Stránka 1 z 2

Prosim o kontrolu (Skype - lagne HDD)

Napsal: 07 lis 2013 20:28
od mari
Zdravím,

cca 3 dny zpět pustím PC a vidím nějaký problém. Prostě disk nepřestane "něco" číst, přesto využití procesoru i pamětí je naprosto na nulových hodnotách. Otevírání= spouštění Skype laguje naprosto celé PC= důvod neznám, neupgradoval jsem verze, max nejaký win update jinak si nejsem nićeho vědom. Bez spuštěného Skype se zdá vše naprosto funkční.. takže naprosto nechápu dovod problému.

projel jsem PC: Malwerbyte (nic), HD Tune (zde se číselně zobrazilo 0% vad)- ale jedna grafická kostka byla red?- (chyba?), Jinak klasika Defraggler, CCleaner, MSE, teploty-> Nikde nic
{{Win 7 prof. 64}}

LOG:
Logfile of random's system information tool 1.09 (written by random/random)
Run by mixe at 2013-11-07 19:48:37
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 560 GB (59%) free of 954 GB
Total RAM: 12286 MB (79% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:48:40, on 7.11.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files (x86)\Seznam.cz\bin\postak.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe
C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe
C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDWebCam.exe
C:\Users\mixe\Documents\LCDHost\bin\LCDHost.exe
C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe
C:\Program Files (x86)\Seznam.cz\bin\MiniBrowser.exe
C:\Program Files (x86)\Seznam.cz\bin\MiniBrowser.exe
C:\Program Files\trend micro\mixe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=;ftp=;https=;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files (x86)\Seznam.cz\bin\postak.exe" -s
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - Startup: LCDHost.lnk = mixe\Documents\LCDHost\bin\LCDHost.exe
O4 - Global Startup: TotalMedia Server.lnk = C:\Program Files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Spustit klienta k monitoru &1 - C:\Windows\web\AOpenClient.htm
O8 - Extra context menu item: Spustit klienta k monitoru &2 - C:\Windows\web\AOpenClient.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwar ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Media Toolbox 6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit (mi-raysat_3dsmax2013_64) - Unknown owner - C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe
O23 - Service: Autodesk Moldflow Inventor Tool Suite Integration 2013 Job Manager (mitsijm2013) - - C:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: OKI OPHD DCS Loader - Oki Data Corporation - C:\Windows\system32\spool\DRIVERS\x64\3\OPHDLDCS.EXE
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13068 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
"C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe"
"C:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe"
C:\Windows\system32\spool\DRIVERS\x64\3\OPHDLDCS.EXE
C:\Windows\SysWOW64\IoctlSvc.exe
"C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2276
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fd76712c-2d59-4eb2-8b20-14bfe4b462d1 -SystemEventPortName:HostProcess-b6928eb2-b212-4d19-b01f-5d10111b0673 -IoCancelEventPortName:HostProcess-2e621af4-0210-4788-b438-b77faf44dae2 -NonStateChangingEventPortName:HostProcess-8baf5655-e287-4638-8564-4e6a2928ef7a -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5f66b16d-d0cf-469d-b323-06a1d81d6d14 -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-75e201ce-37f3-4526-8286-5936712f8ccd -SystemEventPortName:HostProcess-2e273579-54bf-476a-88b2-0d5149fff3a4 -IoCancelEventPortName:HostProcess-cd100016-c082-4905-b2f6-e9345334a281 -NonStateChangingEventPortName:HostProcess-2489133b-468b-462f-abf8-246f9a8b1a84 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:f3d4b8aa-0c95-4b50-9842-da107b5a9cb6 -DeviceGroupId:
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
"C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
KHALMNPR.EXE /API
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\viaaud.exe"
"C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Windows\System32\rundll32.exe" sbavmon.dll,SBAVMonitor
"C:\Program Files (x86)\Seznam.cz\bin\postak.exe" -s
"C:\Program Files\Logitech\SetPointG\SetPointII.exe"
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDMovieViewer.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDYT.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDPictureViewer.exe"
"C:\Program Files\Logitech\GamePanel Software\Applets\ColorOnly\LCDWebCam.exe"
"C:\Users\mixe\Documents\LCDHost\bin\LCDHost.exe" --hidden
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe"
HydraDM64.exe -h:66282 "Maximalizovat na celou plochu" "Maximalizovat k rohům okna" "Obnovit pracovní plochu"
"C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe"
"C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" /r
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"taskhost.exe"
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=6068.127fae00.509020980 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 6068 "\\.\pipe\gecko-crash-server-pipe.6068" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe" --proxy-stub-channel=Flash5468.645ECA40.1816 --host-broker-channel=Flash5468.645ECA40.23293 --host-pid=5468 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe" --channel=5660.0040F890.2078615747 --proxy-stub-channel=Flash5468.645ECA40.1816 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll" --host-npapi-version=27 --type=renderer
"C:\Program Files (x86)\Seznam.cz\bin\MiniBrowser.exe" "szn-login:aHR0cHM6Ly9lbWFpbC5zZXpuYW0uY3ovZ2F0ZT9zZXNzaW9uSWQ9MSU3Y1dsY0FBVUFCV3hSWFRBbGJYd01MREY5WFYxOVBWVlZaSVY5TU5IZE1BMFFxVGpwMDF5RnBWMlR3ME9za0JTSGtjenMxREQlM2QlM2Q=" -t "marijhorn_II@seznam" -f "current" -p "Default"
"C:\Program Files (x86)\Seznam.cz\bin\MiniBrowser.exe" -S
taskmgr.exe /3
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\mixe\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\mixe\AppData\Roaming\Mozilla\Firefox\Profiles\p7otcsw2.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "about:home"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.my-tools-app.com/?babsrc= ... id=9853&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.117 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.7.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Windows\system32\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll


C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
mall-cz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-09 537576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-09 193512]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-08 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-08 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"=C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe [2010-08-03 415816]
"Launch LCDMon"=C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [2010-08-03 2412616]
"Launch LGDCore"=C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [2010-08-03 4725320]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-06-26 1609296]
"VIAAUD"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe [2010-08-11 700528]
"Seagate Scheduler2 Service"=C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe [2009-11-02 136544]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2013-08-12 1356240]
"Autodesk Sync"=C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [2012-02-05 415680]
"Creative SB Monitoring Utility"=RunDll32 sbavmon.dll,SBAVMonitor []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"Seznam Postak"=C:\Program Files (x86)\Seznam.cz\bin\postak.exe [2012-01-10 491040]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2011-10-03 393216]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-10-21 20549280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe -automount []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-10-21 20549280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\games\Steam\steam.exe [2013-10-09 1813928]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SolidWorks Nástroj pro stahování na pozadí.lnk]
C:\PROGRA~2\COMMON~1\MANAER~1\BACKGR~1\SLDBGD~1.EXE [2010-10-07 1826600]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-08-11 2472048]
"DiscWizardMonitor.exe"=C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe [2009-11-02 1346000]
"AcronisTimounterMonitor"=C:\Program Files (x86)\Seagate\DiscWizard\TimounterMonitor.exe [2009-11-02 906288]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"VolPanel"=C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe [2009-07-07 241789]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2013-05-01 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-08-16 152392]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [2013-10-08 766208]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TotalMedia Server.lnk - C:\Program Files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe

C:\Users\mixe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
LCDHost.lnk - C:\Users\mixe\Documents\LCDHost\bin\LCDHost.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2013-11-07 19:48:37 ----D---- C:\rsit
2013-11-07 18:59:00 ----D---- C:\Users\mixe\AppData\Roaming\Skype
2013-11-07 18:58:53 ----RD---- C:\Program Files (x86)\Skype
2013-11-07 18:58:46 ----D---- C:\ProgramData\Skype
2013-11-06 23:00:10 ----D---- C:\Program Files (x86)\HD Tune
2013-11-05 20:15:16 ----A---- C:\Windows\ntbtlog.txt
2013-10-30 19:59:37 ----D---- C:\ProgramData\ATI
2013-10-30 19:59:06 ----D---- C:\Program Files (x86)\AMD AVT
2013-10-29 19:21:44 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-10-27 08:18:45 ----D---- C:\ProgramData\Oracle
2013-10-27 08:17:42 ----A---- C:\Windows\SYSWOW64\javaws.exe
2013-10-27 08:17:34 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2013-10-27 08:17:34 ----A---- C:\Windows\SYSWOW64\javaw.exe
2013-10-27 08:17:34 ----A---- C:\Windows\SYSWOW64\java.exe
2013-10-26 13:01:32 ----D---- C:\Users\mixe\AppData\Roaming\SpaceEngineers
2013-10-26 12:52:26 ----D---- C:\ProgramData\Package Cache
2013-10-12 02:13:49 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-10-12 02:13:48 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-10-12 02:13:48 ----A---- C:\Windows\system32\ieui.dll
2013-10-12 02:13:47 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-10-12 02:13:47 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-10-12 02:13:47 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-10-12 02:13:47 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-10-12 02:13:47 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-12 02:13:47 ----A---- C:\Windows\system32\iesysprep.dll
2013-10-12 02:13:47 ----A---- C:\Windows\system32\iesetup.dll
2013-10-12 02:13:47 ----A---- C:\Windows\system32\iernonce.dll
2013-10-12 02:13:47 ----A---- C:\Windows\system32\ie4uinit.exe
2013-10-12 02:13:46 ----A---- C:\Windows\system32\iertutil.dll
2013-10-12 02:13:45 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-10-12 02:13:45 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-10-12 02:13:45 ----A---- C:\Windows\system32\msfeeds.dll
2013-10-12 02:13:45 ----A---- C:\Windows\system32\jscript.dll
2013-10-12 02:13:44 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-10-12 02:13:44 ----A---- C:\Windows\system32\jscript9.dll
2013-10-12 02:13:43 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-10-12 02:13:43 ----A---- C:\Windows\system32\urlmon.dll
2013-10-12 02:13:42 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-10-12 02:13:42 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-10-12 02:13:42 ----A---- C:\Windows\system32\jsproxy.dll
2013-10-12 02:13:41 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-10-12 02:13:41 ----A---- C:\Windows\system32\wininet.dll
2013-10-12 02:13:40 ----A---- C:\Windows\system32\ieframe.dll
2013-10-12 02:13:39 ----A---- C:\Windows\system32\mshtml.dll
2013-10-12 02:13:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-10-11 20:13:21 ----A---- C:\Windows\system32\comctl32.dll
2013-10-11 20:13:20 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2013-10-11 20:13:18 ----A---- C:\Windows\SYSWOW64\lpk.dll
2013-10-11 20:13:18 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2013-10-11 20:13:18 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2013-10-11 20:13:18 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2013-10-11 20:13:18 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2013-10-11 20:13:18 ----A---- C:\Windows\system32\lpk.dll
2013-10-11 20:13:18 ----A---- C:\Windows\system32\fontsub.dll
2013-10-11 20:13:18 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2013-10-11 20:13:18 ----A---- C:\Windows\system32\dciman32.dll
2013-10-11 20:13:18 ----A---- C:\Windows\system32\atmlib.dll
2013-10-11 20:13:18 ----A---- C:\Windows\system32\atmfd.dll
2013-10-11 20:13:17 ----A---- C:\Windows\system32\drivers\usbcir.sys
2013-10-11 20:13:17 ----A---- C:\Windows\system32\drivers\USBAUDIO.sys
2013-10-11 20:13:16 ----A---- C:\Windows\system32\drivers\usbscan.sys
2013-10-11 20:13:16 ----A---- C:\Windows\system32\drivers\hidparse.sys
2013-10-11 20:13:16 ----A---- C:\Windows\system32\drivers\hidclass.sys
2013-10-11 20:13:15 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2013-10-11 20:13:15 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2013-10-11 20:13:15 ----A---- C:\Windows\system32\WebClnt.dll
2013-10-11 20:13:15 ----A---- C:\Windows\system32\davclnt.dll
2013-10-11 20:13:14 ----A---- C:\Windows\system32\mswsock.dll
2013-10-11 20:13:14 ----A---- C:\Windows\system32\drivers\tcpip.sys
2013-10-11 20:13:14 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2013-10-11 20:13:13 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2013-10-11 20:13:13 ----A---- C:\Windows\system32\drivers\afd.sys
2013-10-11 20:13:11 ----A---- C:\Windows\system32\win32k.sys
2013-10-11 20:13:06 ----A---- C:\Windows\system32\ntoskrnl.exe
2013-10-11 20:13:05 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2013-10-11 20:13:05 ----A---- C:\Windows\system32\advapi32.dll
2013-10-11 20:13:04 ----A---- C:\Windows\SYSWOW64\tdh.dll
2013-10-11 20:13:04 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2013-10-11 20:13:04 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2013-10-11 20:13:04 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2013-10-11 20:13:04 ----A---- C:\Windows\system32\tdh.dll
2013-10-11 20:13:04 ----A---- C:\Windows\system32\ntdll.dll
2013-10-11 20:13:03 ----A---- C:\Windows\SYSWOW64\wow32.dll
2013-10-11 20:13:03 ----A---- C:\Windows\SYSWOW64\user.exe
2013-10-11 20:13:03 ----A---- C:\Windows\SYSWOW64\setup16.exe
2013-10-11 20:13:03 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2013-10-11 20:13:03 ----A---- C:\Windows\SYSWOW64\instnm.exe
2013-10-11 20:13:03 ----A---- C:\Windows\system32\wow64.dll
2013-10-11 20:12:59 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 20:12:59 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 20:12:50 ----A---- C:\Windows\system32\scavengeui.dll
2013-10-11 20:12:49 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2013-10-08 20:49:06 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2013-10-08 15:01:14 ----A---- C:\Windows\system32\atimpc64.dll
2013-10-08 15:01:14 ----A---- C:\Windows\system32\amdpcom64.dll
2013-10-08 15:01:12 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2013-10-08 15:01:12 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2013-10-08 15:01:04 ----A---- C:\Windows\system32\atiu9p64.dll
2013-10-08 14:58:42 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2013-10-08 14:39:22 ----A---- C:\Windows\system32\clinfo.exe
2013-10-08 14:39:10 ----A---- C:\Windows\system32\amdocl_ld64.exe
2013-10-08 14:39:10 ----A---- C:\Windows\system32\amdocl_as64.exe
2013-10-08 14:39:08 ----A---- C:\Windows\SYSWOW64\amdocl_ld32.exe
2013-10-08 14:39:08 ----A---- C:\Windows\SYSWOW64\amdocl_as32.exe
2013-10-08 14:39:06 ----A---- C:\Windows\system32\OpenVideo64.dll
2013-10-08 14:38:58 ----A---- C:\Windows\SYSWOW64\OpenVideo.dll
2013-10-08 14:38:58 ----A---- C:\Windows\system32\coinst_13.152.1.8.dll
2013-10-08 14:38:52 ----A---- C:\Windows\system32\OVDecode64.dll
2013-10-08 14:38:48 ----A---- C:\Windows\SYSWOW64\OVDecode.dll
2013-10-08 14:38:30 ----A---- C:\Windows\system32\amdocl64.dll
2013-10-08 14:36:22 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2013-10-08 14:34:34 ----A---- C:\Windows\system32\OpenCL.dll
2013-10-08 14:34:28 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2013-10-08 14:17:50 ----A---- C:\Windows\system32\atio6axx.dll
2013-10-08 14:13:44 ----A---- C:\Windows\system32\atiapfxx.exe
2013-10-08 14:13:34 ----A---- C:\Windows\system32\aticalrt64.dll
2013-10-08 14:13:32 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2013-10-08 14:13:26 ----A---- C:\Windows\system32\aticalcl64.dll
2013-10-08 14:13:24 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2013-10-08 14:13:08 ----A---- C:\Windows\system32\aticaldd64.dll
2013-10-08 14:09:52 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2013-10-08 14:00:30 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2013-10-08 13:54:10 ----A---- C:\Windows\system32\atidemgy.dll
2013-10-08 13:53:58 ----A---- C:\Windows\system32\atimuixx.dll
2013-10-08 13:53:50 ----A---- C:\Windows\system32\atieclxx.exe
2013-10-08 13:52:58 ----A---- C:\Windows\system32\atiesrxx.exe
2013-10-08 13:51:30 ----A---- C:\Windows\system32\atitmm64.dll
2013-10-08 13:28:26 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2013-10-08 13:28:12 ----A---- C:\Windows\system32\atig6pxx.dll
2013-10-08 13:28:08 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2013-10-08 13:28:08 ----A---- C:\Windows\system32\atiglpxx.dll
2013-10-08 13:28:04 ----A---- C:\Windows\system32\atig6txx.dll
2013-10-08 13:27:56 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2013-10-08 13:27:46 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2013-10-08 13:24:54 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2013-10-08 09:50:12 ----A---- C:\Windows\system32\kdbsdk64.dll
2013-10-08 09:45:08 ----A---- C:\Windows\SYSWOW64\kdbsdk32.dll

======List of files/folders modified in the last 1 month======

2013-11-07 19:48:40 ----D---- C:\Windows\Prefetch
2013-11-07 19:48:39 ----D---- C:\Windows\Temp
2013-11-07 19:48:38 ----D---- C:\Program Files\trend micro
2013-11-07 19:07:59 ----D---- C:\Windows\system32\config
2013-11-07 18:58:58 ----SHD---- C:\Windows\Installer
2013-11-07 18:58:54 ----D---- C:\Program Files (x86)\Common Files
2013-11-07 18:58:53 ----RD---- C:\Program Files (x86)
2013-11-07 18:58:46 ----HD---- C:\ProgramData
2013-11-06 22:54:54 ----SHD---- C:\System Volume Information
2013-11-06 06:20:37 ----D---- C:\Windows
2013-11-06 06:20:36 ----D---- C:\Windows\inf
2013-11-05 22:57:15 ----D---- C:\Program Files\Defraggler
2013-11-05 21:45:24 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2013-11-05 21:42:50 ----D---- C:\games
2013-11-05 20:23:14 ----D---- C:\Users\mixe\AppData\Roaming\uTorrent
2013-11-05 20:12:52 ----D---- C:\Users\mixe\AppData\Roaming\DAEMON Tools Lite
2013-11-05 20:12:46 ----D---- C:\Windows\Panther
2013-11-05 20:12:46 ----D---- C:\Windows\Logs
2013-11-05 20:12:46 ----D---- C:\Windows\debug
2013-11-04 21:00:53 ----D---- C:\Windows\System32
2013-11-04 21:00:53 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-11-01 20:15:55 ----D---- C:\Windows\Microsoft.NET
2013-10-31 23:30:25 ----D---- C:\Windows\SysWOW64
2013-10-31 23:30:25 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2013-10-30 20:21:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-30 20:20:54 ----D---- C:\Windows\system32\catroot
2013-10-30 19:59:07 ----D---- C:\ProgramData\AMD
2013-10-30 19:58:28 ----D---- C:\Program Files\ATI Technologies
2013-10-30 19:55:30 ----D---- C:\Windows\system32\drivers
2013-10-30 19:55:29 ----D---- C:\Windows\system32\DriverStore
2013-10-30 19:55:25 ----D---- C:\Windows\system32\catroot2
2013-10-30 19:49:18 ----D---- C:\Windows\SYSWOW64\en-US
2013-10-30 19:49:17 ----D---- C:\Windows\system32\en-US
2013-10-27 08:17:34 ----D---- C:\Program Files (x86)\Java
2013-10-26 13:01:27 ----RSD---- C:\Windows\assembly
2013-10-26 13:01:04 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-10-26 13:01:04 ----D---- C:\Windows\system32\cs-CZ
2013-10-21 05:15:48 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-10-15 23:56:34 ----D---- C:\Program Files\Microsoft Security Client
2013-10-15 23:56:33 ----D---- C:\Program Files (x86)\Microsoft Security Client
2013-10-12 03:10:30 ----D---- C:\Windows\rescache
2013-10-12 02:34:09 ----D---- C:\Windows\winsxs
2013-10-12 02:32:51 ----D---- C:\Program Files\Microsoft Silverlight
2013-10-12 02:32:50 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2013-10-12 02:31:05 ----D---- C:\Program Files\Internet Explorer
2013-10-12 02:31:05 ----D---- C:\Program Files (x86)\Internet Explorer
2013-10-12 02:31:04 ----D---- C:\Windows\AppPatch
2013-10-12 02:15:11 ----D---- C:\ProgramData\Microsoft Help
2013-10-12 02:05:27 ----D---- C:\Windows\system32\MRT
2013-10-12 02:05:26 ----A---- C:\Windows\system32\MRT.exe
2013-10-08 15:01:06 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2013-10-08 15:01:06 ----A---- C:\Windows\system32\atiuxp64.dll
2013-10-08 15:01:04 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2013-10-08 15:01:02 ----A---- C:\Windows\system32\aticfx64.dll
2013-10-08 15:01:00 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2013-10-08 15:00:56 ----A---- C:\Windows\system32\atidxx64.dll
2013-10-08 15:00:52 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2013-10-08 15:00:46 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2013-10-08 15:00:42 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2013-10-08 15:00:36 ----A---- C:\Windows\system32\atiumd6a.dll
2013-10-08 15:00:32 ----A---- C:\Windows\system32\atiumd64.dll
2013-10-08 13:28:36 ----A---- C:\Windows\system32\atiadlxx.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-06-18 247216]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2010-12-09 235040]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2012-06-16 560184]
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\Windows\system32\DRIVERS\tdrpman.sys [2010-12-09 593952]
R0 timounter;Seagate DiscWizard Image Backup Archive Explorer; C:\Windows\system32\DRIVERS\timntr.sys [2010-12-09 711712]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 ArcSec;archlp; C:\Windows\system32\drivers\ArcSec.sys [2010-09-21 312184]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys [2008-06-27 88632]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-06-18 139616]
R2 tifsfilter;Seagate DiscWizard FS Filter; C:\Windows\system32\DRIVERS\tifsfilt.sys [2010-12-09 81952]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2013-10-08 12534784]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2013-10-08 619008]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-07-05 96256]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 ksaud;Creative USB Audio Driver; C:\Windows\system32\drivers\ksaud.sys [2010-07-14 1558656]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2009-11-23 22408]
R3 LGPBTDD;LGPBTDD.sys Display Driver; C:\Windows\System32\Drivers\LGPBTDD.sys [2009-07-01 30728]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2009-11-23 16008]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2010-03-18 63568]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2010-03-18 57936]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2009-07-16 15416]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-03-21 452200]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-08-04 1342064]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-01-28 116736]
S3 atqk0lo3;atqk0lo3; C:\Windows\system32\drivers\atqk0lo3.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2013-10-08 239616]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-12-21 57008]
R2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2009-12-28 286720]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 mi-raysat_3dsmax2013_64;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit; C:\Program Files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe [2011-09-15 86016]
R2 mitsijm2013;Autodesk Moldflow Inventor Tool Suite Integration 2013 Job Manager; C:\Program Files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe [2012-01-31 339776]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-08-12 23808]
R2 OKI OPHD DCS Loader;OKI OPHD DCS Loader; C:\Windows\system32\spool\DRIVERS\x64\3\OPHDLDCS.EXE [2006-11-30 19968]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [2006-12-19 81920]
R2 SgtSch2Svc;Seagate Scheduler2 Service; C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [2009-11-02 606048]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-08-16 641352]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2013-08-12 366600]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-07-09 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-07-08 123856]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-21 257416]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2012-07-08 51648]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2012-07-19 79360]
S3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [2012-07-19 79360]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-05-09 1432400]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-12-17 1044816]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2010-05-06 357456]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-10-29 119408]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2010-12-17 79360]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2013-10-09 565672]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-09-02 1255736]
S4 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2012-07-09 139696]
S4 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]

-----------------EOF-----------------

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 08 lis 2013 20:17
od Rudy
Zdravím!
Zkoušel jste Skype přeinstalovat?

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 08 lis 2013 20:56
od mari
Zdravim,

a rovnou se omlouvam, ze jsem to jiz puvodne nenapsal. Asi 3x s odinstalovanim vsech souvisejicich souboru co jsem byl schopen nalezt= naprosto bez změn. Nic jiného se takto neprojevuje, naprosto nechápu jak je to možné. Kdyby to mimochodem bylo diskem, tak po odinstalovaní a nahraní jiných vecí mezi tím by pravděpodobně prostor na disku přehrálo...

celý problém je pro mě jedna velká záhada. :?:

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 08 lis 2013 21:27
od Rudy
Pro mne též. Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 08 lis 2013 22:59
od mari
ComboFix 13-11-07.01 - mixe 08.11.2013 22:33:45.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.12286.9888 [GMT 1:00]
Spuštěný z: c:\users\mixe\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\mixe\Documents\LCDHost\bin\LCDHost.exe
c:\windows\iun6002.exe
c:\windows\SysWow64\tmp81ED.tmp
c:\windows\SysWow64\tmp81FD.tmp
c:\windows\SysWow64\tmp9C20.tmp
c:\windows\SysWow64\tmp9C21.tmp
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-08 do 2013-11-08 )))))))))))))))))))))))))))))))
.
.
2013-11-08 21:39 . 2013-11-08 21:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-08 17:48 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04C58BCC-91BC-457D-89EA-8ABB349F82CF}\mpengine.dll
2013-11-07 18:48 . 2013-11-07 18:48 -------- d-----w- C:\rsit
2013-11-07 17:59 . 2013-11-08 17:37 -------- d-----w- c:\users\mixe\AppData\Roaming\Skype
2013-11-07 17:58 . 2013-11-07 17:58 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-11-07 17:58 . 2013-11-07 17:58 -------- d-----r- c:\program files (x86)\Skype
2013-11-07 17:58 . 2013-11-07 17:58 -------- d-----w- c:\programdata\Skype
2013-11-06 22:00 . 2013-11-06 22:00 -------- d-----w- c:\program files (x86)\HD Tune
2013-11-06 21:24 . 2013-10-18 21:06 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8FC59328-53C6-442E-A9E8-F7FC4BA52574}\gapaengine.dll
2013-11-06 21:23 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-10-30 18:59 . 2013-10-30 18:59 -------- d-----w- c:\programdata\ATI
2013-10-30 18:59 . 2013-10-30 18:59 -------- d-----w- c:\program files (x86)\AMD AVT
2013-10-27 07:18 . 2013-10-27 07:18 -------- d-----w- c:\programdata\Oracle
2013-10-27 07:17 . 2013-10-27 07:17 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-10-27 07:17 . 2013-10-08 06:50 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-26 12:01 . 2013-10-26 12:04 -------- d-----w- c:\users\mixe\AppData\Roaming\SpaceEngineers
2013-10-26 11:52 . 2013-10-30 18:53 -------- d-----w- c:\programdata\Package Cache
2013-10-20 20:19 . 2013-10-20 20:19 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2013-10-11 19:13 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll
2013-10-11 19:12 . 2013-07-20 10:33 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 19:12 . 2013-07-20 10:33 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 19:12 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-11 19:12 . 2013-08-01 12:09 983488 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-21 04:15 . 2012-04-04 06:12 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-21 04:15 . 2011-05-20 04:41 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-18 21:06 . 2011-03-26 08:12 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-12 01:05 . 2010-09-02 07:05 80541720 ----a-w- c:\windows\system32\MRT.exe
2013-10-09 20:49 . 2013-10-08 19:49 17750408 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-10-08 14:01 . 2013-10-08 14:01 78432 ----a-w- c:\windows\system32\atimpc64.dll
2013-10-08 14:01 . 2013-10-08 14:01 78432 ----a-w- c:\windows\system32\amdpcom64.dll
2013-10-08 14:01 . 2013-10-08 14:01 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll
2013-10-08 14:01 . 2013-10-08 14:01 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2013-10-08 14:01 . 2012-09-28 01:11 125824 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2013-10-08 14:01 . 2011-10-03 15:22 142792 ----a-w- c:\windows\system32\atiuxp64.dll
2013-10-08 14:01 . 2013-10-08 14:01 114488 ----a-w- c:\windows\system32\atiu9p64.dll
2013-10-08 14:01 . 2012-09-28 01:10 97984 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2013-10-08 14:01 . 2010-03-03 04:15 1237200 ----a-w- c:\windows\system32\aticfx64.dll
2013-10-08 14:01 . 2012-09-28 01:43 1030128 ----a-w- c:\windows\SysWow64\aticfx32.dll
2013-10-08 14:00 . 2010-03-03 03:57 9464840 ----a-w- c:\windows\system32\atidxx64.dll
2013-10-08 14:00 . 2012-09-28 01:39 8215992 ----a-w- c:\windows\SysWow64\atidxx32.dll
2013-10-08 14:00 . 2012-09-28 01:22 6176008 ----a-w- c:\windows\SysWow64\atiumdva.dll
2013-10-08 14:00 . 2012-09-28 02:23 6189416 ----a-w- c:\windows\SysWow64\atiumdag.dll
2013-10-08 14:00 . 2012-04-06 01:34 6767240 ----a-w- c:\windows\system32\atiumd6a.dll
2013-10-08 14:00 . 2012-04-06 01:23 7256496 ----a-w- c:\windows\system32\atiumd64.dll
2013-10-08 13:58 . 2013-10-08 13:58 12534784 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2013-10-08 13:39 . 2013-10-08 13:39 229376 ----a-w- c:\windows\system32\clinfo.exe
2013-10-08 13:39 . 2013-10-08 13:39 1187342 ----a-w- c:\windows\system32\amdocl_as64.exe
2013-10-08 13:39 . 2013-10-08 13:39 1061902 ----a-w- c:\windows\system32\amdocl_ld64.exe
2013-10-08 13:39 . 2013-10-08 13:39 995342 ----a-w- c:\windows\SysWow64\amdocl_as32.exe
2013-10-08 13:39 . 2013-10-08 13:39 798734 ----a-w- c:\windows\SysWow64\amdocl_ld32.exe
2013-10-08 13:39 . 2013-10-08 13:39 98816 ----a-w- c:\windows\system32\OpenVideo64.dll
2013-10-08 13:38 . 2013-10-08 13:38 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2013-10-08 13:38 . 2013-10-08 13:38 127488 ----a-w- c:\windows\system32\coinst_13.152.1.8.dll
2013-10-08 13:38 . 2013-10-08 13:38 86528 ----a-w- c:\windows\system32\OVDecode64.dll
2013-10-08 13:38 . 2013-10-08 13:38 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll
2013-10-08 13:38 . 2013-10-08 13:38 28192256 ----a-w- c:\windows\system32\amdocl64.dll
2013-10-08 13:36 . 2013-10-08 13:36 23761408 ----a-w- c:\windows\SysWow64\amdocl.dll
2013-10-08 13:34 . 2013-10-08 13:34 63488 ----a-w- c:\windows\system32\OpenCL.dll
2013-10-08 13:34 . 2013-10-08 13:34 57344 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-10-08 13:17 . 2013-10-08 13:17 25385984 ----a-w- c:\windows\system32\atio6axx.dll
2013-10-08 13:13 . 2013-10-08 13:13 368640 ----a-w- c:\windows\system32\atiapfxx.exe
2013-10-08 13:13 . 2013-10-08 13:13 62464 ----a-w- c:\windows\system32\aticalrt64.dll
2013-10-08 13:13 . 2013-10-08 13:13 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll
2013-10-08 13:13 . 2013-10-08 13:13 55808 ----a-w- c:\windows\system32\aticalcl64.dll
2013-10-08 13:13 . 2013-10-08 13:13 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll
2013-10-08 13:13 . 2013-10-08 13:13 15716352 ----a-w- c:\windows\system32\aticaldd64.dll
2013-10-08 13:09 . 2013-10-08 13:09 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll
2013-10-08 13:00 . 2013-10-08 13:00 21400064 ----a-w- c:\windows\SysWow64\atioglxx.dll
2013-10-08 12:54 . 2013-10-08 12:54 442368 ----a-w- c:\windows\system32\atidemgy.dll
2013-10-08 12:53 . 2013-10-08 12:53 26112 ----a-w- c:\windows\system32\atimuixx.dll
2013-10-08 12:53 . 2013-10-08 12:53 576512 ----a-w- c:\windows\system32\atieclxx.exe
2013-10-08 12:52 . 2013-10-08 12:52 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2013-10-08 12:51 . 2013-10-08 12:51 190976 ----a-w- c:\windows\system32\atitmm64.dll
2013-10-08 12:28 . 2011-10-03 15:23 784384 ----a-w- c:\windows\system32\atiadlxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 594944 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2013-10-08 12:28 . 2013-10-08 12:28 75264 ----a-w- c:\windows\system32\atig6pxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 69632 ----a-w- c:\windows\system32\atiglpxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 100352 ----a-w- c:\windows\system32\atig6txx.dll
2013-10-08 12:27 . 2013-10-08 12:27 96768 ----a-w- c:\windows\SysWow64\atigktxx.dll
2013-10-08 12:27 . 2013-10-08 12:27 619008 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2013-10-08 12:24 . 2013-10-08 12:24 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2013-10-08 08:50 . 2013-10-08 08:50 51200 ----a-w- c:\windows\system32\kdbsdk64.dll
2013-10-08 08:45 . 2013-10-08 08:45 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
2013-08-29 01:48 . 2013-10-11 19:13 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\program files (x86)\Seznam.cz\bin\postak.exe" [2012-01-10 491040]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-21 20549280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-08-11 2472048]
"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-11-02 1346000]
"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2009-11-02 906288]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"VolPanel"="c:\program files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" [2009-07-07 241789]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-08-16 152392]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-10-08 766208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TotalMedia Server.lnk - c:\program files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe [2011-3-19 519744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 mi-raysat_3dsmax2013_64;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit;c:\program files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe;c:\program files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ArcSec;archlp;c:\windows\system32\drivers\ArcSec.sys;c:\windows\SYSNATIVE\drivers\ArcSec.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 mitsijm2013;Autodesk Moldflow Inventor Tool Suite Integration 2013 Job Manager;c:\program files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe;c:\program files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe [x]
S2 OKI OPHD DCS Loader;OKI OPHD DCS Loader;c:\windows\system32\spool\DRIVERS\x64\3\OPHDLDCS.EXE;c:\windows\SYSNATIVE\spool\DRIVERS\x64\3\OPHDLDCS.EXE [x]
S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys;c:\windows\SYSNATIVE\drivers\ksaud.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys;c:\windows\SYSNATIVE\Drivers\LGPBTDD.sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 04:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1609296]
"VIAAUD"="c:\program files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe" [2010-08-11 700528]
"Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2009-11-02 136544]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-08-12 1356240]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Creative SB Monitoring Utility"="sbavmon.dll" [2010-01-12 109056]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Spustit klienta k monitoru &1 - c:\windows\web\AOpenClient.htm
IE: Spustit klienta k monitoru &2 - c:\windows\web\AOpenClient.htm
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\sign
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojeplatba.cz\www
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 192.168.1.1
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\mixe\AppData\Roaming\Mozilla\Firefox\Profiles\p7otcsw2.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9853&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
c:\users\mixe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LCDHost.lnk - c:\users\mixe\Documents\LCDHost\bin\LCDHost.exe --hidden
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Read Count\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Read Count\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Write Count\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Write Count\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Idle Time\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Idle Time\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Read Time\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Read Time\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Write Time\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Write Time\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Read\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Read\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Written\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Written\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Free Space\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Free Space\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Total Space\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Total Space\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Used Space\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Used Space\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Last Update\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Last Update\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Queue Depth\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Queue Depth\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\SecuROM\License information*]
"datasecu"=hex:3f,74,5c,03,2e,4d,89,86,67,02,d1,2d,34,de,70,5f,08,33,e8,65,5f,
69,48,2e,60,dd,ca,38,19,2d,a3,76,47,3e,b7,dd,d9,18,f3,47,d3,ee,4b,3f,ce,68,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2013-11-08 22:42:04
ComboFix-quarantined-files.txt 2013-11-08 21:42
.
Před spuštěním: Volných bajtů: 585 474 842 624
Po spuštění: Volných bajtů: 585 100 255 232
.
- - End Of File - - F4C739B1112EE290AE7E830A93D551D7
A36C5E4F47E84449FF07ED3517B43A31

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 08 lis 2013 23:22
od Rudy
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

Regnull::
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\SecuROM\License information*]

RegLock::
HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu:

Obrázek

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 09 lis 2013 08:53
od mari
Díky, zde je log:


ComboFix 13-11-07.01 - mixe 09.11.2013 8:35.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.12286.9382 [GMT 1:00]
Spuštěný z: c:\users\mixe\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\mixe\Desktop\CFScript.txt.txt
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-10-09 do 2013-11-09 )))))))))))))))))))))))))))))))
.
.
2013-11-09 07:39 . 2013-11-09 07:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-11-08 22:00 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{09807CD0-69F2-4021-B44C-3E030358E7B1}\mpengine.dll
2013-11-07 18:48 . 2013-11-07 18:48 -------- d-----w- C:\rsit
2013-11-07 17:59 . 2013-11-08 17:37 -------- d-----w- c:\users\mixe\AppData\Roaming\Skype
2013-11-07 17:58 . 2013-11-07 17:58 -------- d-----w- c:\program files (x86)\Common Files\Skype
2013-11-07 17:58 . 2013-11-07 17:58 -------- d-----r- c:\program files (x86)\Skype
2013-11-07 17:58 . 2013-11-07 17:58 -------- d-----w- c:\programdata\Skype
2013-11-06 22:00 . 2013-11-06 22:00 -------- d-----w- c:\program files (x86)\HD Tune
2013-11-06 21:24 . 2013-10-18 21:06 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8FC59328-53C6-442E-A9E8-F7FC4BA52574}\gapaengine.dll
2013-11-06 21:23 . 2013-10-14 07:12 10280728 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-10-30 18:59 . 2013-10-30 18:59 -------- d-----w- c:\programdata\ATI
2013-10-30 18:59 . 2013-10-30 18:59 -------- d-----w- c:\program files (x86)\AMD AVT
2013-10-27 07:18 . 2013-10-27 07:18 -------- d-----w- c:\programdata\Oracle
2013-10-27 07:17 . 2013-10-27 07:17 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-10-27 07:17 . 2013-10-08 06:50 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-26 12:01 . 2013-10-26 12:04 -------- d-----w- c:\users\mixe\AppData\Roaming\SpaceEngineers
2013-10-26 11:52 . 2013-10-30 18:53 -------- d-----w- c:\programdata\Package Cache
2013-10-20 20:19 . 2013-10-20 20:19 163504 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2013-10-11 19:13 . 2013-07-04 12:50 633856 ----a-w- c:\windows\system32\comctl32.dll
2013-10-11 19:12 . 2013-07-20 10:33 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 19:12 . 2013-07-20 10:33 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-11 19:12 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll
2013-10-11 19:12 . 2013-08-01 12:09 983488 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-21 04:15 . 2012-04-04 06:12 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-21 04:15 . 2011-05-20 04:41 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-18 21:06 . 2011-03-26 08:12 965000 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-10-12 01:05 . 2010-09-02 07:05 80541720 ----a-w- c:\windows\system32\MRT.exe
2013-10-09 20:49 . 2013-10-08 19:49 17750408 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-10-08 14:01 . 2013-10-08 14:01 78432 ----a-w- c:\windows\system32\atimpc64.dll
2013-10-08 14:01 . 2013-10-08 14:01 78432 ----a-w- c:\windows\system32\amdpcom64.dll
2013-10-08 14:01 . 2013-10-08 14:01 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll
2013-10-08 14:01 . 2013-10-08 14:01 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll
2013-10-08 14:01 . 2012-09-28 01:11 125824 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2013-10-08 14:01 . 2011-10-03 15:22 142792 ----a-w- c:\windows\system32\atiuxp64.dll
2013-10-08 14:01 . 2013-10-08 14:01 114488 ----a-w- c:\windows\system32\atiu9p64.dll
2013-10-08 14:01 . 2012-09-28 01:10 97984 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2013-10-08 14:01 . 2010-03-03 04:15 1237200 ----a-w- c:\windows\system32\aticfx64.dll
2013-10-08 14:01 . 2012-09-28 01:43 1030128 ----a-w- c:\windows\SysWow64\aticfx32.dll
2013-10-08 14:00 . 2010-03-03 03:57 9464840 ----a-w- c:\windows\system32\atidxx64.dll
2013-10-08 14:00 . 2012-09-28 01:39 8215992 ----a-w- c:\windows\SysWow64\atidxx32.dll
2013-10-08 14:00 . 2012-09-28 01:22 6176008 ----a-w- c:\windows\SysWow64\atiumdva.dll
2013-10-08 14:00 . 2012-09-28 02:23 6189416 ----a-w- c:\windows\SysWow64\atiumdag.dll
2013-10-08 14:00 . 2012-04-06 01:34 6767240 ----a-w- c:\windows\system32\atiumd6a.dll
2013-10-08 14:00 . 2012-04-06 01:23 7256496 ----a-w- c:\windows\system32\atiumd64.dll
2013-10-08 13:58 . 2013-10-08 13:58 12534784 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2013-10-08 13:39 . 2013-10-08 13:39 229376 ----a-w- c:\windows\system32\clinfo.exe
2013-10-08 13:39 . 2013-10-08 13:39 1187342 ----a-w- c:\windows\system32\amdocl_as64.exe
2013-10-08 13:39 . 2013-10-08 13:39 1061902 ----a-w- c:\windows\system32\amdocl_ld64.exe
2013-10-08 13:39 . 2013-10-08 13:39 995342 ----a-w- c:\windows\SysWow64\amdocl_as32.exe
2013-10-08 13:39 . 2013-10-08 13:39 798734 ----a-w- c:\windows\SysWow64\amdocl_ld32.exe
2013-10-08 13:39 . 2013-10-08 13:39 98816 ----a-w- c:\windows\system32\OpenVideo64.dll
2013-10-08 13:38 . 2013-10-08 13:38 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2013-10-08 13:38 . 2013-10-08 13:38 127488 ----a-w- c:\windows\system32\coinst_13.152.1.8.dll
2013-10-08 13:38 . 2013-10-08 13:38 86528 ----a-w- c:\windows\system32\OVDecode64.dll
2013-10-08 13:38 . 2013-10-08 13:38 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll
2013-10-08 13:38 . 2013-10-08 13:38 28192256 ----a-w- c:\windows\system32\amdocl64.dll
2013-10-08 13:36 . 2013-10-08 13:36 23761408 ----a-w- c:\windows\SysWow64\amdocl.dll
2013-10-08 13:34 . 2013-10-08 13:34 63488 ----a-w- c:\windows\system32\OpenCL.dll
2013-10-08 13:34 . 2013-10-08 13:34 57344 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-10-08 13:17 . 2013-10-08 13:17 25385984 ----a-w- c:\windows\system32\atio6axx.dll
2013-10-08 13:13 . 2013-10-08 13:13 368640 ----a-w- c:\windows\system32\atiapfxx.exe
2013-10-08 13:13 . 2013-10-08 13:13 62464 ----a-w- c:\windows\system32\aticalrt64.dll
2013-10-08 13:13 . 2013-10-08 13:13 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll
2013-10-08 13:13 . 2013-10-08 13:13 55808 ----a-w- c:\windows\system32\aticalcl64.dll
2013-10-08 13:13 . 2013-10-08 13:13 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll
2013-10-08 13:13 . 2013-10-08 13:13 15716352 ----a-w- c:\windows\system32\aticaldd64.dll
2013-10-08 13:09 . 2013-10-08 13:09 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll
2013-10-08 13:00 . 2013-10-08 13:00 21400064 ----a-w- c:\windows\SysWow64\atioglxx.dll
2013-10-08 12:54 . 2013-10-08 12:54 442368 ----a-w- c:\windows\system32\atidemgy.dll
2013-10-08 12:53 . 2013-10-08 12:53 26112 ----a-w- c:\windows\system32\atimuixx.dll
2013-10-08 12:53 . 2013-10-08 12:53 576512 ----a-w- c:\windows\system32\atieclxx.exe
2013-10-08 12:52 . 2013-10-08 12:52 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2013-10-08 12:51 . 2013-10-08 12:51 190976 ----a-w- c:\windows\system32\atitmm64.dll
2013-10-08 12:28 . 2011-10-03 15:23 784384 ----a-w- c:\windows\system32\atiadlxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 594944 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2013-10-08 12:28 . 2013-10-08 12:28 75264 ----a-w- c:\windows\system32\atig6pxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 69632 ----a-w- c:\windows\system32\atiglpxx.dll
2013-10-08 12:28 . 2013-10-08 12:28 100352 ----a-w- c:\windows\system32\atig6txx.dll
2013-10-08 12:27 . 2013-10-08 12:27 96768 ----a-w- c:\windows\SysWow64\atigktxx.dll
2013-10-08 12:27 . 2013-10-08 12:27 619008 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2013-10-08 12:24 . 2013-10-08 12:24 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2013-10-08 08:50 . 2013-10-08 08:50 51200 ----a-w- c:\windows\system32\kdbsdk64.dll
2013-10-08 08:45 . 2013-10-08 08:45 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
2013-08-29 01:48 . 2013-10-11 19:13 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="c:\program files (x86)\Seznam.cz\bin\postak.exe" [2012-01-10 491040]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-10-21 20549280]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-08-11 2472048]
"DiscWizardMonitor.exe"="c:\program files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-11-02 1346000]
"AcronisTimounterMonitor"="c:\program files (x86)\Seagate\DiscWizard\TimounterMonitor.exe" [2009-11-02 906288]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"VolPanel"="c:\program files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" [2009-07-07 241789]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-08-16 152392]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-10-08 766208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TotalMedia Server.lnk - c:\program files (x86)\ArcSoft\TotalMedia Theatre 5\TotalMedia Server\TM Server.exe [2011-3-19 519744]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x]
R3 Creative Media Toolbox 6 Licensing Service;Creative Media Toolbox 6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe;c:\program files (x86)\Common Files\Creative Labs Shared\Service\MT6Licensing.exe [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 ArcSec;archlp;c:\windows\system32\drivers\ArcSec.sys;c:\windows\SYSNATIVE\drivers\ArcSec.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
S2 mi-raysat_3dsmax2013_64;mental ray 3.10 Satellite for Autodesk 3ds Max 2013 64-bit;c:\program files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe;c:\program files\Autodesk\3ds Max Design 2013\NVIDIA\raysat_3dsmax2013_64server.exe [x]
S2 mitsijm2013;Autodesk Moldflow Inventor Tool Suite Integration 2013 Job Manager;c:\program files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe;c:\program files\Autodesk\Inventor 2013\Moldflow\bin\mitsijm.exe [x]
S2 OKI OPHD DCS Loader;OKI OPHD DCS Loader;c:\windows\system32\spool\DRIVERS\x64\3\OPHDLDCS.EXE;c:\windows\SYSNATIVE\spool\DRIVERS\x64\3\OPHDLDCS.EXE [x]
S2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe;c:\program files (x86)\Common Files\Seagate\Schedule2\schedul2.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys;c:\windows\SYSNATIVE\drivers\ksaud.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys;c:\windows\SYSNATIVE\Drivers\LGPBTDD.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
2013-11-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 04:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2010-08-03 415816]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2010-08-03 2412616]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2010-08-03 4725320]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1609296]
"VIAAUD"="c:\program files (x86)\VIA\VIAudioi\VDeck\VIAAUD.exe" [2010-08-11 700528]
"Seagate Scheduler2 Service"="c:\program files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe" [2009-11-02 136544]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-08-12 1356240]
"Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2012-02-05 415680]
"Creative SB Monitoring Utility"="sbavmon.dll" [2010-01-12 109056]
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyServer = http=;ftp=;https=;
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Spustit klienta k monitoru &1 - c:\windows\web\AOpenClient.htm
IE: Spustit klienta k monitoru &2 - c:\windows\web\AOpenClient.htm
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\sign
Trusted Zone: mojebanka.cz\www
Trusted Zone: mojeplatba.cz\www
Trusted Zone: mojebanka.cz\etrading
Trusted Zone: mojebanka.cz\www
TCP: DhcpNameServer = 192.168.1.1
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
FF - ProfilePath - c:\users\mixe\AppData\Roaming\Mozilla\Firefox\Profiles\p7otcsw2.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.my-tools-app.com/?babsrc=home&s=web&as=0&isid=9853&q=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-Uplay - c:\program files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Read Count\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Read Count\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Write Count\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Counters\Write Count\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Idle Time\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Idle Time\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Read Time\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Read Time\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Write Time\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Activity Percentages\Write Time\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Read\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Read\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Written\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Bytes Read\Written\Bytes Written\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Free Space\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Free Space\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Total Space\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Total Space\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Used Space\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Disk Space\Used Space\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Last Update\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Last Update\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Queue Depth\*5]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_USERS\S-1-5-21-3432410009-2185330963-190606145-1001\Software\Link Data\LCDHost\plugins\LH_DriveStats\setupitems\SourceFields\Drive Stats\Queue Depth\*5\String]
"type"=dword:00000008
"extrastr"=""
"extraint"=dword:00000000
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\SysWOW64\IoctlSvc.exe
.
**************************************************************************
.
Celkový čas: 2013-11-09 08:51:44 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-11-09 07:51
ComboFix2.txt 2013-11-08 21:42
.
Před spuštěním: Volných bajtů: 585 166 426 112
Po spuštění: Volných bajtů: 585 090 023 424
.
- - End Of File - - 8AF547EEADA2C76A511EFBEE1D823528
A36C5E4F47E84449FF07ED3517B43A31

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 09 lis 2013 11:40
od Rudy
Smazáno, log je již OK. Nastala nějaká změna?

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 09 lis 2013 11:49
od mari
nope, skype pri spusteni stale dela to stjne. Ihned narposto vytizi HDD, jako kdyby zapisoval/cetl plnou rychlosti GB dat...

:/

za procisteni balastu diky.

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 09 lis 2013 11:54
od Rudy
Zkušel jste kompletní přeinstalaci Skype, vč. smazání jeho dočasných souborů?

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 09 lis 2013 13:24
od mari
Zkoušel jsem smazat veškeré dočasné soubory od Skype, které jsem našel. Momentálně nejsem u daného PC a tak nejsem schopen to v rychlosti provést znova/ zkontrolovat jestli jsem to provedl důkladně...

Ještě to zkusím a pak napíši.

Diky

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 09 lis 2013 18:18
od Rudy
OK.

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 10 lis 2013 11:25
od mari
Zdravim,

problem pretrvava a dle vseho to asi delaji aplikace co se spousti na pozadi a komunikuji pres net. Jelikoz naprosto stejny problem vytvari take napriklad steam.

Hned po spousteni naprosto zasekne systemovy disk a jakakoliv dalsi prace je prakticky nemozna az do nejakeho CTRL+ALT+DEL a nez-li se v tomhle zahlcenem "modu" program vypne...

:?:

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 10 lis 2013 12:05
od Rudy
Např. Steam by z mého PC letěl velkým obloukem :) Něco podobného bych nestrpěl, ale já nejsem pařan. Závěr je ten, že tu komunikaci způsobují zcela regulérní aplikace, které přes internet komunikují. Řešením je odinstaloat takové, které již nepotřebujete a systému se jistě uleví. Současné aplikace jsou zkrátka programované na to, aby přes net komunikovaly a když je jich mnoho a připojení není zrovna naddimenzováno, stane se tohle.

Re: Prosim o kontrolu (Skype - lagne HDD)

Napsal: 10 lis 2013 19:22
od mari
Rozumím, také v posledních letech na hry nemám téměř čas a proto jsem na problém se steamem přišel až teď.

Internet mám řekl bych kvalitní: 60/10 Mb/s. PC "slušné": i5 750@2.7GHz, 12GB ram, 5870ATI....

ze by to tedy bylo pc ci internetem se me nechce verit, protoze provozuji 15x narocnejsi napriklad graficke aplikace nez je nejaky komunikator /Skype/. A kdybych bez nich mohl v klidu zit, tak to samozrejme vubec neresim.. Bohuzel jej pouzivam i k praci.
-> problém bude tedy někde jinde, samozřejmě může být i hardwarový. Ale nenapadámě nic co by to mohlo způsobit.