Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosim o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

prosim o kontrolu

#1 Příspěvek od Deleter »

Tak krom klasiky, ze to beha pomaleji, jeste musim pri zapnuti pc vypnout a zapnout monitor, aby bezel. A protoze kabelaz vypada vpohode, tak to zkusim tady. Predem dik.

# AdwCleaner v3.014 - Report created 09/12/2013 at 20:45:12
# Updated 01/12/2013 by Xplode
# Operating System : Windows 7 Ultimate (32 bits)
# Username : Deleter - DELETER-PC
# Running from : C:\Users\Deleter\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : vToolbarUpdater17.1.2

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\BitGuard
Folder Deleted : C:\ProgramData\DSearchLink
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Program Files\AVG Secure Search
Folder Deleted : C:\Program Files\SoftwareUpdater
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\Deleter\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Deleter\AppData\Local\Bundled software uninstaller
Folder Deleted : C:\Users\Deleter\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Deleter\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Deleter\AppData\Roaming\Babylon
Folder Deleted : C:\Users\Deleter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Folder Deleted : C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
File Deleted : C:\Users\Deleter\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
File Deleted : C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage
File Deleted : C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage-journal
File Deleted : C:\Windows\System32\Tasks\BitGuard

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mggiecmcgkpfmegnobeimepgndgdhbjm
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4226D1D4-285D-42E7-9279-CE7C3E69BEDF}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4226D1D4-285D-42E7-9279-CE7C3E69BEDF}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optimizerpro_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\optprostart_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKCU\Software\53e8cd1b03dec10
Key Deleted : HKLM\SOFTWARE\53e8cd1b03dec10
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\DataMngr
[#] Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\SoftwareUpdater
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\Vittalia
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\bitguard\271832~1.68\{c16c1~1\bitguard.dll

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7100.0

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : icon_url
Deleted : search_url
Deleted : keyword
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [8730 octets] - [09/12/2013 20:44:37]
AdwCleaner[S0].txt - [8576 octets] - [09/12/2013 20:45:12]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8636 octets] ##########



Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-12-2013
Ran by Deleter (administrator) on DELETER-PC on 09-12-2013 20:51:22
Running from C:\Users\Deleter\Downloads
Microsoft Windows 7 Ultimate (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgcsrvx.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgwdsvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgui.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2013\avgemcx.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
() C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2013\avgui.exe [4411952 2013-09-23] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKCU\...\Run: [QIP Internet Guardian] - C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe [188416 2010-10-20] ()
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1823656 2013-12-04] (Valve Corporation)
MountPoints2: {bff25a1a-05a0-11e3-9e84-50465d8e211a} - D:\Setup.exe
AppInit_DLLs: [ ] ()
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
SearchScopes: HKLM - DefaultScope value is missing.
BHO: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Deleter\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchKeyword: babylon.com
CHR DefaultSearchProvider: Babylon Search
CHR DefaultSearchURL: http://search.babylon.com/?q={searchTer ... 5&tsp=4975
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Dota 2 Lounge Helper) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmpblpndedodbmceeghpahabeppemed\0.2_0
CHR Extension: (Ghostery) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\5.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

========================== Services (Whitelisted) =================

R2 AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [4939312 2013-07-04] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [283136 2013-07-23] (AVG Technologies CZ, s.r.o.)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [1724192 2013-01-31] (TuneUp Software)
S3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH)

==================== Drivers (Whitelisted) ====================

S3 amdsata; C:\Windows\system32\DRIVERS\amdsata.sys [77904 2009-04-22] (AMD)
R0 amdxata; C:\Windows\System32\DRIVERS\amdxata.sys [23120 2009-04-22] (AMD)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [208184 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [60216 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22328 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [171320 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [246072 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [96568 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [39224 2013-09-05] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [182072 2013-03-21] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-11-11] (AVG Technologies)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-08-15] (Disc Soft Ltd)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [55104 2012-07-17] (Intel Corporation)
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [33056 2011-06-15] (Realtek )
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [40736 2011-06-15] (Realtek Corporation)
S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan620.sys [27752 2011-09-16] (Realtek Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [27136 2009-09-16] (Tunngle.net)
S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [40736 2011-06-15] (Realtek Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [10088 2012-09-18] (TuneUp Software)
R3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN620.sys [27752 2011-09-16] (Realtek Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-09 20:51 - 2013-12-09 20:51 - 00010541 _____ C:\Users\Deleter\Downloads\FRST.txt
2013-12-09 20:51 - 2013-12-09 20:51 - 00000000 ____D C:\FRST
2013-12-09 20:44 - 2013-12-09 20:45 - 00000000 ____D C:\AdwCleaner
2013-12-09 20:42 - 2013-12-09 20:43 - 01110034 _____ C:\Users\Deleter\Downloads\AdwCleaner.exe
2013-12-09 20:40 - 2013-12-09 20:41 - 01060641 _____ (Farbar) C:\Users\Deleter\Downloads\FRST.exe
2013-12-09 20:38 - 2013-12-09 20:38 - 00000000 ____D C:\rsit
2013-12-09 20:38 - 2013-12-09 20:38 - 00000000 ____D C:\Program Files\trend micro
2013-12-09 20:37 - 2013-12-09 20:37 - 00781383 _____ C:\Users\Deleter\Downloads\RSIT.exe
2013-12-09 20:26 - 2013-12-09 20:36 - 00000000 ___SD C:\32788R22FWJFW
2013-12-09 20:26 - 2013-12-09 20:26 - 00000000 ____D C:\Windows\erdnt
2013-12-09 20:23 - 2013-12-09 20:26 - 05153091 ____R (Swearware) C:\Users\Deleter\Desktop\ComboFix.exe
2013-12-08 12:39 - 2013-12-08 12:42 - 373917624 _____ C:\Users\Deleter\Downloads\Greys.Anatomy.S10E11.HDTV.XviD.avi
2013-12-08 12:39 - 2013-12-08 12:39 - 00073055 _____ C:\Users\Deleter\Downloads\Greys-Anatomy-10x11.zip
2013-12-01 12:42 - 2013-12-01 12:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-12-01 12:42 - 2013-12-01 12:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2013-11-25 13:20 - 2013-11-25 13:21 - 214335687 _____ C:\Users\Deleter\Downloads\Greys.Anatomy.S10E10.HDTV.x264-LOL.mp4
2013-11-25 13:17 - 2013-11-25 13:17 - 00104186 _____ C:\Users\Deleter\Downloads\Greys-Anatomy-10x103.zip
2013-11-24 21:53 - 2013-11-24 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-24 21:53 - 2013-11-24 21:54 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-11-24 21:53 - 2013-11-24 21:53 - 00002115 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-24 21:53 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2013-11-24 21:52 - 2013-11-24 21:53 - 46988968 _____ C:\Users\Deleter\Downloads\spybot-2.2.exe
2013-11-15 18:45 - 2013-11-15 19:28 - 233424458 _____ C:\Users\Deleter\Downloads\The-big-bang-theory-s07e08-hdtv-lol-+-cz-titulky.avi
2013-11-15 18:24 - 2013-11-15 18:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-11-14 13:27 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2013-11-14 13:27 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2013-11-14 13:27 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2013-11-14 13:27 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2013-11-14 13:27 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2013-11-14 13:27 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2013-11-14 13:27 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2013-11-14 13:27 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2013-11-14 13:27 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2013-11-14 13:27 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2013-11-14 13:27 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2013-11-14 13:27 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2013-11-14 13:27 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2013-11-14 13:27 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2013-11-14 13:27 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2013-11-14 13:27 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2013-11-14 13:27 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2013-11-14 13:27 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2013-11-14 13:27 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2013-11-14 13:27 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2013-11-14 13:27 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2013-11-14 13:27 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2013-11-14 13:27 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2013-11-14 13:27 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2013-11-14 13:27 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2013-11-14 13:27 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2013-11-14 13:27 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2013-11-14 13:27 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2013-11-14 13:27 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2013-11-14 13:27 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2013-11-14 13:27 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2013-11-14 13:27 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2013-11-14 13:27 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2013-11-14 13:27 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2013-11-14 13:27 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2013-11-14 13:27 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2013-11-14 13:27 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2013-11-14 13:27 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2013-11-14 13:27 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2013-11-14 13:27 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2013-11-14 13:27 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2013-11-14 13:27 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2013-11-14 13:27 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2013-11-14 13:27 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2013-11-14 13:27 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2013-11-14 13:27 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2013-11-14 13:27 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2013-11-14 13:27 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2013-11-14 13:27 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2013-11-14 13:27 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2013-11-14 13:27 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2013-11-14 13:27 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2013-11-14 13:27 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2013-11-14 13:27 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2013-11-14 13:27 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2013-11-14 13:27 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2013-11-14 13:27 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2013-11-14 13:27 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2013-11-14 13:27 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2013-11-14 13:27 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2013-11-14 13:27 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2013-11-14 13:27 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2013-11-14 13:27 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2013-11-14 13:27 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2013-11-14 13:27 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2013-11-14 13:27 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2013-11-14 13:27 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2013-11-14 13:27 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2013-11-14 13:27 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2013-11-14 13:27 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2013-11-14 13:27 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2013-11-14 13:27 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2013-11-14 13:27 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2013-11-14 13:27 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2013-11-14 13:27 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2013-11-14 13:27 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2013-11-14 13:27 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2013-11-14 13:27 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2013-11-14 13:27 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2013-11-14 13:26 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2013-11-14 13:26 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2013-11-14 13:26 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2013-11-14 13:26 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2013-11-14 13:26 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2013-11-14 13:26 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2013-11-14 13:26 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2013-11-14 13:26 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2013-11-14 13:26 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2013-11-14 13:10 - 2013-11-14 13:10 - 00000187 _____ C:\Users\Deleter\Desktop\Dota 2 Test.url

==================== One Month Modified Files and Folders =======

2013-12-09 20:51 - 2013-12-09 20:51 - 00010541 _____ C:\Users\Deleter\Downloads\FRST.txt
2013-12-09 20:51 - 2013-12-09 20:51 - 00000000 ____D C:\FRST
2013-12-09 20:49 - 2013-08-03 00:44 - 01361784 _____ C:\Windows\WindowsUpdate.log
2013-12-09 20:47 - 2013-09-04 01:30 - 00000000 ____D C:\Program Files\Steam
2013-12-09 20:47 - 2013-08-04 13:08 - 00000000 ____D C:\Users\Deleter\AppData\Roaming\Skype
2013-12-09 20:46 - 2013-08-03 01:55 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-09 20:46 - 2009-04-22 09:27 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-09 20:46 - 2009-04-22 09:12 - 00029532 _____ C:\Windows\setupact.log
2013-12-09 20:45 - 2013-12-09 20:44 - 00000000 ____D C:\AdwCleaner
2013-12-09 20:43 - 2013-12-09 20:42 - 01110034 _____ C:\Users\Deleter\Downloads\AdwCleaner.exe
2013-12-09 20:41 - 2013-12-09 20:40 - 01060641 _____ (Farbar) C:\Users\Deleter\Downloads\FRST.exe
2013-12-09 20:38 - 2013-12-09 20:38 - 00000000 ____D C:\rsit
2013-12-09 20:38 - 2013-12-09 20:38 - 00000000 ____D C:\Program Files\trend micro
2013-12-09 20:37 - 2013-12-09 20:37 - 00781383 _____ C:\Users\Deleter\Downloads\RSIT.exe
2013-12-09 20:36 - 2013-12-09 20:26 - 00000000 ___SD C:\32788R22FWJFW
2013-12-09 20:26 - 2013-12-09 20:26 - 00000000 ____D C:\Windows\erdnt
2013-12-09 20:26 - 2013-12-09 20:23 - 05153091 ____R (Swearware) C:\Users\Deleter\Desktop\ComboFix.exe
2013-12-09 20:24 - 2013-10-02 12:58 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-09 20:10 - 2013-08-03 01:55 - 00000942 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-09 17:39 - 2013-08-03 02:44 - 00000000 ____D C:\ProgramData\MFAData
2013-12-09 16:06 - 2013-08-03 00:51 - 00713888 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-08 13:36 - 2013-08-04 05:12 - 00000000 ____D C:\Users\Deleter\AppData\Roaming\vlc
2013-12-08 12:42 - 2013-12-08 12:39 - 373917624 _____ C:\Users\Deleter\Downloads\Greys.Anatomy.S10E11.HDTV.XviD.avi
2013-12-08 12:39 - 2013-12-08 12:39 - 00073055 _____ C:\Users\Deleter\Downloads\Greys-Anatomy-10x11.zip
2013-12-05 17:13 - 2013-08-03 01:56 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-12-05 12:03 - 2013-08-03 02:42 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-12-02 16:34 - 2013-08-03 02:48 - 00000947 _____ C:\Users\Public\Desktop\AVG 2013.lnk
2013-12-02 11:58 - 2013-08-03 02:01 - 00024496 _____ C:\Windows\PFRO.log
2013-12-01 17:42 - 2013-08-03 03:11 - 00000000 ____D C:\Users\Deleter\AppData\Roaming\TS3Client
2013-12-01 12:43 - 2013-11-02 18:50 - 00000000 ____D C:\Users\Deleter\Downloads\Sony Vegas Pro 11
2013-12-01 12:42 - 2013-12-01 12:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2013-12-01 12:42 - 2013-12-01 12:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2013-11-26 16:03 - 2013-08-04 13:08 - 00000000 ___RD C:\Program Files\Skype
2013-11-26 16:03 - 2013-08-04 13:08 - 00000000 ____D C:\ProgramData\Skype
2013-11-25 13:21 - 2013-11-25 13:20 - 214335687 _____ C:\Users\Deleter\Downloads\Greys.Anatomy.S10E10.HDTV.x264-LOL.mp4
2013-11-25 13:17 - 2013-11-25 13:17 - 00104186 _____ C:\Users\Deleter\Downloads\Greys-Anatomy-10x103.zip
2013-11-24 21:55 - 2013-11-24 21:53 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-24 21:54 - 2013-11-24 21:53 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-11-24 21:53 - 2013-11-24 21:53 - 00002115 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-24 21:53 - 2013-11-24 21:52 - 46988968 _____ C:\Users\Deleter\Downloads\spybot-2.2.exe
2013-11-22 16:53 - 2013-11-03 04:01 - 00000213 _____ C:\Users\Deleter\Desktop\Dota 2.url
2013-11-15 19:28 - 2013-11-15 18:45 - 233424458 _____ C:\Users\Deleter\Downloads\The-big-bang-theory-s07e08-hdtv-lol-+-cz-titulky.avi
2013-11-15 18:24 - 2013-11-15 18:24 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2013-11-14 13:10 - 2013-11-14 13:10 - 00000187 _____ C:\Users\Deleter\Desktop\Dota 2 Test.url
2013-11-14 13:10 - 2013-09-04 01:46 - 00000000 ____D C:\Users\Deleter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-11-11 13:55 - 2013-08-03 02:35 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys

Some content of TEMP:
====================
C:\Users\Deleter\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe
[2009-04-22 04:40] - [2009-04-22 06:19] - 2607616 ____A (Microsoft Corporation) C133788B393EEC01439AD997D24E66ED

C:\Windows\System32\winlogon.exe
[2009-04-22 04:35] - [2009-04-22 06:19] - 0285696 ____A (Microsoft Corporation) B9CFF761509E6C95E964B29B279D7721

C:\Windows\System32\wininit.exe
[2009-04-22 04:35] - [2009-04-22 06:19] - 0096256 ____A (Microsoft Corporation) 2E4264C95BAB587431C79C101899CCC8

C:\Windows\System32\svchost.exe
[2009-04-22 04:16] - [2009-04-22 06:19] - 0020992 ____A (Microsoft Corporation) 5F1FE2F551E74B069C436152F06CCFDC

C:\Windows\System32\services.exe
[2009-04-22 04:08] - [2009-04-22 06:19] - 0259072 ____A (Microsoft Corporation) 77474E495E99CCE05AD2720E6FA85A35

C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe
[2009-04-22 04:32] - [2009-04-22 06:19] - 0026112 ____A (Microsoft Corporation) 50771CA86FF1ADAF5FD1920F8CB5665E

C:\Windows\System32\Drivers\volsnap.sys
[2009-04-22 04:08] - [2009-04-22 06:23] - 0244304 ____A (Microsoft Corporation) 803F111D3DBA35D34DE1F0AC12517DE8



LastRegBack: 2013-08-03 00:39

==================== End Of Log ============================[/code]

Kód: Vybrat vše

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-12-2013
Ran by Deleter at 2013-12-09 20:51:47
Running from C:\Users\Deleter\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: AVG AntiVirus Free Edition 2013 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: AVG AntiVirus Free Edition 2013 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 (Disabled) {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}

==================== Installed Programs ======================

Adobe Flash Player 11 Plugin (Version: 11.9.900.117)
AMD APP SDK Runtime (Version: 10.0.938.2)
AMD Catalyst Install Manager (Version: 8.0.881.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.70727.2219)
ASUS Product Register Program (Version: 1.0.014)
AVG 2013 (Version: 13.0.3426)
AVG 2013 (Version: 13.0.3658)
AVG 2013 (Version: 2013.0.3426)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center (Version: 2012.0806.1213.19931)
Catalyst Control Center Graphics Previews Common (Version: 2012.0806.1213.19931)
Catalyst Control Center InstallProxy (Version: 2012.0806.1213.19931)
Catalyst Control Center Localization All (Version: 2012.0806.1213.19931)
CCC Help Czech (Version: 2012.0806.1212.19931)
CCC Help Danish (Version: 2012.0806.1212.19931)
CCC Help Dutch (Version: 2012.0806.1212.19931)
CCC Help English (Version: 2012.0806.1212.19931)
CCC Help Finnish (Version: 2012.0806.1212.19931)
CCC Help French (Version: 2012.0806.1212.19931)
CCC Help German (Version: 2012.0806.1212.19931)
CCC Help Greek (Version: 2012.0806.1212.19931)
CCC Help Hungarian (Version: 2012.0806.1212.19931)
CCC Help Chinese Standard (Version: 2012.0806.1212.19931)
CCC Help Chinese Traditional (Version: 2012.0806.1212.19931)
CCC Help Italian (Version: 2012.0806.1212.19931)
CCC Help Japanese (Version: 2012.0806.1212.19931)
CCC Help Korean (Version: 2012.0806.1212.19931)
CCC Help Norwegian (Version: 2012.0806.1212.19931)
CCC Help Polish (Version: 2012.0806.1212.19931)
CCC Help Portuguese (Version: 2012.0806.1212.19931)
CCC Help Russian (Version: 2012.0806.1212.19931)
CCC Help Spanish (Version: 2012.0806.1212.19931)
CCC Help Swedish (Version: 2012.0806.1212.19931)
CCC Help Thai (Version: 2012.0806.1212.19931)
CCC Help Turkish (Version: 2012.0806.1212.19931)
ccc-utility (Version: 2012.0806.1213.19931)
DAEMON Tools Lite (Version: 4.47.1.0335)
Dota 2 Test
Dream Tale - The Golden Keys (Version: 1.0)
Google Chrome (Version: 31.0.1650.63)
Google Update Helper (Version: 1.3.22.3)
Left 4 Dead 2 version 2.1.2.9 (Version: 2.1.2.9)
Magicka
Microsoft Silverlight (Version: 4.0.60310.0)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (Version: 11.0.60610.1)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610 (Version: 11.0.60610)
Microsoft XNA Framework Redistributable 3.1 (Version: 3.1.10527.0)
MSVCRT Redists (Version: 1.0)
Mumble 1.2.4 (Version: 1.2.4)
Open Broadcaster Software
OpenOffice.org 3.4.1 (Version: 3.41.9593)
Path of Exile (Version: 1.0.0.29229)
PokerStars
QIP 2005 8097 (HKCU Version: 8097)
QIP Internet Guardian
Realtek Ethernet Controller Driver (Version: 7.52.203.2012)
Realtek Ethernet Diagnostic Utility (Version: 1.00.0000)
Skype™ 6.11 (Version: 6.11.102)
Spybot - Search & Destroy (Version: 2.2.25)
Steam (Version: 1.0.0.0)
TeamSpeak 3 Client (Version: 3.0.11)
The Battle for Middle-earth (tm) II
TuneUp Utilities 2013 (Version: 13.0.3020.7)
TuneUp Utilities Language Pack (en-US) (Version: 13.0.3020.7)
Tunngle beta
Unity Web Player (HKCU Version: )
Vegas Pro 10.0 (Version: 10.0.387)
Vegas Pro 11.0 (Version: 11.0.682)
VLC media player 2.0.8 (Version: 2.0.8)
WinRAR 5.00 beta 7 (32-bit) (Version: 5.00.7)
x264vfw - H.264/MPEG-4 AVC codec (remove only)

==================== Restore Points  =========================

21-11-2013 17:59:38 Scheduled Checkpoint
08-12-2013 13:46:38 Scheduled Checkpoint

==================== Hosts content: ==========================

2009-04-22 06:57 - 2009-03-20 16:31 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {185F42AC-BF32-4509-8455-1BB6BE2C07F5} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files\TuneUp Utilities 2013\OneClick.exe [2013-01-31] (TuneUp Software)
Task: {22E3FCC5-8EAC-4F6F-992D-25E58222C1FF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: {24D0CEA5-A6C0-4AFF-9417-6B7FBAF61225} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {4B624321-3827-4DE4-902F-208A7E3842BB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {60BD51E4-1E71-4537-919C-9C0D3D0B4E25} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-03] (Google Inc.)
Task: {FAC1E707-9726-4CCE-9A7E-772801345325} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {FF85A062-F53B-4962-91D8-1783366546C4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-03] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-11-24 21:53 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-11-24 21:53 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2013-08-21 13:18 - 2013-11-06 22:48 - 00691200 _____ () C:\Program Files\Steam\SDL2.dll
2012-06-22 01:39 - 2013-12-04 03:51 - 01135016 _____ () C:\Program Files\Steam\bin\chromehtml.DLL
2012-06-22 01:39 - 2013-11-06 22:48 - 20625832 _____ () C:\Program Files\Steam\bin\libcef.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files\Steam\bin\avcodec-53.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files\Steam\bin\avutil-51.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files\Steam\bin\avformat-53.dll
2012-08-06 11:07 - 2012-08-06 11:07 - 00369152 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-12-05 17:13 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
2013-12-05 17:13 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll
2013-12-05 17:13 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll
2013-12-05 17:13 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
2013-12-05 17:13 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll
2013-12-05 17:13 - 2013-12-04 03:48 - 13586896 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== Faulty Device Manager Devices =============

Name: Universal Serial Bus (USB) Controller
Description: Universal Serial Bus (USB) Controller
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/09/2013 08:46:44 PM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x80070005.

Error: (12/09/2013 08:46:43 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU Client has failed to start

Error: (12/09/2013 04:00:44 PM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x80070005.

Error: (12/09/2013 04:00:43 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU Client has failed to start

Error: (12/08/2013 10:03:06 AM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x80070005.

Error: (12/08/2013 10:03:00 AM) (Source: ATIeRecord) (User: )
Description: ATI EEU Client has failed to start

Error: (12/07/2013 03:54:07 PM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x80070005.

Error: (12/07/2013 03:54:04 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU Client has failed to start

Error: (12/06/2013 03:54:05 PM) (Source: Winlogon) (User: )
Description: Windows license activation failed. Error 0x80070005.

Error: (12/06/2013 03:53:59 PM) (Source: ATIeRecord) (User: )
Description: ATI EEU Client has failed to start


System errors:
=============
Error: (12/09/2013 08:45:51 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
%%5

Error: (12/09/2013 04:03:39 PM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}

Error: (12/08/2013 11:23:35 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
%%5

Error: (12/08/2013 10:06:24 AM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}

Error: (12/07/2013 09:18:51 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
%%5

Error: (12/07/2013 03:57:03 PM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}

Error: (12/06/2013 09:17:06 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
%%5

Error: (12/06/2013 03:57:18 PM) (Source: DCOM) (User: )
Description: C:\Windows\System32\slui.exe -Embedding5{F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}

Error: (12/06/2013 03:54:17 PM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureActions with the following error: 
%%5

Error: (12/05/2013 10:46:16 PM) (Source: Service Control Manager) (User: )
Description: The TuneUp Utilities Service service did not shut down properly after receiving a preshutdown control.


Microsoft Office Sessions:
=========================
Error: (12/09/2013 08:46:44 PM) (Source: Winlogon)(User: )
Description: 0x800700050x00000000

Error: (12/09/2013 08:46:43 PM) (Source: ATIeRecord)(User: )
Description: 

Error: (12/09/2013 04:00:44 PM) (Source: Winlogon)(User: )
Description: 0x800700050x00000000

Error: (12/09/2013 04:00:43 PM) (Source: ATIeRecord)(User: )
Description: 

Error: (12/08/2013 10:03:06 AM) (Source: Winlogon)(User: )
Description: 0x800700050x00000000

Error: (12/08/2013 10:03:00 AM) (Source: ATIeRecord)(User: )
Description: 

Error: (12/07/2013 03:54:07 PM) (Source: Winlogon)(User: )
Description: 0x800700050x00000000

Error: (12/07/2013 03:54:04 PM) (Source: ATIeRecord)(User: )
Description: 

Error: (12/06/2013 03:54:05 PM) (Source: Winlogon)(User: )
Description: 0x800700050x00000000

Error: (12/06/2013 03:53:59 PM) (Source: ATIeRecord)(User: )
Description: 


CodeIntegrity Errors:
===================================
  Date: 2013-12-09 20:46:43.770
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-09 16:21:24.633
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-09 16:00:43.215
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 23:23:17.055
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 23:04:23.815
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 22:58:43.486
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 15:25:25.314
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 14:56:08.766
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 14:45:44.253
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-12-08 13:43:53.863
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\user32.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info =========================== 

Percentage of memory in use: 49%
Total physical RAM: 3549.66 MB
Available physical RAM: 1802.54 MB
Total Pagefile: 7097.6 MB
Available Pagefile: 4573.59 MB
Total Virtual: 2047.88 MB
Available Virtual: 1880.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.5 GB) (Free:800.71 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Magicka) (CDROM) (Total:0.95 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 202B202A)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Naposledy upravil(a) vyosek dne 09 pro 2013 21:09, celkem upraveno 1 x.
Důvod: log odstranen z code

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Jen se zeptam pouzivate legalni operacni system, nejvyssi licence Ultimate zrovna neni bezna. :?:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#3 Příspěvek od Deleter »

predevsim sory za code, myslel sem ze to bude prehlednejsi

a pak.. ano

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#4 Příspěvek od vyosek »

:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na OTL pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pokud pouzivate 64bitovy OS, zkontrolujte, zda-li je zaskrtnuty ctverecek u Pro 64 bitové OS, pokud ne, zaskrtnete jej
  • Zaskrtnete okenko Pro vsechny uzivatele
  • Zaskrtnete okenko Kontrola na havet "LOP"
  • Zaskrtnete okenko Kontrola na havet "Purity"
  • Stari souboru zmente z 30 dnu na 7 dnu
  • Do spodniho okenka Vlastni skenovani/opravy vlozte skript nize
  • Kód: Vybrat vše

    CREATERESTOREPOINT
    
    netsvcs
    drivers32
    savembr:0
    
    /md5start
    atapi.sys
    autochk.exe
    cdrom.sys
    explorer.exe
    hal.dll
    scecli.dll
    services.exe
    svchost.exe
    tcpip.sys
    userinit.exe
    winlogon.exe
    /md5stop
    
    %systemroot%*.* /U /s
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.
    %ALLUSERSPROFILE%\Application Data\*.exe /s
    %APPDATA%\*.
    %APPDATA%\*.exe /s
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\drivers\*.sys /3
    %systemroot%\system32\*.* /3
    %SYSTEMDRIVE%\*.exe
    
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
    
    %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5
    %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5
    %PROGRAMFILES%\Opera\opera.exe /md5
    %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5
    
    %SystemDrive%\PhysicalMBR.bin /md5 
    
    *crack* /s
    *keygen* /s
    *loader* /s
  • Kliknete na tlacitko Prohledat
  • Po dokonceni skenu (cca 10 az 15 min) se objevi logy OTL.txt a Extras.txt, oba sem vlozte
  • Pokud budou logy dlouhe (forum bude kricet o prekroceni maximalniho poctu znaku), tak je rozdelte do vice prispevku
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#5 Příspěvek od Deleter »

OTL logfile created on: 9.12.2013 23:04:33 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deleter\Desktop
Ultimate Edition (Version = 6.1.7100) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7100.0)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,47 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 54,40% Memory free
6,93 Gb Paging File | 3,89 Gb Available in Paging File | 56,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931,50 Gb Total Space | 800,78 Gb Free Space | 85,97% Space Free | Partition Type: NTFS
Drive D: | 975,30 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: DELETER-PC | User Name: Deleter | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Processes (SafeList) ==========

PRC - [2013.12.09 23:02:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deleter\Desktop\OTL.exe
PRC - [2013.12.04 03:51:18 | 001,823,656 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2013.12.04 03:51:18 | 000,569,768 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe
PRC - [2013.12.04 03:48:06 | 000,863,184 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013.10.15 12:27:38 | 003,921,880 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013.09.23 01:17:34 | 004,411,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgui.exe
PRC - [2013.09.23 01:17:30 | 001,117,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgnsx.exe
PRC - [2013.09.20 10:57:26 | 001,042,272 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013.09.13 10:38:30 | 000,171,416 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2013.07.25 11:19:26 | 005,624,784 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013.07.23 18:09:28 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe
PRC - [2013.07.10 00:33:22 | 000,452,144 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgcsrvx.exe
PRC - [2013.07.04 14:53:28 | 000,763,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgrsx.exe
PRC - [2013.07.04 14:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgidsagent.exe
PRC - [2013.03.18 01:38:48 | 000,799,280 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2013\avgemcx.exe
PRC - [2013.01.31 10:35:52 | 001,926,944 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
PRC - [2013.01.31 10:35:50 | 001,724,192 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
PRC - [2012.07.28 03:09:30 | 000,217,600 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2010.10.20 13:35:20 | 000,188,416 | ---- | M] () -- C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe
PRC - [2009.04.22 06:19:35 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.04.22 06:19:02 | 002,607,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009.04.22 06:18:45 | 000,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe


========== Modules (No Company Name) ==========

MOD - [2013.12.04 03:51:20 | 001,135,016 | ---- | M] () -- C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2013.12.04 03:48:04 | 000,399,312 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppgooglenaclpluginchrome.dll
MOD - [2013.12.04 03:48:03 | 013,586,896 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
MOD - [2013.12.04 03:48:02 | 004,055,504 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll
MOD - [2013.12.04 03:47:11 | 000,702,416 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
MOD - [2013.12.04 03:47:11 | 000,099,792 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll
MOD - [2013.12.04 03:47:08 | 001,619,408 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll
MOD - [2013.11.06 22:48:12 | 020,625,832 | ---- | M] () -- C:\Program Files\Steam\bin\libcef.dll
MOD - [2013.11.06 22:48:10 | 000,691,200 | ---- | M] () -- C:\Program Files\Steam\SDL2.dll
MOD - [2013.08.04 05:34:03 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f1f0a543ec9b729e8766e1722f601ffc\WindowsFormsIntegration.ni.dll
MOD - [2013.08.04 05:32:34 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\e78709bedd31f237055667ad99b9451f\System.Core.ni.dll
MOD - [2013.08.04 02:22:21 | 000,224,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60102d8f5e5c5c9c412dc0b0a0b17c30\PresentationFramework.Classic.ni.dll
MOD - [2013.08.04 02:22:10 | 011,803,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\11b8aa2c4cd99e656f75406a26afb6b3\System.Web.ni.dll
MOD - [2013.08.04 02:22:04 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\9d947ba8920086e6c53c0c6cc304d394\System.Runtime.Remoting.ni.dll
MOD - [2013.08.04 02:21:51 | 014,321,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7d80b7d912fbf0f7532f1b9adc235646\PresentationFramework.ni.dll
MOD - [2013.08.04 02:21:29 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\73250999d6824f453014e7e7fb17e459\System.Windows.Forms.ni.dll
MOD - [2013.08.04 02:21:24 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a177ac590efb7e5a37efd9e5033a1365\System.Drawing.ni.dll
MOD - [2013.08.04 02:21:21 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\809ff0119b894ea8a65eb39b694050d6\UIAutomationProvider.ni.dll
MOD - [2013.08.04 02:21:19 | 012,217,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\c79b7f336e6099b8c94081f975e9411e\PresentationCore.ni.dll
MOD - [2013.08.04 02:21:13 | 003,314,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\c7663f3a74fb6aa480c60108634d285a\WindowsBase.ni.dll
MOD - [2013.08.04 02:21:07 | 005,452,288 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\93d38ea87365928456313035f8091126\System.Xml.ni.dll
MOD - [2013.08.04 02:21:02 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\9c2727d244dcc72fbefcf1ae22660f35\System.Configuration.ni.dll
MOD - [2013.08.04 02:21:00 | 007,948,288 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ade9214f5bce88462742bce1278864c0\System.ni.dll
MOD - [2013.08.04 02:20:46 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\70603943245265de9397091048337dda\mscorlib.ni.dll
MOD - [2013.06.15 00:49:12 | 001,100,800 | ---- | M] () -- C:\Program Files\Steam\bin\avcodec-53.dll
MOD - [2013.06.15 00:49:12 | 000,192,000 | ---- | M] () -- C:\Program Files\Steam\bin\avformat-53.dll
MOD - [2013.06.15 00:49:12 | 000,124,416 | ---- | M] () -- C:\Program Files\Steam\bin\avutil-51.dll
MOD - [2013.05.16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013.05.16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2012.08.06 11:07:30 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010.10.20 13:35:20 | 000,188,416 | ---- | M] () -- C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe


========== Services (SafeList) ==========

SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - [2013.12.04 03:51:18 | 000,569,768 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013.10.09 18:24:48 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013.09.05 10:34:30 | 000,171,680 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.09.03 01:38:28 | 000,759,192 | ---- | M] (Tunngle.net GmbH) [On_Demand | Stopped] -- C:\Program Files\Tunngle\TnglCtrl.exe -- (TunngleService)
SRV - [2013.08.03 01:53:43 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2013.07.23 18:09:28 | 000,283,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
SRV - [2013.07.04 14:53:10 | 004,939,312 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013.01.31 10:35:50 | 001,724,192 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2013.01.31 10:35:48 | 000,029,984 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2012.07.28 03:09:30 | 000,217,600 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2009.04.22 06:21:49 | 000,025,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.04.22 06:21:40 | 001,004,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.04.22 06:20:52 | 000,680,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2013.11.11 13:55:55 | 000,037,664 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2013.09.10 01:34:48 | 000,022,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2013.09.05 01:43:42 | 000,039,224 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2013.08.15 17:18:38 | 000,243,128 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2013.07.20 00:51:00 | 000,246,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avglogx.sys -- (Avglogx)
DRV - [2013.07.20 00:50:56 | 000,208,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2013.07.20 00:50:56 | 000,060,216 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2013.07.20 00:50:50 | 000,171,320 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2013.07.01 00:45:28 | 000,096,568 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2013.03.21 02:08:24 | 000,182,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2012.09.18 15:02:02 | 000,010,088 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2012.07.28 05:06:48 | 008,758,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012.07.28 02:14:22 | 000,296,448 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012.07.17 17:12:08 | 000,055,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2012.05.14 07:12:28 | 000,086,656 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2011.09.16 14:12:58 | 000,027,752 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtVlan620.sys -- (VLAN)
DRV - [2011.09.16 14:12:58 | 000,027,752 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan620.sys -- (RTVLANPT)
DRV - [2011.06.15 20:11:20 | 000,040,736 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (TEAM)
DRV - [2011.06.15 20:11:20 | 000,040,736 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV - [2011.06.15 20:11:20 | 000,033,056 | ---- | M] (Realtek ) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2009.09.16 07:02:40 | 000,027,136 | ---- | M] (Tunngle.net) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0901t.sys -- (tap0901t)
DRV - [2009.04.22 06:23:55 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009.04.22 06:23:47 | 000,040,912 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009.04.22 06:23:44 | 000,028,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009.04.22 04:26:30 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009.04.22 04:26:29 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={ ... orm=IE8SRC
IE - HKU\S-1-5-21-223359588-2542410596-43808220-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Deleter\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\OKitSpace@Vittalia.es: C:\Users\Deleter\AppData\Roaming\okitspace\Firefox


========== Chrome ==========

CHR - default_search_provider: Babylon Search (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTer ... 5&tsp=4975
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Dokumenty Google = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Disk Google = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Vyhled00E1v00E1n00ED Google = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Dota 2 Lounge Helper = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmpblpndedodbmceeghpahabeppemed\0.2_0\
CHR - Extension: Ghostery = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\5.0.0_0\
CHR - Extension: Pen\u011B\u017Eenka Google = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0\
CHR - Extension: Gmail = C:\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009.03.20 16:31:18 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (QIPBHO Class) - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Deleter\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll File not found
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-223359588-2542410596-43808220-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (Disc Soft Ltd)
O4 - HKU\S-1-5-21-223359588-2542410596-43808220-1000..\Run: [QIP Internet Guardian] C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe ()
O4 - HKU\S-1-5-21-223359588-2542410596-43808220-1000..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 213.46.172.36 213.46.172.37
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{059498EE-9E21-4EDE-B949-7A80A898BE3D}: DhcpNameServer = 213.46.172.36 213.46.172.37
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.20 16:42:25 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011.01.25 18:01:20 | 000,000,058 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{bff25a1a-05a0-11e3-9e84-50465d8e211a}\Shell - "" = AutoRun
O33 - MountPoints2\{bff25a1a-05a0-11e3-9e84-50465d8e211a}\Shell\AutoRun\command - "" = D:\Setup.exe -- [2011.01.25 18:01:20 | 000,651,283 | R--- | M] (Paradox Interactive )
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.x264 - C:\Program Files\x264vfw\x264vfw.dll (x264vfw project)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 7 Days ==========

[2013.12.09 23:02:52 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Deleter\Desktop\OTL.exe
[2013.12.09 20:51:02 | 000,000,000 | ---D | C] -- C:\FRST
[2013.12.09 20:44:34 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.12.09 20:38:03 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.12.09 20:38:03 | 000,000,000 | ---D | C] -- C:\rsit
[2013.12.09 20:26:38 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.12.09 20:26:33 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2013.12.04 19:20:34 | 000,000,000 | -HSD | C] -- C:\Config.Msi

========== Files - Modified Within 7 Days ==========

[2013.12.09 23:06:28 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.12.09 23:02:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deleter\Desktop\OTL.exe
[2013.12.09 22:24:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013.12.09 22:10:00 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.12.09 22:10:00 | 000,000,938 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.12.09 20:52:43 | 000,606,992 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013.12.09 20:52:43 | 000,103,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013.12.09 20:46:42 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.12.09 20:46:41 | 2791,567,360 | -HS- | M] () -- C:\hiberfil.sys
[2013.12.09 20:26:21 | 005,153,091 | R--- | M] (Swearware) -- C:\Users\Deleter\Desktop\ComboFix.exe
[2013.12.05 17:13:09 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk

========== Files Created - No Company Name ==========

[2013.12.09 23:06:28 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.10.02 12:56:59 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat
[2013.08.03 02:31:43 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013.08.03 01:16:05 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012.07.28 02:30:54 | 000,204,952 | ---- | C] () -- C:\Windows\System32\ativvsvl.dat
[2012.07.28 02:30:54 | 000,157,144 | ---- | C] () -- C:\Windows\System32\ativvsva.dat
[2012.07.27 21:47:36 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012.04.12 20:30:10 | 000,637,743 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat

========== ZeroAccess Check ==========

[2009.04.22 09:16:17 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009.04.22 06:21:56 | 012,855,296 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009.04.22 06:20:29 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009.04.22 06:22:12 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013.12.01 12:42:14 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013.12.01 12:42:14 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2013.08.03 02:48:44 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\AVG2013
[2013.08.15 17:20:30 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\DAEMON Tools Lite
[2013.09.22 16:07:57 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Mumble
[2013.10.10 21:09:21 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\My Battle for Middle-earth(tm) II Files
[2013.08.03 04:12:51 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\OBS
[2013.09.16 09:10:03 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\OpenOffice.org
[2013.11.02 18:59:29 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Publish Providers
[2013.08.03 02:06:40 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\QIP
[2013.08.03 02:25:39 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\QipGuard
[2013.08.24 14:34:41 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Seznam.cz
[2013.11.02 18:59:25 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Sony
[2013.12.01 17:42:54 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\TS3Client
[2013.09.27 21:07:37 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\ts3overlay
[2013.08.03 02:48:05 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\TuneUp Software
[2013.10.06 14:10:59 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Tunngle
[2013.10.28 13:28:27 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Unity
[2013.11.02 19:05:27 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< >
[2009.04.22 09:27:21 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2009.04.22 09:27:21 | 000,032,564 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2013.08.03 01:55:47 | 000,000,938 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.08.03 01:55:48 | 000,000,942 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013.10.02 12:58:06 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< >

< MD5 for: ATAPI.SYS >
[2009.04.22 06:24:04 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=80C40F7FDFC376E4C5FEEC28B41C119E -- C:\Windows\System32\drivers\atapi.sys
[2009.04.22 06:24:04 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=80C40F7FDFC376E4C5FEEC28B41C119E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_b27d5421375ad1cd\atapi.sys
[2009.04.22 06:24:04 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=80C40F7FDFC376E4C5FEEC28B41C119E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7100.0_none_4e2b207b769f9fe5\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2009.04.22 06:18:45 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=DCE8C59D84D5923D0CA54EF116DD8138 -- C:\Windows\System32\autochk.exe
[2009.04.22 06:18:45 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=DCE8C59D84D5923D0CA54EF116DD8138 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7100.0_none_52e6e5ab16d6f438\autochk.exe

< MD5 for: CDROM.SYS >
[2009.04.22 04:08:50 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=EDF617E3CE277E60B8DDC2B6E99B1D54 -- C:\Windows\System32\drivers\cdrom.sys
[2009.04.22 04:08:50 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=EDF617E3CE277E60B8DDC2B6E99B1D54 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_979e56719b05c594\cdrom.sys
[2009.04.22 04:08:50 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=EDF617E3CE277E60B8DDC2B6E99B1D54 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7100.0_none_d09c5443f8dd3b93\cdrom.sys

< MD5 for: EXPLORER.EXE >
[2009.04.22 06:19:02 | 002,607,616 | ---- | M] (Microsoft Corporation) MD5=C133788B393EEC01439AD997D24E66ED -- C:\Windows\explorer.exe
[2009.04.22 06:19:02 | 002,607,616 | ---- | M] (Microsoft Corporation) MD5=C133788B393EEC01439AD997D24E66ED -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7100.0_none_c2a79f73ced24008\explorer.exe
[2013.09.20 10:51:08 | 003,885,120 | ---- | M] (Safer-Networking Ltd.) MD5=CDEB46FE688F062D3033209B29755203 -- C:\Program Files\Spybot - Search & Destroy 2\explorer.exe

< MD5 for: HAL.DLL >
[2009.04.22 06:24:20 | 000,194,128 | ---- | M] (Microsoft Corporation) MD5=826E8635457E8215C87DB6300DFC8F35 -- C:\Windows\System32\hal.dll
[2009.04.22 06:24:20 | 000,194,128 | ---- | M] (Microsoft Corporation) MD5=826E8635457E8215C87DB6300DFC8F35 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7100.0_none_1c1beb05aec0089e\hal.dll

< MD5 for: SCECLI.DLL >
[2009.04.22 06:21:47 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=686BAFE6AF35AF1C8D5EB536A8500430 -- C:\Windows\System32\scecli.dll
[2009.04.22 06:21:47 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=686BAFE6AF35AF1C8D5EB536A8500430 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7100.0_none_a900dabd2e31405b\scecli.dll

< MD5 for: SERVICES.EXE >
[2009.04.22 06:19:27 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=77474E495E99CCE05AD2720E6FA85A35 -- C:\Windows\System32\services.exe
[2009.04.22 06:19:27 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=77474E495E99CCE05AD2720E6FA85A35 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7100.0_none_4052b8c9225ed253\services.exe

< MD5 for: SVCHOST.EXE >
[2009.04.22 06:19:35 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5F1FE2F551E74B069C436152F06CCFDC -- C:\Windows\System32\svchost.exe
[2009.04.22 06:19:35 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5F1FE2F551E74B069C436152F06CCFDC -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7100.0_none_26ae52025a638f2e\svchost.exe

< MD5 for: TCPIP.SYS >
[2009.04.22 06:23:55 | 001,267,280 | ---- | M] (Microsoft Corporation) MD5=4EB1831B5C67AFF9CFFA5269A3905505 -- C:\Windows\System32\drivers\tcpip.sys
[2009.04.22 06:23:55 | 001,267,280 | ---- | M] (Microsoft Corporation) MD5=4EB1831B5C67AFF9CFFA5269A3905505 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7100.0_none_24110ab3bb7c123f\tcpip.sys

< MD5 for: USERINIT.EXE >
[2009.04.22 06:19:37 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=50771CA86FF1ADAF5FD1920F8CB5665E -- C:\Windows\System32\userinit.exe
[2009.04.22 06:19:37 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=50771CA86FF1ADAF5FD1920F8CB5665E -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7100.0_none_4d1bb27726c5c954\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009.04.22 06:19:40 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=B9CFF761509E6C95E964B29B279D7721 -- C:\Windows\System32\winlogon.exe
[2009.04.22 06:19:40 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=B9CFF761509E6C95E964B29B279D7721 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7100.0_none_e0b5f9782a074d3e\winlogon.exe

< >

< %systemroot%*.* /U /s >
[2 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2013.10.02 12:58:52 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Adobe
[2013.08.03 02:32:24 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\ATI
[2013.08.03 02:48:44 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\AVG2013
[2013.08.15 17:20:30 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\DAEMON Tools Lite
[2013.08.03 00:48:58 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Identities
[2013.10.02 12:58:52 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Macromedia
[2009.04.22 11:24:12 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Media Center Programs
[2013.08.22 23:54:11 | 000,000,000 | --SD | M] -- C:\Users\Deleter\AppData\Roaming\Microsoft
[2013.09.22 16:07:57 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Mumble
[2013.10.10 21:09:21 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\My Battle for Middle-earth(tm) II Files
[2013.08.03 04:12:51 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\OBS
[2013.09.16 09:10:03 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\OpenOffice.org
[2013.11.02 18:59:29 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Publish Providers
[2013.08.03 02:06:40 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\QIP
[2013.08.03 02:25:39 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\QipGuard
[2013.08.24 14:34:41 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Seznam.cz
[2013.12.09 23:10:33 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Skype
[2013.11.02 18:59:25 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Sony
[2013.12.01 17:42:54 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\TS3Client
[2013.09.27 21:07:37 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\ts3overlay
[2013.08.03 02:48:05 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\TuneUp Software
[2013.10.06 14:10:59 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Tunngle
[2013.10.28 13:28:27 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Unity
[2013.11.02 19:05:27 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\uTorrent
[2013.12.08 13:36:00 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\vlc
[2013.08.03 02:24:53 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\WinRAR
[2013.10.02 16:03:11 | 000,000,000 | ---D | M] -- C:\Users\Deleter\AppData\Roaming\Xfire

< %APPDATA%\*.exe /s >
[2010.10.20 13:35:20 | 000,188,416 | ---- | M] () -- C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe
[2013.08.08 07:08:08 | 000,880,640 | ---- | M] (BitTorrent Inc.) -- C:\Users\Deleter\AppData\Roaming\uTorrent\utorrent.exe
[2013.08.08 07:08:08 | 000,880,640 | ---- | M] (BitTorrent Inc.) -- C:\Users\Deleter\AppData\Roaming\uTorrent\updates\3.3.1_30003.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job >
[2013.12.09 22:24:00 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013.12.09 22:10:00 | 000,000,938 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013.12.09 23:10:00 | 000,000,942 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[2013.12.09 20:52:43 | 000,103,370 | ---- | M] () -- C:\Windows\system32\perfc009.dat
[2013.12.09 20:52:43 | 000,606,992 | ---- | M] () -- C:\Windows\system32\perfh009.dat
[2013.12.09 20:52:43 | 000,713,888 | ---- | M] () -- C:\Windows\system32\PerfStringBackup.INI

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"QIP Internet Guardian" = C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe -- [2010.10.20 13:35:20 | 000,188,416 | ---- | M] ()
"Sidebar" = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun -- [2009.04.22 06:19:30 | 001,174,016 | ---- | M] (Microsoft Corporation)
"Skype" = "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun -- [2013.11.14 16:42:42 | 020,584,608 | R--- | M] (Skype Technologies S.A.)
"DAEMON Tools Lite" = "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun -- [2013.07.03 14:16:46 | 003,673,184 | ---- | M] (Disc Soft Ltd)
"Steam" = "C:\Program Files\Steam\steam.exe" -silent -- [2013.12.04 03:51:18 | 001,823,656 | ---- | M] (Valve Corporation)

< >

< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >

< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2009.04.22 06:23:15 | 000,674,072 | ---- | M] (Microsoft Corporation) MD5=38632B02A013CD09D0F46BD0DF8C218E -- C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Opera\opera.exe /md5 >

< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2013.12.04 03:48:06 | 000,863,184 | ---- | M] (Google Inc.) MD5=376A9B411BF8B77D5BF84B24D0C7DACD -- C:\Program Files\Google\Chrome\Application\chrome.exe

< >

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.12.09 23:06:28 | 000,000,512 | ---- | M] () MD5=206990476D3741FFEEA4EF8A31D2FD45 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[11 \Users\Deleter\AppData\Local\Temp\*.tmp files -> \Users\Deleter\AppData\Local\Temp\*.tmp -> ]
[2013.08.15 17:33:03 | 000,014,672 | ---- | M] () -- \Users\Deleter\Downloads\[kickass.to]monopoly.2012.full.precracked.foxy.games.torrent
[2013.08.15 17:37:30 | 741,818,610 | ---- | M] () -- \Users\Deleter\Downloads\Monopoly 2012 - Full PreCracked - Foxy Games\Monopoly 2012 - Full PreCracked - Foxy Games.exe

< *keygen* /s >
[2013.09.23 09:43:12 | 000,093,184 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\SoftwareUpdater\KeyGen.dll.vir

< *loader* /s >
[2013.11.11 13:55:53 | 000,004,178 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\AVG Secure Search\Chrome\content\icons\loader.gif.vir
[2013.11.11 13:55:53 | 000,019,497 | ---- | M] () -- \AdwCleaner\Quarantine\C\Program Files\AVG Secure Search\UninstallRes\ClientPackage\Images\uninstall\loader.gif.vir
[2013.11.12 14:20:13 | 000,004,178 | ---- | M] () -- \AdwCleaner\Quarantine\C\Users\Deleter\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\17.1.2.1_0\content\icons\loader.gif.vir
[2012.08.13 09:52:58 | 000,006,081 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.py
[2012.08.10 15:50:58 | 000,020,992 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.dll
[2012.08.13 10:04:18 | 000,000,171 | ---- | M] () -- \Program Files\OpenOffice.org 3\Basis\program\pythonloader.uno.ini
[2012.08.10 15:50:54 | 000,029,696 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\bin\javaloader.uno.dll
[2012.08.13 09:12:36 | 000,003,868 | ---- | M] () -- \Program Files\OpenOffice.org 3\URE\java\unoloader.jar
[2013.06.19 14:59:00 | 000,072,638 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.gif
[2013.06.19 14:59:00 | 000,003,032 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\loader.png
[2013.11.11 14:39:40 | 000,006,012 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\normal\loader_15fps.gif
[2013.11.11 14:39:40 | 000,021,956 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\normal\loader_30fps.gif
[2013.06.19 14:59:00 | 000,009,772 | ---- | M] () -- \ProgramData\Skype\Apps\login\images\retina\loader@2x.png
[2013.06.19 14:59:00 | 000,072,638 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.gif
[2013.06.19 14:59:00 | 000,003,032 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\loader.png
[2013.11.11 14:39:40 | 000,006,012 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\normal\loader_15fps.gif
[2013.11.11 14:39:40 | 000,021,956 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\normal\loader_30fps.gif
[2013.06.19 14:59:00 | 000,009,772 | ---- | M] () -- \Users\All Users\Skype\Apps\login\images\retina\loader@2x.png
[2013.11.04 13:24:34 | 000,110,642 | ---- | M] () -- \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AO6I6AZH\AdLoader-05424a4ab7d836fbf1bc3b5c2b3458f1.min[1].js
[2013.12.09 18:13:21 | 000,001,537 | ---- | M] () -- \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AO6I6AZH\AdLoader[1].htm
[5 \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AO6I6AZH\*.tmp files -> \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AO6I6AZH\*.tmp -> ]
[2013.11.16 02:12:34 | 000,015,748 | ---- | M] () -- \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q5T5FV38\loader[1].js
[5 \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q5T5FV38\*.tmp files -> \Users\Deleter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q5T5FV38\*.tmp -> ]
[2013.10.01 20:01:56 | 000,021,747 | ---- | M] () -- \Users\Deleter\AppData\Roaming\ts3overlay\logs\DIABLO-III-8370-ENGB-INSTALLER-DOWNLOADER.EXE.log
[2013.10.01 18:22:43 | 007,336,664 | ---- | M] () -- \Users\Deleter\Downloads\Diablo-III-8370-enGB-Installer-downloader.exe
[2013.08.15 17:13:54 | 000,167,480 | ---- | M] () -- \Users\Deleter\Downloads\MonopolyDeluxezip_downloader_by_OneOnlineGames.exe
[2009.04.22 06:00:53 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009.04.22 06:20:16 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2009.04.22 09:27:33 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2009.04.22 10:01:06 | 000,002,879 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7100.0_en-us_e78bb2673919a7bc.manifest
[2009.04.22 10:01:06 | 000,033,344 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7100.0_en-us_e78bb2673919a7bc_winload.exe.mui_3bc5b827
[2009.04.22 10:01:06 | 000,029,760 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7100.0_en-us_e78bb2673919a7bc_winresume.exe.mui_ff8b5358
[2009.04.22 07:07:04 | 000,004,213 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7100.0_none_cc19b293c1bcb191.manifest
[2009.04.22 07:07:04 | 000,507,056 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7100.0_none_cc19b293c1bcb191_winload.exe_75835076
[2009.04.22 07:07:04 | 000,441,896 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7100.0_none_cc19b293c1bcb191_winresume.exe_85cd1215
[2009.04.22 07:07:01 | 000,002,886 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7100.0_none_dc26209aa631b5fb.manifest
[2009.04.22 07:07:01 | 000,017,488 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7100.0_none_dc26209aa631b5fb_spldr.sys_98bd87a0
[2009.04.22 07:26:38 | 000,002,879 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7100.0_en-us_e78bb2673919a7bc.manifest
[2009.04.22 06:39:42 | 000,004,213 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7100.0_none_cc19b293c1bcb191.manifest
[2009.04.22 06:43:35 | 000,002,886 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7100.0_none_dc26209aa631b5fb.manifest
[2009.04.22 06:20:16 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7100.0_none_b6e71452e4b8a0a3\dmloader.dll
[2009.04.22 06:00:53 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7100.0_none_7ba4e857d0e5c485\api-ms-win-core-libraryloader-l1-1-0.dll

< End of report >

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#6 Příspěvek od Deleter »

OTL Extras logfile created on: 9.12.2013 23:04:33 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deleter\Desktop
Ultimate Edition (Version = 6.1.7100) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7100.0)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

3,47 Gb Total Physical Memory | 1,89 Gb Available Physical Memory | 54,40% Memory free
6,93 Gb Paging File | 3,89 Gb Available in Paging File | 56,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 931,50 Gb Total Space | 800,78 Gb Free Space | 85,97% Space Free | Partition Type: NTFS
Drive D: | 975,30 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: DELETER-PC | User Name: Deleter | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 7 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02114B53-9324-456F-B96B-80B5CF20D9C9}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{070452BC-081F-42B4-BAF8-977CB8F128F0}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{14A43A66-26FC-425D-BD64-80DFDB478403}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{1B52A4AA-47D3-4956-979D-7CA82DA4BC7A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{1DCFF88B-FC5D-4FA0-ACB7-D1568A632B18}" = protocol=17 | dir=in | app=c:\program files\tunngle\tunngle.exe |
"{23DA39A7-54F9-4494-B076-1221D9B53625}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{2ACE8F16-5878-413F-B7AD-27F13FB116B2}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{3352A330-93D4-4F31-B55E-6EB5D92E79C9}" = protocol=17 | dir=in | app=c:\program files\electronic arts\the battle for middle-earth (tm) ii\game.dat |
"{34019193-655D-4BE3-AF4B-CA215D51698C}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{366220F1-91E5-48F0-8A59-BEC6DE43EA9D}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{42C54025-5C87-4C5D-B5C7-1433EBDA57E8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 test\dota.exe |
"{435E8A43-5CDA-4B20-AAF5-4A71BE1E3525}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{47959BF1-F49C-48CA-A7EC-9FE00140E825}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{61F7D885-65FD-4C55-BEFB-7323B5DE9244}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{6539D09B-AF97-4E16-8099-76A5BC2A7B43}" = protocol=17 | dir=in | app=c:\program files\tunngle\tnglctrl.exe |
"{6B0766EC-1DD7-4818-B278-BBFCC875DD9A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 test\dota.exe |
"{772EAFC6-1A42-4C92-8DF5-21DBBE9E6BCB}" = protocol=6 | dir=in | app=c:\program files\tunngle\tunngle.exe |
"{8AC5A33B-23C1-4FB2-9D9A-657263B7B20E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{9AC7B2E0-8A57-45C2-B4DB-5A9D2D2FE5DC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{9DEFFC67-99A2-45A1-AEC8-1AE80EF59C34}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{9F27AE8F-4AC2-4578-B19F-D530B4B3F935}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{A9EB035B-00A1-4F6A-BF03-91952892F194}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{B0773DF0-211F-4082-98FB-834C7514B0DD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{B3245380-927D-4B1E-AA5B-29DA8E29FF01}" = protocol=6 | dir=in | app=c:\program files\tunngle\tnglctrl.exe |
"{C043A71E-5D85-4339-8654-2FD98C32F05A}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{C9DE43D8-FAD8-4842-AE4E-9AFAF6EB1FDB}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{CE916586-945C-47E7-ACEC-87F5572AAD12}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgemcx.exe |
"{D5512BE6-C5AB-425B-8E1C-3F292586961D}" = protocol=6 | dir=in | app=c:\program files\electronic arts\the battle for middle-earth (tm) ii\game.dat |
"{DB5D5058-3DE4-4586-B0C6-A61150425373}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dota 2 beta\dota.exe |
"{ED45C121-7386-48B8-AA82-8D5FCC86A328}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{FC63F2CA-E493-4EA2-894A-8DFE0BC37F0B}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"TCP Query User{BCA7D212-D08B-41F3-9B1E-91802A86C5F7}C:\program files\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"UDP Query User{D130926C-0D4D-4B42-ACA4-EDFDA75357E5}C:\program files\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04475621-9BF8-EF82-4691-1C8FD9D40FD2}" = CCC Help Polish
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07A733AA-2D8C-1E0E-ED9B-B4CA59AE86B3}" = Catalyst Control Center
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1AADBEB8-3F11-7FB7-6DDC-EE2276C1A80E}" = CCC Help Italian
"{1E0AF527-0B8E-4F8A-BA27-CB3C359998C6}" = OpenOffice.org 3.4.1
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = The Battle for Middle-earth (tm) II
"{2C3F42F5-935B-E64C-13D7-4369B0D66DE9}" = CCC Help Greek
"{3039C874-762C-4759-70F3-3DCA2FCE55FA}" = AMD Drag and Drop Transcoding
"{37CE847B-3279-1A39-CA09-FBF330B5EC97}" = CCC Help Czech
"{3B78608F-D09A-11DF-A54E-0013D3D69929}" = Vegas Pro 10.0
"{3C15E8E2-3463-584F-D4F8-D95878737EAB}" = CCC Help Norwegian
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{40719211-D09A-11DF-BA30-0013D3D69929}" = MSVCRT Redists
"{420500EA-4038-AADB-DD76-90D0311E5867}" = CCC Help Spanish
"{43403BCA-6051-A108-682C-5BABB69D3919}" = CCC Help Hungarian
"{49603CBF-8861-4D94-AD85-E4854AD366CA}" = AVG 2013
"{49BE9B8A-E858-4533-A74A-64306C13DB59}" = ASUS Product Register Program
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.11
"{549ECD2C-5ACD-0598-56E6-BF88F6B5CE9E}" = CCC Help Portuguese
"{5BAD1D5F-157F-C4D7-05B8-7B2D08874DFA}" = CCC Help German
"{6280C3D1-00A3-4E79-BDF6-98332A29B706}" = AVG 2013
"{6AEFCA01-8DF1-11E1-A17B-F04DA23A5C58}" = Vegas Pro 11.0
"{6E9484D8-F1F5-8737-3C35-C2ACB8BC9BF8}" = CCC Help Danish
"{6EB6BC61-0079-80B7-9AE8-A28E02F81E04}" = CCC Help Japanese
"{70CB6C40-8DF1-11E1-BDCF-F04DA23A5C58}" = MSVCRT Redists
"{74DDE8F9-FAD1-4C64-84DF-DF287EAE6FAE}" = CCC Help Turkish
"{7C53D4FA-0F42-3B24-686B-2AB688C8B112}" = Catalyst Control Center Localization All
"{85F76CD3-92C2-6422-202C-ADC655E83940}" = CCC Help Chinese Standard
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DA03380-AB50-EB7F-FB21-D43DBB997919}" = ccc-utility
"{90A4562F-D4A1-4B65-906D-41F236CF6902}" = Path of Exile
"{92E71E47-7BDE-2A10-A9C2-373DCAE4EEB9}" = CCC Help Chinese Traditional
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{9693675A-7108-247D-A369-AF08C8E32CFD}" = CCC Help English
"{9971CC5F-9E89-6024-72CD-2F9B33305B7F}" = CCC Help Swedish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E8426B6-0027-8C7E-9729-E86053D9A3D5}" = CCC Help Finnish
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A6F5703D-A4B1-4857-9EDD-DC0ABBBB0D96}" = TuneUp Utilities Language Pack (en-US)
"{A793A380-9E70-7392-30CF-259E458F02EF}" = AMD Media Foundation Decoders
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B66F4972-5C17-90A5-95AB-0C4DAEFC92A4}" = CCC Help Korean
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{C6B0FBD0-067F-5ED3-B4C1-BC61284A1079}" = Catalyst Control Center InstallProxy
"{CAF5DA8C-62A3-C020-E878-6AEFAB54BF6A}" = AMD Catalyst Install Manager
"{DADC7AB0-E554-4705-9F6A-83EA82ED708E}" = Realtek Ethernet Diagnostic Utility
"{DB689397-D3C2-BD23-A83E-FCA68454F0FE}" = CCC Help Dutch
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{EAD24F4A-8BB8-EAC5-A995-3D9A96DF3FA4}" = CCC Help French
"{F0BC0231-25D6-B4BF-5D9E-633220A2C09A}" = CCC Help Russian
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F30ECD7F-0336-48C8-B484-94F58B9F38AD}_is1" = Left 4 Dead 2 version 2.1.2.9
"{F501FACA-3AFB-FAC4-825D-F6D1343F0C69}" = Catalyst Control Center Graphics Previews Common
"{F7657E34-0046-9515-61D9-7AAFC84C4AC8}" = CCC Help Thai
"{FD8F9644-A572-44AD-84B0-21CA46CB7DC6}" = Mumble 1.2.4
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2013
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dream Tale - The Golden Keys1.0" = Dream Tale - The Golden Keys
"Google Chrome" = Google Chrome
"Magicka_is1" = Magicka
"Open Broadcaster Software" = Open Broadcaster Software
"PokerStars" = PokerStars
"Steam App 205790" = Dota 2 Test
"Steam App 570" = Dota 2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"Tunngle beta_is1" = Tunngle beta
"VLC media player" = VLC media player 2.0.8
"WinRAR archiver" = WinRAR 5.00 beta 7 (32-bit)
"x264vfw" = x264vfw - H.264/MPEG-4 AVC codec (remove only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-223359588-2542410596-43808220-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"QIP 2005" = QIP 2005 8097
"QipGuard" = QIP Internet Guardian
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6.12.2013 10:53:59 | Computer Name = Deleter-PC | Source = ATIeRecord | ID = 16386
Description = ATI EEU Client has failed to start

Error - 6.12.2013 10:54:05 | Computer Name = Deleter-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 7.12.2013 10:54:04 | Computer Name = Deleter-PC | Source = ATIeRecord | ID = 16386
Description = ATI EEU Client has failed to start

Error - 7.12.2013 10:54:07 | Computer Name = Deleter-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 8.12.2013 5:03:00 | Computer Name = Deleter-PC | Source = ATIeRecord | ID = 16386
Description = ATI EEU Client has failed to start

Error - 8.12.2013 5:03:06 | Computer Name = Deleter-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 9.12.2013 11:00:43 | Computer Name = Deleter-PC | Source = ATIeRecord | ID = 16386
Description = ATI EEU Client has failed to start

Error - 9.12.2013 11:00:44 | Computer Name = Deleter-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

Error - 9.12.2013 15:46:43 | Computer Name = Deleter-PC | Source = ATIeRecord | ID = 16386
Description = ATI EEU Client has failed to start

Error - 9.12.2013 15:46:44 | Computer Name = Deleter-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.

[ System Events ]
Error - 6.12.2013 10:54:17 | Computer Name = Deleter-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 6.12.2013 10:57:18 | Computer Name = Deleter-PC | Source = DCOM | ID = 10001
Description =

Error - 6.12.2013 16:17:06 | Computer Name = Deleter-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 7.12.2013 10:57:03 | Computer Name = Deleter-PC | Source = DCOM | ID = 10001
Description =

Error - 7.12.2013 16:18:51 | Computer Name = Deleter-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 8.12.2013 5:06:24 | Computer Name = Deleter-PC | Source = DCOM | ID = 10001
Description =

Error - 8.12.2013 18:23:35 | Computer Name = Deleter-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 9.12.2013 11:03:39 | Computer Name = Deleter-PC | Source = DCOM | ID = 10001
Description =

Error - 9.12.2013 15:45:51 | Computer Name = Deleter-PC | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 9.12.2013 16:04:07 | Computer Name = Deleter-PC | Source = DCOM | ID = 10001
Description =


< End of report >

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#7 Příspěvek od vyosek »

:arrow: Odinstalujte Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
    Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
    HKCU\...\Run: [QIP Internet Guardian] - C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe [188416 2010-10-20] ()
    HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
    HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
    HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1823656 2013-12-04] (Valve Corporation)
    MountPoints2: {bff25a1a-05a0-11e3-9e84-50465d8e211a} - D:\Setup.exe
    AppInit_DLLs: [ ] ()
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
    URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
    SearchScopes: HKLM - DefaultScope value is missing.
    BHO: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Deleter\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll No File
    
    CHR DefaultSearchKeyword: babylon.com
    CHR DefaultSearchProvider: Babylon Search
    CHR DefaultSearchURL: http://search.babylon.com/?q={searchTerms}&babsrc=SP_ss&mntrId=88B850465D8E211A&affID=123895&tsp=4975
    CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    2013-11-24 21:53 - 2013-11-24 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
    2013-11-24 21:53 - 2013-11-24 21:54 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
    2013-11-24 21:53 - 2013-11-24 21:53 - 00002115 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    2013-11-24 21:53 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
    2013-11-24 21:52 - 2013-11-24 21:53 - 46988968 _____ C:\Users\Deleter\Downloads\spybot-2.2.exe
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#8 Příspěvek od Deleter »

ix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-12-2013
Ran by Deleter at 2013-12-10 17:38:07 Run:1
Running from C:\Users\Deleter\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKCU\...\Run: [QIP Internet Guardian] - C:\Users\Deleter\AppData\Roaming\QipGuard\QipGuard.exe [188416 2010-10-20] ()
HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKCU\...\Run: [Steam] - C:\Program Files\Steam\Steam.exe [1823656 2013-12-04] (Valve Corporation)
MountPoints2: {bff25a1a-05a0-11e3-9e84-50465d8e211a} - D:\Setup.exe
AppInit_DLLs: [ ] ()

HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
SearchScopes: HKLM - DefaultScope value is missing.
BHO: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Deleter\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll No File

CHR DefaultSearchKeyword: babylon.com
CHR DefaultSearchProvider: Babylon Search
CHR DefaultSearchURL: http://search.babylon.com/?q={searchTer ... 5&tsp=4975
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

2013-11-24 21:53 - 2013-11-24 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-11-24 21:53 - 2013-11-24 21:54 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-11-24 21:53 - 2013-11-24 21:53 - 00002115 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-11-24 21:53 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2013-11-24 21:52 - 2013-11-24 21:53 - 46988968 _____ C:\Users\Deleter\Downloads\spybot-2.2.exe

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SDTray => Value not found.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => Key not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\QIP Internet Guardian => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Steam => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bff25a1a-05a0-11e3-9e84-50465d8e211a} => Key deleted successfully.
HKCR\CLSID\{bff25a1a-05a0-11e3-9e84-50465d8e211a} => Key not found.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955} => Key deleted successfully.
HKCR\CLSID\{95289393-33EA-4F8D-B952-483415B9C955} => Key not found.
CHR DefaultSearchKeyword: babylon.com ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchProvider: Babylon Search ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchURL: http://search.babylon.com/?q={searchTer ... 5&tsp=4975 ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} ==> The Chrome "Settings" can be used to fix the entry.
HKLM\SOFTWARE\Policies\Google => Key deleted successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\Program Files\Spybot - Search & Destroy 2 => Moved successfully.
"C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk" => File/Directory not found.
"C:\Windows\system32\sdnclean.exe" => File/Directory not found.
C:\Users\Deleter\Downloads\spybot-2.2.exe => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========


==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#9 Příspěvek od vyosek »

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#10 Příspěvek od Deleter »

Zmenu jsem moc nepocitil.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#11 Příspěvek od vyosek »

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Dejte log z RSIT http://forum.viry.cz/viewtopic.php?f=24&t=130784
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#12 Příspěvek od Deleter »

Logfile of random's system information tool 1.09 (written by random/random)
Run by Deleter at 2013-12-15 13:45:51
Microsoft Windows 7 Ultimate
System drive C: has 870 GB (91%) free of 954 GB
Total RAM: 3550 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:45:55, on 15.12.2013
Platform: Windows 7 (WinNT 6.00.3004)
MSIE: Internet Explorer v8.00 (8.00.7100.0000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Deleter\Downloads\RSIT (1).exe
C:\Program Files\trend micro\Deleter.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe

--
End of file - 3426 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2012-08-06 642216]
"AVG_UI"=C:\Program Files\AVG\AVG2013\avgui.exe [2013-11-20 4411952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-22 1174016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll [2009-04-22 236032]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll
"vidc.x264"=C:\PROGRA~1\x264vfw\x264vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2013-12-15 13:45:25 ----D---- C:\rsit
2013-12-14 14:08:19 ----D---- C:\Program Files\Defraggler
2013-12-10 17:35:37 ----A---- C:\Windows\wininit.ini
2013-12-10 17:30:42 ----D---- C:\Program Files\CCleaner
2013-12-09 20:38:03 ----D---- C:\Program Files\trend micro
2013-11-25 01:48:36 ----A---- C:\Windows\system32\drivers\avgidsdriverx.sys

======List of files/folders modified in the last 1 month======

2013-12-15 13:45:55 ----D---- C:\Windows\Prefetch
2013-12-15 13:36:06 ----D---- C:\Windows\Temp
2013-12-15 08:26:39 ----D---- C:\ProgramData\MFAData
2013-12-15 06:43:57 ----SHD---- C:\System Volume Information
2013-12-15 05:23:50 ----D---- C:\Windows\system32\config
2013-12-15 04:00:20 ----D---- C:\Program Files\Steam
2013-12-15 04:00:17 ----D---- C:\Users\Deleter\AppData\Roaming\Skype
2013-12-14 14:10:40 ----D---- C:\Windows\System32
2013-12-14 14:10:40 ----D---- C:\Windows\inf
2013-12-14 14:10:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2013-12-14 14:08:19 ----RD---- C:\Program Files
2013-12-14 14:06:51 ----D---- C:\Windows
2013-12-13 18:32:11 ----D---- C:\Windows\system32\catroot2
2013-12-12 17:39:45 ----D---- C:\Program Files\Common Files\Steam
2013-12-11 20:47:55 ----D---- C:\Users\Deleter\AppData\Roaming\TS3Client
2013-12-10 20:24:16 ----D---- C:\Windows\Tasks
2013-12-10 20:24:04 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2013-12-10 17:38:07 ----HD---- C:\ProgramData
2013-12-10 17:38:07 ----D---- C:\Windows\system32\drivers\etc
2013-12-10 17:35:39 ----SD---- C:\ProgramData\Microsoft
2013-12-10 17:31:38 ----D---- C:\Windows\debug
2013-12-10 16:18:40 ----SHD---- C:\Windows\Installer
2013-12-10 16:18:02 ----D---- C:\Windows\system32\drivers
2013-12-09 20:45:16 ----D---- C:\Windows\system32\Tasks
2013-12-09 20:45:15 ----D---- C:\Program Files\Common Files
2013-12-08 13:36:00 ----D---- C:\Users\Deleter\AppData\Roaming\vlc
2013-11-26 16:03:19 ----D---- C:\ProgramData\Skype
2013-11-26 16:03:10 ----RD---- C:\Program Files\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHX;AVGIDSHX; C:\Windows\system32\DRIVERS\avgidshx.sys [2013-07-20 60216]
R0 Avglogx;AVG Logging Driver; C:\Windows\system32\DRIVERS\avglogx.sys [2013-07-20 246072]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx86.sys [2013-07-01 96568]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx86.sys [2013-10-23 39224]
R0 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-04-22 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-04-22 173648]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdriverx.sys [2013-11-25 208184]
R1 AVGIDSShim;AVGIDSShim; C:\Windows\system32\DRIVERS\avgidsshimx.sys [2013-10-23 22328]
R1 Avgldx86;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx86.sys [2013-07-20 171320]
R1 Avgtdix;AVG TDI Driver; C:\Windows\system32\DRIVERS\avgtdix.sys [2013-03-21 182072]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx86.sys [2013-11-11 37664]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-04-22 387584]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-08-15 243128]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-04-22 8704]
R2 RtNdPt60;Realtek NDIS Protocol Driver; C:\Windows\system32\DRIVERS\RtNdPt60.sys [2011-06-15 33056]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2012-07-28 8758784]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2012-07-28 296448]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW73.sys [2012-05-14 86656]
R3 MEI;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECI.sys [2012-07-17 55104]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2012-02-03 514152]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [2012-09-18 10088]
R3 VLAN;Realtek Virtual Miniport Driver for VLAN (NDIS 6.2); C:\Windows\system32\DRIVERS\RtVLAN620.sys [2011-09-16 27752]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-04-22 70736]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-04-22 53328]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-04-22 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-04-22 78336]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-04-22 133120]
S3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2); C:\Windows\system32\DRIVERS\RtTeam60.sys [2011-06-15 40736]
S3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2); C:\Windows\system32\DRIVERS\RtVlan620.sys [2011-09-16 27752]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-04-22 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-04-22 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-04-22 28240]
S3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2); C:\Windows\system32\DRIVERS\RtTeam60.sys [2011-06-15 40736]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-04-22 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-04-22 52736]
S3 vmbus;vmbus; C:\Windows\system32\DRIVERS\vmbus.sys [2009-04-22 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-04-22 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2012-07-28 217600]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2013\avgidsagent.exe [2013-07-04 4939312]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2013\avgwdsvc.exe [2013-11-20 283136]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-04-22 20992]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe [2013-01-31 1724192]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-04-22 20992]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-03 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10 257416]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-04-22 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-08-03 116648]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-04-22 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2013-12-11 569768]
S3 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2013-09-03 759192]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-04-22 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-08-03 1343400]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#13 Příspěvek od vyosek »

:arrow: Doinstalujte ServicePack 1 a ostatni dulezite aktualizace

:arrow: Jinak log vypada OK
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Deleter
Návštěvník
Návštěvník
Příspěvky: 14
Registrován: 26 črc 2009 01:04

Re: prosim o kontrolu

#14 Příspěvek od Deleter »

Ok. Diky za pomoc.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: prosim o kontrolu

#15 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno