:12 - 00000000 ____D E:\rsit
2013-08-24 19:04 - 2013-08-24 19:04 - 00000000 ____D E:\Program Files\CCleaner
2013-08-24 19:03 - 2013-08-24 19:03 - 00000000 ____D E:\WINDOWS\Sun
2013-08-24 14:33 - 2013-08-24 14:33 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\GlarySoft
2013-08-24 14:24 - 2013-08-24 14:24 - 00000000 ____D E:\Program Files\ESET
2013-08-22 12:58 - 2013-08-24 19:03 - 00000000 ____D E:\Program Files\Minecraft-1.4.6
2013-08-22 11:59 - 2013-05-09 10:58 - 06583664 _____ (AVAST Software) E:\Prog
2013-08-19 15:51 - 2013-09-08 20:33 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\Hry D
2013-08-17 14:53 - 2013-08-17 14:53 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\streumon
2013-08-17 09:16 - 2013-08-17 21:26 - 00000000 ____D E:\Program Files\Mozilla Firefox
2013-08-16 17:53 - 2013-08-24 14:16 - 00000000 ____D E:\WINDOWS\Minidump
2013-08-14 12:14 - 2013-08-14 12:16 - 00000000 ____D E:\WINDOWS\system32\MRT
2013-08-14 12:09 - 2013-08-14 12:09 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 12:09 - 2013-08-14 12:09 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 12:08 - 2013-08-14 12:08 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 12:08 - 2013-08-14 12:08 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2849470$
2013-08-11 21:10 - 2013-08-11 21:10 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Hi-Rez Studios
2013-08-11 21:04 - 2013-08-11 21:05 - 00000000 ____D E:\Program Files\AGEIA Technologies
2013-08-11 21:04 - 2013-08-11 21:04 - 00000000 ____D E:\WINDOWS\system32\AGEIA
2013-08-11 21:04 - 2013-08-11 21:04 - 00000000 ____D E:\Program Files\Common Files\Wise Installation Wizard
2013-08-11 10:41 - 2013-08-11 10:41 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.mnaucraft
2013-08-10 11:12 - 2013-09-09 16:31 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.techniclauncher

==================== One Month Modified Files and Folders =======

2013-09-09 16:37 - 2013-09-09 16:37 - 00000000 ____D E:\FRST
2013-09-09 16:37 - 2013-07-16 15:27 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\Stažené soubory
2013-09-09 16:37 - 2013-07-16 13:51 - 00000000 ___HD E:\DOCUME~1\Admin\LOCALS~1\Data aplikací
2013-09-09 16:37 - 2013-07-16 13:51 - 00000000 ____D E:\Documents and Settings\Admin\Plocha
2013-09-09 16:31 - 2013-08-10 11:12 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.techniclauncher
2013-09-09 16:28 - 2013-07-17 16:27 - 00000914 _____ E:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-09-09 16:19 - 2013-07-16 16:35 - 00065536 _____ E:\WINDOWS\system32\config\ACEEvent.evt
2013-09-09 16:18 - 2013-07-17 17:13 - 00000938 _____ E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-09 16:01 - 2013-07-16 16:05 - 00000466 ____H E:\WINDOWS\Tasks\User_Feed_Synchronization-{B2C153F0-FBDB-4EE1-9E14-848BD117B08E}.job
2013-09-09 15:55 - 2013-07-16 13:44 - 01627395 _____ E:\WINDOWS\WindowsUpdate.log
2013-09-09 15:38 - 2013-07-16 15:38 - 00000362 ____H E:\WINDOWS\Tasks\avast! Emergency Update.job
2013-09-09 14:11 - 2013-07-17 16:41 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Skype
2013-09-09 14:00 - 2013-09-09 14:00 - 00000217 _____ E:\Documents and Settings\Admin\Plocha\Call of Duty Modern Warfare 2 - Multiplayer.url
2013-09-09 13:11 - 2013-07-17 17:13 - 00000934 _____ E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-09 13:11 - 2013-07-16 15:35 - 00000159 _____ E:\WINDOWS\wiadebug.log
2013-09-09 13:11 - 2013-07-16 15:35 - 00000048 _____ E:\WINDOWS\wiaservc.log
2013-09-09 13:11 - 2013-07-16 13:51 - 00000006 ____H E:\WINDOWS\Tasks\SA.DAT
2013-09-09 13:11 - 2008-04-14 14:00 - 00013646 _____ E:\WINDOWS\system32\wpa.dbl
2013-09-08 23:29 - 2013-09-09 16:37 - 01082207 _____ (Farbar) E:\Documents and Settings\Admin\Plocha\FRST.exe
2013-09-08 22:24 - 2013-07-17 17:49 - 00131072 _____ E:\WINDOWS\system32\config\OAlerts.evt
2013-09-08 22:24 - 2013-07-16 13:51 - 00032318 _____ E:\WINDOWS\SchedLgU.Txt
2013-09-08 22:24 - 2013-07-16 13:51 - 00000178 ___SH E:\Documents and Settings\Admin\ntuser.ini
2013-09-08 22:24 - 2013-07-16 13:51 - 00000000 ____D E:\Documents and Settings\Admin
2013-09-08 22:23 - 2013-07-20 17:56 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\Soubory aplikace Outlook
2013-09-08 22:02 - 2013-09-08 21:23 - 00022328 _____ E:\WINDOWS\system32\Drivers\PnkBstrK.sys
2013-09-08 22:02 - 2013-09-08 21:22 - 00103736 _____ E:\WINDOWS\system32\PnkBstrB.exe
2013-09-08 21:53 - 2013-09-08 21:22 - 00066872 _____ E:\WINDOWS\system32\PnkBstrA.exe
2013-09-08 21:48 - 2013-09-08 21:48 - 00001508 _____ E:\Documents and Settings\Admin\Plocha\GamePark.lnk
2013-09-08 21:48 - 2013-07-20 17:41 - 00000000 ____D E:\Program Files\GamePark
2013-09-08 21:46 - 2013-07-16 14:19 - 00000000 ___HD E:\Program Files\InstallShield Installation Information
2013-09-08 21:39 - 2013-09-08 21:39 - 00000000 __SHD E:\WINDOWS\ftpcache
2013-09-08 21:39 - 2013-09-08 21:38 - 00124380 _____ E:\WINDOWS\DirectX.log
2013-09-08 21:39 - 2013-08-27 12:23 - 00078872 _____ E:\WINDOWS\setupapi.log
2013-09-08 21:39 - 2013-07-16 13:43 - 00000000 ____D E:\WINDOWS\system32\DirectX
2013-09-08 21:38 - 2013-07-16 15:33 - 00000000 ____D E:\Documents and Settings\All Users\Plocha
2013-09-08 21:23 - 2013-09-08 21:23 - 00022328 _____ E:\Documents and Settings\Admin\Data aplikací\PnkBstrK.sys
2013-09-08 21:23 - 2013-07-16 13:51 - 00000000 __RHD E:\Documents and Settings\Admin\Data aplikací
2013-09-08 21:22 - 2013-09-08 21:22 - 00000278 _____ E:\WINDOWS\game.ini
2013-09-08 21:22 - 2013-09-08 21:22 - 00000000 ____D E:\WINDOWS\system32\LogFiles
2013-09-08 20:33 - 2013-08-19 15:51 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\Hry D
2013-09-08 19:34 - 2013-07-21 20:39 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.technic
2013-09-08 16:16 - 2013-08-24 19:12 - 00000000 ____D E:\Program Files\trend micro
2013-09-06 15:41 - 2013-09-06 15:41 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.mono
2013-09-06 15:27 - 2013-09-06 15:27 - 00000000 __SHD E:\WINDOWS\system32\AI_RecycleBin
2013-09-06 15:26 - 2013-09-06 15:26 - 00000000 ____D E:\Program Files\Pando Networks
2013-09-06 15:26 - 2013-09-06 15:26 - 00000000 ____D E:\Documents and Settings\All Users\Data aplikac
2013-09-06 15:26 - 2013-09-06 15:25 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Riot Games
2013-09-06 15:26 - 2013-07-16 15:31 - 00000000 __RHD E:\Documents and Settings\All Users\Data aplikací
2013-09-05 16:05 - 2013-09-05 16:05 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\Mimibazar
2013-09-05 15:10 - 2013-09-05 14:08 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\Crysis2
2013-09-05 14:08 - 2013-07-16 13:51 - 00000000 ___RD E:\Documents and Settings\Admin\Dokumenty
2013-09-04 20:55 - 2013-09-04 20:35 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Hamachi
2013-09-04 20:53 - 2013-07-16 13:51 - 00000000 ___RD E:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění
2013-09-04 20:35 - 2013-09-04 20:35 - 00025280 _____ (LogMeIn, Inc.) E:\WINDOWS\system32\Drivers\hamachi.sys
2013-09-04 20:35 - 2013-09-04 20:35 - 00000000 ____D E:\Program Files\Hamachi
2013-09-04 19:54 - 2013-09-04 19:49 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Origin
2013-09-04 19:38 - 2013-08-27 12:24 - 00000348 _____ E:\WINDOWS\setupact.log
2013-09-03 14:48 - 2013-09-03 14:48 - 00000975 _____ E:\Documents and Settings\Admin\Plocha\PC Inspector File Recovery.lnk
2013-09-03 14:48 - 2013-09-03 14:48 - 00000000 ____D E:\Program Files\Convar
2013-09-03 14:48 - 2013-09-03 14:48 - 00000000 ____D E:\Documents and Settings\Admin\Nabídka Start\Programy\Convar
2013-09-03 14:48 - 2013-07-16 13:51 - 00000000 ___RD E:\Documents and Settings\Admin\Nabídka Start\Programy
2013-09-02 16:49 - 2013-09-02 16:49 - 00000000 ____D E:\Program Files\Western Digital Corporation
2013-09-02 16:49 - 2013-09-02 16:49 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\Nová složka
2013-09-02 16:34 - 2013-07-16 15:01 - 00001324 _____ E:\WINDOWS\system32\d3d9caps.dat
2013-08-28 12:03 - 2013-08-28 12:03 - 00006182 _____ E:\WINDOWS\FaxSetup.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00004377 _____ E:\WINDOWS\KB2834902-v2.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00002956 _____ E:\WINDOWS\ocgen.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00002359 _____ E:\WINDOWS\tsoc.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00002024 _____ E:\WINDOWS\comsetup.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00001374 _____ E:\WINDOWS\imsins.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00001229 _____ E:\WINDOWS\ntdtcsetup.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000968 _____ E:\WINDOWS\iis6.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000386 _____ E:\WINDOWS\ocmsn.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000309 _____ E:\WINDOWS\msgsocm.log
2013-08-28 12:03 - 2013-08-28 12:03 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2834902-v2_WM10$
2013-08-27 12:24 - 2013-08-27 12:24 - 00000000 _____ E:\WINDOWS\setuperr.log
2013-08-25 20:29 - 2013-08-25 20:28 - 00040776 _____ (Malwarebytes Corporation) E:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2013-08-25 20:19 - 2013-08-25 20:16 - 00000000 ____D E:\Avenger
2013-08-25 20:16 - 2013-08-25 20:14 - 00001780 _____ E:\avenger.txt
2013-08-25 20:15 - 2013-08-25 20:15 - 00135168 _____ E:\zip.exe
2013-08-25 20:15 - 2013-08-25 20:15 - 00019286 _____ E:\cleanup.exe
2013-08-25 18:46 - 2013-07-16 16:08 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB971657$
2013-08-25 12:04 - 2013-08-25 12:04 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2013-08-25 11:58 - 2013-08-25 11:58 - 00000000 ____D E:\Program Files\7-Zip
2013-08-25 09:42 - 2008-04-14 14:00 - 00000826 _____ E:\WINDOWS\win.ini
2013-08-24 19:12 - 2013-08-24 19:12 - 00000000 ____D E:\rsit
2013-08-24 19:04 - 2013-08-24 19:04 - 00000000 ____D E:\Program Files\CCleaner
2013-08-24 19:03 - 2013-08-24 19:03 - 00000000 ____D E:\WINDOWS\Sun
2013-08-24 19:03 - 2013-08-22 12:58 - 00000000 ____D E:\Program Files\Minecraft-1.4.6
2013-08-24 19:03 - 2013-07-21 20:45 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.minecraft
2013-08-24 14:33 - 2013-08-24 14:33 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\GlarySoft
2013-08-24 14:24 - 2013-08-24 14:24 - 00000000 ____D E:\Program Files\ESET
2013-08-24 14:16 - 2013-08-16 17:53 - 00000000 ____D E:\WINDOWS\Minidump
2013-08-24 11:39 - 2013-07-26 22:15 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Awesomium
2013-08-23 08:22 - 2013-07-16 16:24 - 00000000 ____D E:\WINDOWS\Microsoft.NET
2013-08-22 18:39 - 2013-07-16 15:34 - 01146122 _____ E:\WINDOWS\system32\PerfStringBackup.INI
2013-08-22 15:51 - 2013-07-27 14:49 - 00000000 ____D E:\Documents and Settings\Admin\Plocha\cesnek
2013-08-17 21:26 - 2013-08-17 09:16 - 00000000 ____D E:\Program Files\Mozilla Firefox
2013-08-17 21:26 - 2013-07-16 14:42 - 00000000 ____D E:\Program Files\Mozilla Maintenance Service
2013-08-17 14:53 - 2013-08-17 14:53 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\streumon
2013-08-17 09:41 - 2013-07-19 19:54 - 00000000 ____D E:\Documents and Settings\Admin\Dokumenty\My Games
2013-08-14 12:16 - 2013-08-14 12:14 - 00000000 ____D E:\WINDOWS\system32\MRT
2013-08-14 12:16 - 2013-07-16 15:47 - 00000000 ____D E:\WINDOWS\ie8updates
2013-08-14 12:13 - 2013-07-16 15:40 - 75778376 _____ (Microsoft Corporation) E:\WINDOWS\system32\MRT.exe
2013-08-14 12:09 - 2013-08-14 12:09 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2859537$
2013-08-14 12:09 - 2013-08-14 12:09 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2850869$
2013-08-14 12:08 - 2013-08-14 12:08 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2863058$
2013-08-14 12:08 - 2013-08-14 12:08 - 00000000 __HDC E:\WINDOWS\$NtUninstallKB2849470$
2013-08-14 12:08 - 2013-07-16 15:42 - 00012520 _____ E:\WINDOWS\system32\TZLog.log
2013-08-13 08:32 - 2013-07-17 16:11 - 00000113 _____ E:\Documents and Settings\Admin\default.pls
2013-08-12 08:10 - 2013-07-16 15:31 - 00270984 _____ E:\WINDOWS\system32\FNTCACHE.DAT
2013-08-11 21:10 - 2013-08-11 21:10 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\Hi-Rez Studios
2013-08-11 21:09 - 2013-07-16 16:28 - 00000000 ____D E:\WINDOWS\system32\XPSViewer
2013-08-11 21:09 - 2013-07-16 13:51 - 00000000 ___HD E:\Documents and Settings\LocalService\Local Settings\Data aplikací
2013-08-11 21:05 - 2013-08-11 21:04 - 00000000 ____D E:\Program Files\AGEIA Technologies
2013-08-11 21:04 - 2013-08-11 21:04 - 00000000 ____D E:\WINDOWS\system32\AGEIA
2013-08-11 21:04 - 2013-08-11 21:04 - 00000000 ____D E:\Program Files\Common Files\Wise Installation Wizard
2013-08-11 10:41 - 2013-08-11 10:41 - 00000000 ____D E:\Documents and Settings\Admin\Data aplikací\.mnaucraft

Files to move or delete:
====================
E:\DOCUME~1\Admin\LOCALS~1\Temp\7z920.exe
E:\DOCUME~1\Admin\LOCALS~1\Temp\aiw3835453.EXE
E:\DOCUME~1\Admin\LOCALS~1\Temp\bassmod.dll
E:\DOCUME~1\Admin\LOCALS~1\Temp\fp_pl_pfs_installer.exe
E:\DOCUME~1\Admin\LOCALS~1\Temp\swt-win32-3349.dll

==================== Bamital & volsnap Check =================

E:\Windows\explorer.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 1034240 ____A (Microsoft Corporation) 27afd587c462e280ee046b8cca3c2cd1

E:\Windows\System32\winlogon.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0507904 ____A (Microsoft Corporation) cddb1f8e1aea356f3ad106f2cf9b7fea

E:\Windows\System32\svchost.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0014336 ____A (Microsoft Corporation) be4a520e29b6391f49e79ccc52044d93

E:\Windows\System32\services.exe
[2008-04-14 14:00] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 9ef697af07bb8dd82c3b02ca953a95b7

E:\Windows\System32\User32.dll
[2008-04-14 14:00] - [2008-04-14 14:00] - 0578560 ____A (Microsoft Corporation) e16e0990967374e76f3e40cacafd3d53

E:\Windows\System32\userinit.exe
[2008-04-14 14:00] - [2008-04-14 14:00] - 0026112 ____A (Microsoft Corporation) 7dc1830f22e7d275b438127b68030239

E:\Windows\System32\Drivers\volsnap.sys
[2008-04-14 14:00] - [2008-04-14 14:00] - 0052480 ____A (Microsoft Corporation) 28a4b296b47782173c346e376cb374d1

==================== Alternate Data Streams (whitelisted) ====

AlternateDataStreams: E:\Documents and Settings\Admin\Plocha\Thumbs.db:encryptable

==================== Loaded Modules (whitelisted) ============

2013-09-09 13:12 - 2013-09-09 08:52 - 02098176 _____ () E:\Program Files\AVAST Software\Avast\defs\13090900\algo.dll
2004-12-07 20:47 - 2004-12-07 20:47 - 00077824 _____ (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) E:\WINDOWS\system32\MLMON__Q.DLL
2003-07-22 09:44 - 2003-07-22 09:44 - 00051200 _____ (Zenographics, Inc.) E:\WINDOWS\system32\MSPOOL_Q.dll
2003-07-22 09:44 - 2003-07-22 09:44 - 00010240 _____ (Zenographics, Inc.) E:\WINDOWS\System32\spool\PRTPROCS\W32X86\MIMFPR_Q.DLL
2003-07-22 09:44 - 2003-07-22 09:44 - 00013824 _____ (Zenographics, Inc.) E:\WINDOWS\system32\MIMF32_Q.dll
2003-07-22 09:44 - 2003-07-22 09:44 - 00019456 _____ (Zenographics, Inc.) E:\WINDOWS\system32\MTAG32_Q.dll
2013-07-16 16:28 - 2008-07-06 14:06 - 00089088 _____ (Microsoft Corporation) E:\WINDOWS\System32\spool\PRTPROCS\W32X86\filterpipelineprintproc.dll
2007-09-20 15:33 - 2007-09-20 15:33 - 00255272 _____ (Nero AG) E:\Program Files\Nero\Nero8\Nero BackItUp\NBShell.dll
2013-07-27 17:09 - 2008-09-16 20:18 - 00132608 _____ () E:\Program Files\WinRAR\rarext.dll
2013-07-27 17:09 - 2008-10-11 22:18 - 00319488 _____ () E:\Program Files\WinRAR\rarlng.dll
2007-09-24 09:10 - 2007-09-24 09:10 - 02106664 _____ (Nero AG) E:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll
2007-09-26 19:37 - 2007-09-26 19:37 - 03949864 _____ (Nero AG) E:\Program Files\Common Files\Nero\Shared\NL3\AdvrCntr3.dll
2008-04-14 14:00 - 2008-04-14 14:00 - 00087552 _____ (Microsoft Corporation) E:\WINDOWS\system32\mui\0005\HHCTRLui.dll
2004-08-31 20:50 - 2004-08-31 20:50 - 01490944 _____ (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.) E:\WINDOWS\system32\mstmon_Q.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 00064808 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMIndexingServicePS.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 00027432 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvrPS.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 03118376 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMDataServices.dll
2008-04-14 14:00 - 2008-04-14 14:00 - 00014336 _____ () E:\WINDOWS\system32\msdmo.dll
2013-06-21 09:53 - 2013-06-21 09:53 - 00088680 ____R (Skype Technologies) E:\Program Files\Skype\Updater\Updater.dll
2010-03-16 11:22 - 2010-03-16 11:22 - 00014848 _____ () E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
2010-03-16 11:22 - 2010-03-16 11:22 - 00013312 _____ ( ) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\Interop.WBOCXLib.dll
2012-11-16 14:40 - 2012-11-16 14:40 - 00389120 _____ (Advanced Mirco Devices, Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Runtime.dll
2012-11-16 14:39 - 2012-11-16 14:39 - 00155648 _____ (Advanced Mirco Devices, Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Caste.Graphics.Shared.dll
2010-03-16 11:22 - 2010-03-16 11:22 - 00050688 _____ (Stardock.Net, Inc) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\32\wbhelp2.dll
2009-01-20 13:51 - 2009-01-20 13:51 - 00007168 _____ ( ) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atixclib.dll
2012-11-16 14:43 - 2012-11-16 14:43 - 00069632 _____ (Advanced Mirco Devices, Inc.) E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.Welcome.Graphics.Dashboard.dll
2012-11-16 14:44 - 2012-11-16 14:44 - 00270336 _____ () E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2007-09-20 09:51 - 2007-09-20 09:51 - 01013032 _____ (Nero AG) E:\Program Files\Nero\Nero8\Nero BackItUp\NB.dll
2007-09-26 19:37 - 2007-09-26 19:37 - 00140584 _____ (Nero AG) E:\Program Files\Nero\Nero8\Nero BackItUp\NeroAPIGlueLayerUnicode.dll
2007-09-20 09:51 - 2007-09-20 09:51 - 00410920 _____ (Nero AG) E:\Program Files\Nero\Nero8\Nero BackItUp\LBFC.dll
2007-09-20 09:51 - 2007-09-20 09:51 - 00566568 _____ (Nero AG) E:\Program Files\Nero\Nero8\Nero BackItUp\NBHDMgr.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 00075048 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMLogCxx.dll
2007-09-25 17:40 - 2007-09-25 17:40 - 00828712 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\log4cxx.dll
2007-09-20 15:36 - 2007-09-20 15:36 - 00279848 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMSQLDB.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 00738600 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMCoFoundation.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 00173352 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMPluginBase.dll
2007-09-20 15:35 - 2007-09-20 15:35 - 00222504 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMFullTextExtraction.dll
2007-09-20 15:36 - 2007-09-20 15:36 - 00234792 _____ (Nero AG) E:\Program Files\Common Files\Nero\Lib\NMSearchPluginSimilarImages.dll
2013-08-17 09:16 - 2013-08-17 09:16 - 03551640 _____ () E:\Program Files\Mozilla Firefox\mozjs.dll
2013-07-17 16:27 - 2013-07-17 16:27 - 16166280 _____ () E:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
2013-09-04 19:39 - 2013-08-28 23:47 - 00288680 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\crashhandler.dll
2013-09-03 15:36 - 2013-07-16 00:32 - 02895272 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\steam.dll
2013-09-04 19:39 - 2013-08-28 23:47 - 10654632 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\steamui.dll
2013-09-03 15:36 - 2013-08-22 00:18 - 00687104 _____ () D:\PROGRAMY INSTAL\Steam\SDL2.dll
2013-09-04 19:39 - 2013-08-28 23:47 - 00263080 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\tier0_s.dll
2013-09-04 19:39 - 2013-08-28 23:47 - 00236456 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\vstdlib_s.dll
2013-09-03 15:35 - 2013-06-15 01:49 - 01039192 _____ (Microsoft Corporation) D:\PROGRAMY INSTAL\Steam\DbgHelp.dll
2013-09-03 15:35 - 2013-06-15 01:49 - 00122864 _____ (Valve) D:\PROGRAMY INSTAL\Steam\CSERHelper.dll
2013-09-03 15:33 - 2013-08-28 23:47 - 00169384 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\bin\filesystem_stdio.dll
2013-09-03 15:35 - 2013-08-28 23:47 - 00694696 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\bin\vgui2_s.dll
2013-09-03 15:33 - 2013-08-28 23:47 - 01120680 _____ () D:\PROGRAMY INSTAL\Steam\bin\chromehtml.dll
2013-09-03 15:33 - 2013-08-07 21:31 - 20625832 _____ () D:\PROGRAMY INSTAL\Steam\bin\libcef.dll
2013-09-03 15:33 - 2013-06-15 01:49 - 09955112 _____ (The ICU Project) D:\PROGRAMY INSTAL\Steam\bin\icudt.dll
2013-09-03 15:33 - 2013-06-15 01:49 - 01100800 _____ () D:\PROGRAMY INSTAL\Steam\bin\avcodec-53.dll
2013-09-03 15:33 - 2013-06-15 01:49 - 00124416 _____ () D:\PROGRAMY INSTAL\Steam\bin\avutil-51.dll
2013-09-03 15:33 - 2013-06-15 01:49 - 00192000 _____ () D:\PROGRAMY INSTAL\Steam\bin\avformat-53.dll
2013-09-04 19:39 - 2013-08-28 23:47 - 07745960 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\steamclient.dll
2013-09-03 15:35 - 2013-08-28 23:47 - 02090408 _____ (Valve Corporation) D:\PROGRAMY INSTAL\Steam\bin\steamservice.dll
2013-09-03 15:33 - 2013-08-28 23:47 - 02449832 _____ (Valve Corporation) d:\programy instal\steam\bin\friendsui.dll
2013-09-03 15:34 - 2013-08-28 23:47 - 01804712 _____ (Valve Corporation) d:\programy instal\steam\bin\serverbrowser.dll
Description: Chybující aplikace setup.exe, verze 9.3.2.2730, chybující modul system.dll, verze 0.0.0.0, adresa chyby 0x000018cb.
Description: Chybující aplikace plugin-container.exe, verze 22.0.0.4917, chybující modul mozalloc.dll, verze 22.0.0.4917, adresa chyby 0x00001988.
Description: setup.exe9.3.2.2730system.dll0.0.0.0000018cb
Description: plugin-container.exe22.0.0.4917mozalloc.dll22.0.0.491700001988

==================== Scheduled Tasks (whitelisted) ===========

Task: E:\WINDOWS\Tasks\Adobe Flash Player Updater.job => E:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\WINDOWS\Tasks\avast! Emergency Update.job => E:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files\Google\Update\GoogleUpdate.exe
Task: E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files\Google\Update\GoogleUpdate.exe
Task: E:\WINDOWS\Tasks\User_Feed_Synchronization-{B2C153F0-FBDB-4EE1-9E14-848BD117B08E}.job => E:\WINDOWS\system32\msfeedssync.exe

==================== Supplementary Scan (All) ================


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\{1a3e09be-1e45-494b-9174-d7385b45bbf5}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=dword:00000001
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"="E:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe:*:Enabled:Pando Media Booster"


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe"="E:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe:*:Enabled:Nero ShowTime"
"E:\\Program Files\\Skype\\Phone\\Skype.exe"="E:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"E:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"="E:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"E:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"="E:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"E:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"="E:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Warframe\\Warframe.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Warframe\\Warframe.exe:*:Enabled:Warframe Steam Game 32"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Warframe\\Warframe.x64.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Warframe\\Warframe.x64.exe:*:Enabled:Warframe Steam Game 64"
"E:\\Program Files\\Java\\jre7\\bin\\javaw.exe"="E:\\Program Files\\Java\\jre7\\bin\\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Torchlight II\\Torchlight2.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Torchlight II\\Torchlight2.exe:*:Enabled:Torchlight II"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Borderlands 2\\Binaries\\Win32\\Borderlands2.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Borderlands 2\\Binaries\\Win32\\Borderlands2.exe:*:Enabled:borderlands game"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\regnum\\LiveServer\\ROClientGame.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\regnum\\LiveServer\\ROClientGame.exe:*:Enabled:champions of regnum"
"D:\\hry instal\\World_of_Warplanes\\WOWpLauncher.exe"="D:\\hry instal\\World_of_Warplanes\\WOWpLauncher.exe:*:Enabled:World of Warplanes Launcher"
"D:\\hry instal\\CO4\\iw3mp.exe"="D:\\hry instal\\CO4\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Global Agenda Live\\Binaries\\GlobalAgenda.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Global Agenda Live\\Binaries\\GlobalAgenda.exe:*:Enabled:TgGame Client"
"D:\\PROGRAMY INSTAL\\Steam\\Steam.exe"="D:\\PROGRAMY INSTAL\\Steam\\Steam.exe:*:Enabled:Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)"
"D:\\hry instal\\Panzar\\start.exe"="D:\\hry instal\\Panzar\\start.exe:*:Enabled:FBC Update Client"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Team Fortress 2\\hl2.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Team Fortress 2\\hl2.exe:*:Enabled:Team Fortress 2"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\dota 2 beta\\dota.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\dota 2 beta\\dota.exe:*:Enabled:Dota 2"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Magicka\\Magicka.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Magicka\\Magicka.exe:*:Enabled:Magicka"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Torchlight II\\ModLauncher.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Torchlight II\\ModLauncher.exe:*:Enabled:Torchlight II"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\PlanetSide 2\\LaunchPad.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\PlanetSide 2\\LaunchPad.exe:*:Enabled:PlanetSide 2"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Warframe\\Tools\\Launcher.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Warframe\\Tools\\Launcher.exe:*:Enabled:Warframe"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Crysis 2 Game of the Year\\bin32\\Crysis2Launcher.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Crysis 2 Game of the Year\\bin32\\Crysis2Launcher.exe:*:Enabled:Crysis 2 Maximum Edition"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Borderlands 2\\Binaries\\Win32\\Launcher.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Borderlands 2\\Binaries\\Win32\\Launcher.exe:*:Enabled:Borderlands 2"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Crysis 2 Game of the Year\\bin32\\Crysis2.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Crysis 2 Game of the Year\\bin32\\Crysis2.exe:*:Enabled:Crysis2"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\MarchOfWar\\game.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\MarchOfWar\\game.exe:*:Enabled:March of War"
"E:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"="E:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe:*:Enabled:Pando Media Booster"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\MarchOfWar\\MarchOfWar.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\MarchOfWar\\MarchOfWar.exe:*:Enabled:MarchOfWar"
"D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Marvel Heroes\\UnrealEngine3\\Binaries\\Win32\\MarvelGame.exe"="D:\\PROGRAMY INSTAL\\Steam\\steamapps\\common\\Marvel Heroes\\UnrealEngine3\\Binaries\\Win32\\MarvelGame.exe:*:Enabled:Marvel Heroes"
"C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\iw4mpOLD.exe"="C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\iw4mpOLD.exe:*:Enabled: "
"C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\iw4sp.exe"="C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\iw4sp.exe:*:Enabled:iw4sp"
"E:\\WINDOWS\\system32\\PnkBstrA.exe"="E:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"E:\\WINDOWS\\system32\\PnkBstrB.exe"="E:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\\hry instal\\cod4\\iw3mp.exe"="D:\\hry instal\\cod4\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\iw4mp.exe"="C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\iw4mp.exe:*:Enabled:IW4 Launcher"
"C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\bootstrap\\iw4mp.exe"="C:\\download\\Call of Duty Modern Warfare 2 MP Works 100%\\call of duty modern warfare 2\\bootstrap\\iw4mp.exe:*:Enabled:IW4 Launcher"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"59045:TCP"="59045:TCP:*:Enabled:Pando Media Booster"
"59045:UDP"="59045:UDP:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"59045:TCP"="59045:TCP:*:Enabled:Pando Media Booster"
"59045:UDP"="59045:UDP:*:Enabled:Pando Media Booster"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"="midimap.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.trspch"="tssoft32.acm"
"vidc.cvid"="iccvid.dll"
"VIDC.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"VIDC.IYUV"="iyuv_32.dll"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"VIDC.UYVY"="msyuv.dll"
"VIDC.YUY2"="msyuv.dll"
"VIDC.YVU9"="tsbyuv.dll"
"VIDC.YVYU"="msyuv.dll"
"wavemapper"="msacm32.drv"
"msacm.msg723"="msg723.acm"
"vidc.M263"="msh263.drv"
"vidc.M261"="msh261.drv"
"msacm.msaudio1"="msaud32.acm"
"msacm.sl_anet"="sl_anet.acm"
"msacm.iac2"="E:\\WINDOWS\\system32\\iac25_32.ax"
"vidc.iv50"="ir50_32.dll"
"msacm.l3acm"="E:\\WINDOWS\\system32\\l3codeca.acm"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"
"aux"="wdmaud.drv"
"wave1"="wdmaud.drv"
"midi1"="wdmaud.drv"
"mixer1"="wdmaud.drv"
"aux1"="wdmaud.drv"
"MSVideo8"="VfWWDM32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server\RDP]
"wave"="rdpsnd.dll"
"mixer"="rdpsnd.dll"
"MaxBandwidth"=dword:000056b9
"wavemapper"="msacm32.drv"
"EnableMP3Codec"=dword:00000001
"midimapper"="midimap.dll"


==================== Drive and Memory info ===================

Drive c: (Nový svazek) (Fixed) (Total:164.52 GB) (Free:115.7 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (Nový svazek) (Fixed) (Total:465.76 GB) (Free:390.65 GB) NTFS
Drive e: () (Fixed) (Total:68.35 GB) (Free:43.06 GB) NTFS

Available physical RAM: 1910.97 MB
Total physical RAM: 3070.48 MB
Percentage of memory in use: 37%


==================== End Of Log ==============================

Malwarebytes Anti-Malware 1.75.0.1300
http://www.malwarebytes.org

Verze: v2013.09.09.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Admin :: ADMIN-260F498AE [administrátor]

9.9.2013 17:01:50
MBAM-log-2013-09-09 (18-15-21).txt

Typ: Kompletní kontrola (C:\|D:\|E:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 365072
Uplynulý čas: 1 hodin, 34 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 1
E:\WINDOWS\inf\ntvdm.inf (Malware.Trace) -> Nebyla provedena žádná instrukce.

(konec)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Google-hláška

#4 Příspěvek od vyosek »

:arrow: Ono je to vylozene problem site, resp. zrejme ta IP adresa muze mit nejake problemy

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [NeroFilterCheck] - E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
    HKLM\...\Run: [NBKeyScan] - E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [1836328 2007-09-20] (Nero AG)
    HKLM\...\Run: [RemoteControl10] - E:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
    HKLM\...\Run: [BDRegion] - E:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink)
    HKLM\...\Run: [BCSSync] - E:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
    HKLM\...\Run: [KONICA MINOLTA PagePro 1350WStatusDisplay] - E:\WINDOWS\system32\MSTMON_Q.EXE [167936 2004-11-26] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
    HKLM\...\Run: [SunJavaUpdateSched] - E:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
    HKLM\...\Run: [Adobe ARM] - E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-10] (Adobe Systems Incorporated)
    HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-09-20] (Nero AG)
    HKCU\...\Run: [Skype] - E:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
    HKCU\...\Run: [OfficeSyncProcess] - E:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [719672 2012-01-20] (Microsoft Corporation)
    HKCU\...\Run: [EADM] - D:\PROGRAMY INSTAL\Origin\Origin.exe [3549528 2013-09-04] (Electronic Arts)
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
    HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
    
    CHR HomePage: hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
    
    S1 AmdK8; system32\DRIVERS\AmdK8.sys [x]
    S1 AmdPPM; system32\DRIVERS\AmdPPM.sys [x]
    S4 IntelIde; No ImagePath
    U1 WS2IFSL; 
    
    2013-08-25 20:16 - 2013-08-25 20:19 - 00000000 ____D E:\Avenger
    2013-08-25 20:15 - 2013-08-25 20:15 - 00135168 _____ E:\zip.exe
    2013-08-25 20:15 - 2013-08-25 20:15 - 00019286 _____ E:\cleanup.exe
    2013-08-25 20:14 - 2013-08-25 20:16 - 00001780 _____ E:\avenger.txt
    E:\DOCUME~1\Admin\LOCALS~1\Temp\7z920.exe
    E:\DOCUME~1\Admin\LOCALS~1\Temp\aiw3835453.EXE
    E:\DOCUME~1\Admin\LOCALS~1\Temp\bassmod.dll
    E:\DOCUME~1\Admin\LOCALS~1\Temp\fp_pl_pfs_installer.exe
    E:\DOCUME~1\Admin\LOCALS~1\Temp\swt-win32-3349.dll
    E:\WINDOWS\inf\ntvdm.inf
    
    AlternateDataStreams: E:\Documents and Settings\Admin\Plocha\Thumbs.db:encryptable
    
    Task: E:\WINDOWS\Tasks\Adobe Flash Player Updater.job => E:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: E:\WINDOWS\Tasks\avast! Emergency Update.job => E:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
    Task: E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files\Google\Update\GoogleUpdate.exe
    Task: E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files\Google\Update\GoogleUpdate.exe
    Task: E:\WINDOWS\Tasks\User_Feed_Synchronization-{B2C153F0-FBDB-4EE1-9E14-848BD117B08E}.job => E:\WINDOWS\system32\msfeedssync.exe
    
    Hosts:
    CMD: shutdown /r /f /t 2
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Google-hláška

#5 Příspěvek od civrs »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-09-2013 01
Ran by Admin at 2013-09-09 20:12:23 Run:1
Running from E:\Documents and Settings\Admin\Plocha
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [NeroFilterCheck] - E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [153136 2007-03-01] (Nero AG)
HKLM\...\Run: [NBKeyScan] - E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [1836328 2007-09-20] (Nero AG)
HKLM\...\Run: [RemoteControl10] - E:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
HKLM\...\Run: [BDRegion] - E:\Program Files\Cyberlink\Shared files\brs.exe [75048 2010-03-13] (cyberlink)
HKLM\...\Run: [BCSSync] - E:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [KONICA MINOLTA PagePro 1350WStatusDisplay] - E:\WINDOWS\system32\MSTMON_Q.EXE [167936 2004-11-26] (KONICA MINOLTA BUSINESS TECHNOLOGIES, INC.)
HKLM\...\Run: [SunJavaUpdateSched] - E:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] - E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-10] (Adobe Systems Incorporated)
HKCU\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - E:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [202024 2007-09-20] (Nero AG)
HKCU\...\Run: [Skype] - E:\Program Files\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.)
HKCU\...\Run: [OfficeSyncProcess] - E:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [719672 2012-01-20] (Microsoft Corporation)
HKCU\...\Run: [EADM] - D:\PROGRAMY INSTAL\Origin\Origin.exe [3549528 2013-09-04] (Electronic Arts)

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch

CHR HomePage: hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome

S1 AmdK8; system32\DRIVERS\AmdK8.sys [x]
S1 AmdPPM; system32\DRIVERS\AmdPPM.sys [x]
S4 IntelIde; No ImagePath
U1 WS2IFSL;

2013-08-25 20:16 - 2013-08-25 20:19 - 00000000 ____D E:\Avenger
2013-08-25 20:15 - 2013-08-25 20:15 - 00135168 _____ E:\zip.exe
2013-08-25 20:15 - 2013-08-25 20:15 - 00019286 _____ E:\cleanup.exe
2013-08-25 20:14 - 2013-08-25 20:16 - 00001780 _____ E:\avenger.txt
E:\DOCUME~1\Admin\LOCALS~1\Temp\7z920.exe
E:\DOCUME~1\Admin\LOCALS~1\Temp\aiw3835453.EXE
E:\DOCUME~1\Admin\LOCALS~1\Temp\bassmod.dll
E:\DOCUME~1\Admin\LOCALS~1\Temp\fp_pl_pfs_installer.exe
E:\DOCUME~1\Admin\LOCALS~1\Temp\swt-win32-3349.dll
E:\WINDOWS\inf\ntvdm.inf

AlternateDataStreams: E:\Documents and Settings\Admin\Plocha\Thumbs.db:encryptable

Task: E:\WINDOWS\Tasks\Adobe Flash Player Updater.job => E:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: E:\WINDOWS\Tasks\avast! Emergency Update.job => E:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => E:\Program Files\Google\Update\GoogleUpdate.exe
Task: E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => E:\Program Files\Google\Update\GoogleUpdate.exe
Task: E:\WINDOWS\Tasks\User_Feed_Synchronization-{B2C153F0-FBDB-4EE1-9E14-848BD117B08E}.job => E:\WINDOWS\system32\msfeedssync.exe

Hosts:
CMD: shutdown /r /f /t 2
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NBKeyScan => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RemoteControl10 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BDRegion => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KONICA MINOLTA PagePro 1350WStatusDisplay => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\OfficeSyncProcess => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\EADM => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Search Page => Value deleted successfully.
CHR HomePage: hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome ==> The Chrome "Settings" can be used to fix the entry.
AmdK8 => Service deleted successfully.
AmdPPM => Service deleted successfully.
IntelIde => Service deleted successfully.
WS2IFSL => Service deleted successfully.
E:\Avenger => Moved successfully.
E:\zip.exe => Moved successfully.
E:\cleanup.exe => Moved successfully.
E:\avenger.txt => Moved successfully.
E:\DOCUME~1\Admin\LOCALS~1\Temp\7z920.exe => Moved successfully.
E:\DOCUME~1\Admin\LOCALS~1\Temp\aiw3835453.EXE => Moved successfully.
E:\DOCUME~1\Admin\LOCALS~1\Temp\bassmod.dll => Moved successfully.
E:\DOCUME~1\Admin\LOCALS~1\Temp\fp_pl_pfs_installer.exe => Moved successfully.
E:\DOCUME~1\Admin\LOCALS~1\Temp\swt-win32-3349.dll => Moved successfully.
E:\WINDOWS\inf\ntvdm.inf => Moved successfully.
E:\Documents and Settings\Admin\Plocha\Thumbs.db => ":encryptable" ADS removed successfully.
E:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
E:\WINDOWS\Tasks\avast! Emergency Update.job => Moved successfully.
E:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
E:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
E:\WINDOWS\Tasks\User_Feed_Synchronization-{B2C153F0-FBDB-4EE1-9E14-848BD117B08E}.job => Moved successfully.
E:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========


==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Google-hláška

#6 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Google-hláška

#7 Příspěvek od civrs »

Vše provedeno až na TFC,při spuštění jsem klikl na start a kouslo se to, 2X jsem musel restartovat kvoflem.
Jinak problém furt přetrvává

Teď to zkouším a vyhledávání zatím jde(jen jednou google chtěl opsat kod )

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Google-hláška

#8 Příspěvek od civrs »

Problém je furt stejný.. :?:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Google-hláška

#9 Příspěvek od vyosek »

Muzete zkusit napsat na google, ale to je tak vse...ono z te site muze byt pripojeno mnoho PC a nektere z nich muze vykazovat vetsi aktivitu...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Google-hláška

#10 Příspěvek od civrs »

civrs píše:Vše provedeno až na TFC,při spuštění jsem klikl na start a kouslo se to, 2X jsem musel restartovat kvoflem.
A co s tím TFC

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Google-hláška

#11 Příspěvek od vyosek »

Drobna vada na krase, urcite zadny problem ze nebyl aplikovan...obcas TFC zazlobi :x
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
civrs
Návštěvník
Návštěvník
Příspěvky: 153
Registrován: 02 led 2007 11:35

Re: Google-hláška

#12 Příspěvek od civrs »

Ted momentálne google chodi,takže to bude urcite nejakym pretízenim site,mel jsem strach protioze se to nikdy neobjevovalo.
Zkusim spravce site a pak info na google.
Zatím dekuji a preji prijemny zbytek tydne:-)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Google-hláška

#13 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno