Stránka 1 z 3

Obnovení systému

Napsal: 06 led 2014 17:39
od Neliell
Dobrý den, po obnovení systému je notebook zpomalený a google chrome si žádá reinstalaci. Prosím o pomoc, netuším kde je chyba.
Před obnovou systému byl počítač také zpomalen, ovšem méně než teď. Žádám o radu, děkuji. Bude třeba reinstalace OS?

Přikládám i log:

Logfile of random's system information tool 1.09 (written by random/random)
Run by toshiba at 2014-01-06 17:29:39
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 149 GB (49%) free of 305 GB
Total RAM: 5607 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:30:31, on 6.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16720)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\toshiba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: BetterSurf - {6E3C6B04-08FE-43BC-8E50-F90285024DEA} - C:\Program Files (x86)\BetterSurf\ie\BetterSurf.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Rich Media Downloader - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - C:\Users\toshiba\AppData\Local\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll
O4 - HKLM\..\Run: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe /STARTUP
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\toshiba\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Handy Updater] "C:\Program Files (x86)\HandyUpdater\HUpdater.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Toshiba Places Icon Utility.lnk = C:\Program Files\Toshiba\TOSHIBA Places Icon Utility\TosDIMonitor.exe
O8 - Extra context menu item: Přidat do aplikace TOSHIBA Bulletin Board - res://C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-229 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-228 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
O9 - Extra button: Rich Media Downloader - {A7DF592F-6E2A-45C4-9A87-4BD217D714ED} - C:\Users\toshiba\AppData\Local\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: McAfee Application Installer Cleanup (0279691381158036) (0279691381158036mcinstcleanup) - Unknown owner - C:\Users\toshiba\AppData\Local\Temp\027969~1.EXE (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: @c:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14385 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 29870576
\??\C:\Windows\system32\conhost.exe "-718350295-1731489165981960380-148717933492255060821069346601333174088-177153660
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\diMaster.dll" /prefetch:1
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
WLIDSvcM.exe 2452
"taskhost.exe"
"C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe" /c /a /s UserSession2
taskeng.exe {265450E1-3526-41A9-ABD3-7759FE5B64FF}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\Toshiba\Power Saver\TPwrMain.exe"
"C:\Program Files\Toshiba\FlashCards\TCrdMain.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Toshiba\TECO\Teco.exe" /r
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe" /STARTUP
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\HandyUpdater\HUpdater.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files\Toshiba\TOSHIBA Places Icon Utility\TosDIMonitor.exe"
szndesktop.exe default start
"C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe "-3588705101917573611538619873-1889945138316986104394469967488464572079791137
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe"
"C:\Windows\system32\wuauclt.exe" /RunHandlerComServer
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Users\toshiba\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\hvdleacf.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.DEU
nppdf32.dll
nppdf32.FRA
nppdf32.JPN
nppluginrichmediaplayer.dll

C:\Users\toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\hvdleacf.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll [2013-05-30 509776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL [2012-08-10 387040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}]
BetterSurf - C:\Program Files (x86)\BetterSurf\ie\BetterSurf.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7DF592F-6E2A-45C4-9A87-4BD217D714ED}]
Rich Media Downloader - C:\Users\toshiba\AppData\Local\Rich Media Player\BrowserExtensions\IE\RichMediaDownloader.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-08-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll [2013-05-30 509776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2011-03-30 38304]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2011-02-10 1546720]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2011-03-02 566696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2010-09-25 296824]
"TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2011-03-09 967544]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-12-14 316032]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-02-03 2679592]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2011-04-07 1544104]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-12-08 710040]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2011-07-01 712096]
"TosNC"=C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2011-03-03 597928]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2011-08-03 150992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [2011-05-16 846936]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-07-25 20684656]
"cz.seznam.software.autoupdate"=C:\Users\toshiba\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]
"Handy Updater"=C:\Program Files (x86)\HandyUpdater\HUpdater.exe [2013-10-03 370176]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NBAgent"=c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2011-06-29 1409424]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2013-09-03 40312]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-11-11 343168]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START []
"TSleepSrv"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [2010-06-04 252792]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2010-11-29 1294712]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-10-01 152392]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
Toshiba Places Icon Utility.lnk - C:\Program Files\Toshiba\TOSHIBA Places Icon Utility\TosDIMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-01-06 17:29:41 ----D---- C:\Program Files\trend micro
2014-01-06 17:29:39 ----D---- C:\rsit
2013-12-20 19:05:51 ----D---- C:\Program Files (x86)\WebexpEnhancedV1

======List of files/folders modified in the last 1 month======

2014-01-06 17:29:41 ----RD---- C:\Program Files
2014-01-06 17:29:30 ----D---- C:\Windows\Temp
2014-01-06 17:29:23 ----D---- C:\Windows\winsxs
2014-01-06 17:22:33 ----D---- C:\Windows\SysWOW64
2014-01-06 17:22:20 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-01-06 17:22:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-01-06 17:17:00 ----D---- C:\Windows\system32\MRT
2014-01-06 17:16:40 ----D---- C:\Users\toshiba\AppData\Roaming\Skype
2014-01-06 17:15:47 ----SHD---- C:\System Volume Information
2014-01-06 17:15:46 ----D---- C:\Windows\Logs
2014-01-06 17:11:54 ----D---- C:\Users\toshiba\AppData\Roaming\TS3Client
2014-01-06 17:11:47 ----D---- C:\Users\toshiba\AppData\Roaming\Seznam.cz
2014-01-06 17:11:35 ----D---- C:\Windows\System32
2014-01-06 17:11:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-01-06 17:11:34 ----D---- C:\Windows\inf
2014-01-06 17:06:39 ----D---- C:\Windows\system32\config
2014-01-05 23:22:34 ----D---- C:\Windows\system32\catroot
2014-01-05 23:15:23 ----D---- C:\Windows\system32\catroot2
2014-01-05 23:04:05 ----SHD---- C:\Windows\Installer
2014-01-05 23:00:24 ----RD---- C:\Program Files (x86)
2014-01-05 22:44:50 ----D---- C:\Windows\Tasks
2014-01-05 22:44:50 ----D---- C:\Windows\system32\wfp
2014-01-05 22:44:49 ----RSD---- C:\Windows\Media
2014-01-05 22:44:49 ----D---- C:\Program Files\Internet Explorer
2014-01-05 22:44:34 ----D---- C:\Windows\system32\wbem
2014-01-05 22:44:34 ----D---- C:\Windows
2014-01-05 22:41:14 ----D---- C:\Windows\SYSWOW64\wbem
2014-01-05 22:41:14 ----D---- C:\Windows\system32\DriverStore
2014-01-05 22:41:14 ----D---- C:\Windows\system32\drivers
2014-01-05 22:41:14 ----D---- C:\Program Files\Windows Media Player
2014-01-05 22:41:14 ----D---- C:\Program Files (x86)\Windows Media Player
2014-01-05 22:41:04 ----D---- C:\Windows\SYSWOW64\migration
2014-01-05 22:41:04 ----D---- C:\Windows\SYSWOW64\en-US
2014-01-05 22:41:04 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-01-05 22:41:04 ----D---- C:\Windows\system32\migration
2014-01-05 22:41:04 ----D---- C:\Windows\system32\en-US
2014-01-05 22:41:04 ----D---- C:\Windows\system32\cs-CZ
2014-01-05 22:41:04 ----D---- C:\Windows\rescache
2014-01-05 22:41:04 ----D---- C:\Windows\PolicyDefinitions
2014-01-05 22:41:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-01-05 22:40:04 ----D---- C:\Windows\SYSWOW64\Macromed
2014-01-05 22:39:58 ----D---- C:\Windows\system32\Tasks
2014-01-05 22:39:55 ----D---- C:\Windows\system32\Macromed
2014-01-05 22:39:53 ----D---- C:\Windows\system32\CodeIntegrity
2014-01-05 22:39:43 ----D---- C:\Windows\AppCompat
2014-01-05 22:39:09 ----D---- C:\ProgramData\Norton
2014-01-05 22:39:03 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-01-05 22:39:02 ----D---- C:\Program Files (x86)\Skype
2014-01-05 22:39:01 ----D---- C:\Program Files (x86)\PokerStars
2014-01-05 22:39:00 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-05 22:38:56 ----D---- C:\Program Files (x86)\GotClip
2014-01-05 22:31:56 ----D---- C:\Windows\registration
2014-01-05 22:29:42 ----D---- C:\Users\toshiba\AppData\Roaming\SoftGrid Client
2014-01-05 22:29:23 ----D---- C:\ProgramData\Skype
2014-01-05 22:29:22 ----HD---- C:\ProgramData
2014-01-05 22:27:55 ----D---- C:\Program Files (x86)\BetterSurf
2014-01-05 22:27:54 ----RHD---- C:\MSOCache
2013-12-30 12:01:46 ----D---- C:\Windows\Prefetch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\1404000.028\SYMDS64.SYS [2013-05-20 493656]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\1404000.028\SYMEFA64.SYS [2013-05-22 1139800]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20131203.001_d07\BHDrvx64.sys [2013-12-03 1526488]
R1 ccSet_N360;Norton 360 Settings Manager; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [2013-04-15 169048]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-11-23 484952]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20140103.001_dc1\IDSvia64.sys [2014-01-03 521944]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [2013-03-04 36952]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [2012-07-27 224416]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS [2013-04-24 433752]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2010-11-29 82224]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-11-11 10496512]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-11-10 326656]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-12-17 2675712]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver; C:\Windows\system32\DRIVERS\btfilter.sys [2010-10-18 42096]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2011-01-27 1577088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-01-04 137648]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-02-09 77424]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20140104.006_d24\ENG64.SYS [2014-01-04 126040]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20140104.006_d24\EX64.SYS [2014-01-04 2099288]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2011-02-08 38096]
R3 QIOMem;Generic IO & Memory Access; C:\Windows\system32\drivers\QIOMem.sys [2009-06-15 12800]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSP64.SYS [2013-05-15 796760]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-10-07 177312]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-02-03 1413680]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2011-02-23 291120]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2010-06-18 18872]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2010-08-30 94528]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2011-01-27 67384]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-08-20 103576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-12-01 250984]
S3 RSUSBVSTOR;RTSUVSTOR.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RTSUVSTOR.sys [2010-11-30 307304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-08-20 204568]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2010-11-11 50864]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2010-04-26 63488]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-09 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-11-10 204288]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [2013-05-20 144368]
R2 NAUpdate;@c:\Program Files (x86)\Nero\Update\NASvc.exe,-200; c:\Program Files (x86)\Nero\Update\NASvc.exe [2011-03-29 598312]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-08-14 3291008]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-04-23 3574624]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2010-10-20 138656]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [2010-12-09 489384]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2011-04-07 294328]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-10-01 641352]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-29 54136]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2010-04-12 196976]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-12-08 137632]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2011-07-01 828856]
S2 0279691381158036mcinstcleanup;McAfee Application Installer Cleanup (0279691381158036); C:\Users\toshiba\AppData\Local\Temp\027969~1.EXE -cleanup -nolog []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-03 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-07-25 162672]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-06 257416]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-03 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2013-09-17 118680]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-11-19 4925184]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2011-02-10 112080]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-04-17 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: Obnovení systému

Napsal: 06 led 2014 17:47
od Márty84
Zdravim :)

:arrow: Stahnete crystal disk info http://sourceforge.jp/projects/crystald ... 5_0_0.zip/
Spustte jako spravce. Za chvili se zobrazi vysledek.
Kliknete nahore na napis Úpravy a pak na napis Kopírovat. To co se zkopiruje (ulozi se to do pameti) mi sem vlozte (ctrl + V)


:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a program zacne pracovat.
Az skonci, vyplivne na vas log (pokud ne, najdete ho zde C:\AdwCleaner\AdwCleaner[R?].txt ), ten mi sem zkopirujte.

Re: Obnovení systému

Napsal: 06 led 2014 19:52
od Neliell
CrystalDiskInfo:

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.0 (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Home Premium Edition SP1 [6.1 Build 7601] (x64)
Date : 2014/01/06 19:52:12

-- Controller Map ----------------------------------------------------------
+ ATA Channel 0 (0) [ATA]
- Hitachi HTS547564A9E384 ATA Device
+ ATA Channel 1 (1) [ATA]
- TSSTcorp CDDVDW SN-208AB ATA Device
+ Standardní řadič AHCI 1.0 s rozhraním Serial ATA [ATA]
- ATA Channel 0 (0)
- ATA Channel 1 (1)

-- Disk List ---------------------------------------------------------------
(1) Hitachi HTS547564A9E384 : 640,1 GB [0/0/0, pd1]

----------------------------------------------------------------------------
(1) Hitachi HTS547564A9E384
----------------------------------------------------------------------------
Model : Hitachi HTS547564A9E384
Firmware : JEDOA60B
Serial Number : 130825J2380053CXZMLD
Disk Size : 640,1 GB (8,4/137,4/640,1)
Buffer Size : 8192 KB
Queue Depth : 32
# of Sectors : 1250263728
Rotation Rate : 5400 RPM
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ATA8-ACS version 6
Transfer Mode : SATA/300
Power On Hours : 643 hod.
Power On Count : 189 krát
Temparature : 36 C (96 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, 48bit LBA, NCQ
APM Level : 4080h [ON]
AAM Level : ----

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 100 100 _62 000000000000 Počet chyb čtení
02 100 100 _40 000000000000 Průchodnost disku
03 175 175 _33 001100000001 Čas na roztočení ploten
04 100 100 __0 0000000000BE Počet spuštění/zastavení
05 100 100 __5 000000000000 Počet přemapovaných sektorů
07 100 100 _67 000000000000 Počet chybných hledání
08 100 100 _40 000000000000 Čas potřebný na vyhledání
09 _99 _99 __0 000000000283 Hodin v činnosti
0A 100 100 _60 000000000000 Počet opakovaných pokusů o roztočení ploten
0C 100 100 __0 0000000000BD Počet cyklů zapnutí zařízení
BF _99 _99 __0 000000030000 Počet udalostí zaznamenaných otřesovým senzorem
C0 100 100 __0 000000000010 Počet vypnutí disku
C1 _99 _99 __0 0000000033FB Počet cyklů načítání/vymazání
C2 166 166 __0 002D00130024 Teplota
C4 100 100 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 100 100 __0 000000000000 Počet podezřelých sektorů
C6 100 100 __0 000000000000 Počet neopravitelných sektorů
C7 200 200 __0 000000000000 Počet chyb v kontrolním součtu UltraDMA
DF 100 100 __0 000000000000 Zatížení budiče magnetických hlav způsobené opakovanými úkony

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 045A 3FFF C837 0010 0000 003F 003F 0000 0000 0000
010: 3133 3038 3235 4A32 3338 3533 3533 4358 5A4D 4C44
020: 0003 4000 0004 4A45 444F 3042 3042 4869 7461 6368
030: 6920 4854 5335 3437 3536 3945 3945 3338 3420 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 4000 2F00
050: 4000 0200 0200 0007 3FFF 003F 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 1F06 1F06 0000 005E 0040
080: 01FC 0028 746B 7D69 6163 BC49 BC49 6163 207F 0052
090: 0053 4080 FFFE 0000 0000 0000 0000 0000 0000 0000
100: 82B0 4A85 0000 0000 0000 6003 6003 826C 5000 CCA6
110: 3ECD 2D61 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0029 000B
130: 0000 0000 2182 1CF1 FA00 4000 4000 0400 0108 0000
140: 0000 0806 0808 0A04 0805 0000 0000 0000 0000 0000
150: 0000 0000 4454 4436 0000 0000 0000 5DAD 2518 8000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0003 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 003D 003D 0000 0000 4000
210: 0000 0000 0000 0000 0000 0000 0000 1518 0000 0000
220: 0000 0000 101F 0021 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 21A5

Re: Obnovení systému

Napsal: 06 led 2014 20:04
od Neliell
Adwcleaner:

# AdwCleaner v3.016 - Report created 06/01/2014 at 19:59:29
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : toshiba - TOSHIBA-TOSH
# Running from : C:\Users\toshiba\Desktop\adwcleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16750


-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\hvdleacf.default\prefs.js ]


-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\toshiba\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3987 octets] - [06/01/2014 18:18:46]
AdwCleaner[R1].txt - [1024 octets] - [06/01/2014 19:57:08]
AdwCleaner[R2].txt - [886 octets] - [06/01/2014 19:59:29]
AdwCleaner[S0].txt - [4134 octets] - [06/01/2014 18:19:59]

########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1005 octets] ##########

Re: Obnovení systému

Napsal: 06 led 2014 20:12
od Márty84
:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Obnovení systému

Napsal: 06 led 2014 22:18
od Neliell
Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2014.01.06.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16750
toshiba :: TOSHIBA-TOSH [administrátor]

Ochrana: Povolena

6.1.2014 20:20:58
MBAM-log-2014-01-06 (22-17-53).txt

Typ: Kompletní kontrola (C:\|D:\|Q:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 389469
Uplynulý čas: 1 hodin, 55 minut, 51 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GotClip (PUP.Adware.Gotclip.ScamLotto) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 9
C:\Program Files (x86)\WebexpEnhancedV1 (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284 (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ch (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome\content (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome\content\icons (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome\content\icons\default (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ie (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 10
C:\AdwCleaner\Quarantine\C\Users\toshiba\AppData\Local\SwvUpdater\Updater.exe.vir (PUP.Optional.Amonetize) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\GotClip\Uninstall.exe (PUP.Adware.Gotclip.ScamLotto) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\HandyUpdater\HUpdater.exe (PUP.Optional.HandyUpdater.A) -> Nebyla provedena žádná instrukce.
C:\Users\toshiba\Downloads\FreeCodecPackSetup.exe (Adware.InstallBrain) -> Nebyla provedena žádná instrukce.
C:\Users\toshiba\Downloads\GotClip_Setup.exe (PUP.Optional.HandyUpdater.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ch\WebexpEnhancedV1alpha284.crx (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\install.rdf (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome\content\overlay.xul (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome\content\icons\Thumbs.db (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha284\ff\chrome\content\icons\default\WebexpEnhancedV1alpha284_32.png (PUP.Optional.Webexp) -> Nebyla provedena žádná instrukce.

(konec)

Re: Obnovení systému

Napsal: 06 led 2014 22:33
od Márty84
:arrow: Vsechny nalezy nechte odstranit, pak MBAM odinstalujte.


:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe , ulozte ho na plochu, kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Zprava a objevi se log. Ten mi sem vlozte

Re: Obnovení systému

Napsal: 06 led 2014 22:50
od Neliell
RogueKiller V8.8.0 [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Normální režim
Uživatel : toshiba [Práva správce]
Mód : Kontrola -- Datum : 01/06/2014 22:49:42
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 3 ¤¤¤
[SUSP PATH] szninstall.exe -- C:\Users\toshiba\AppData\Roaming\Seznam.cz\szninstall.exe [7] -> SMAZÁNO [TermThr]
[SUSP PATH] szndesktop.exe -- C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\szndesktop.exe [7] -> SMAZÁNO [TermProc]
[SUSP PATH] listicka-x64.exe -- C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe [7] -> SMAZÁNO [TermThr]

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\toshiba\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> NALEZENO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS547564A9E384 ATA Device +++++
--- User ---
[MBR] 214ebe6cae72fa40a62f5bc428668ce2
[BSP] b3e7c06a331bec5a1847ad562ef786dc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 63 | Size: 400 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 819315 | Size: 304850 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 625153410 | Size: 305227 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_S_01062014_224942.txt >>

Re: Obnovení systému

Napsal: 06 led 2014 22:55
od Márty84
Pokud nepouzivate, doporucuji odinstalovat Seznam Software


:arrow: Znovu spustte RogueKiller jako spravce (pokud jste ho jeste nezavrel/a, rovnou kliknete na napis Smazat)
Probehne kratoucky testik a pak se zpristupni vpravo nahore tlacitko Prohledat. Na to kliknete a probehne dalsi test.
Po dokonceni kliknete na napis Smazat.
Pak kliknete na napis Zprava a objevi se log. Ten mi sem vlozte.
Pak kliknete na napis Oprava Host a Zprava.
Objevi se dalsi log. I ten mi sem vlozte.

Re: Obnovení systému

Napsal: 06 led 2014 23:13
od Neliell
Nejspíše se mi sekl roguekiller, při zapnutí přes správce mi ve statusu běží už několik minut "Kontroluji procesy" bez jakékoliv změny.

Re: Obnovení systému

Napsal: 06 led 2014 23:15
od Márty84
Tak ho ukoncete a zkuste spustit znovu. Pokud nepujde, tak restartujte pc do nouzoceho rezimu a zkuste RK spustit v nem.

Re: Obnovení systému

Napsal: 06 led 2014 23:41
od Neliell
RogueKiller V8.8.0 [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Nouzový režim
Uživatel : toshiba [Práva správce]
Mód : Odebrat -- Datum : 01/06/2014 23:35:32
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.autoupdate ("C:\Users\toshiba\AppData\Roaming\Seznam.cz\szninstall.exe" -c [7]) -> VYMAZÁNO
[RUN][SUSP PATH] HKCU\[...]\Run : cz.seznam.software.szndesktop ("C:\Users\toshiba\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q [7]) -> VYMAZÁNO
[HJ POL][PUM] HKLM\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ POL][PUM] HKLM\[...]\Wow6432Node\[...]\System : EnableLUA (0) -> NAHRAZENO (1)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NAHRAZENO (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ spuštění položky : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Hitachi HTS547564A9E384 ATA Device +++++
--- User ---
[MBR] 214ebe6cae72fa40a62f5bc428668ce2
[BSP] b3e7c06a331bec5a1847ad562ef786dc : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 63 | Size: 400 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 819315 | Size: 304850 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 625153410 | Size: 305227 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_01062014_233532.txt >>
RKreport[0]_S_01062014_224942.txt;RKreport[0]_S_01062014_233524.txt






RogueKiller V8.8.0 [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora : http://www.adlice.com/forum/
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Spuštěno v : Nouzový režim
Uživatel : toshiba [Práva správce]
Mód : Oprava HOSTS -- Datum : 01/06/2014 23:36:25
| ARK || FAK || MBR |

¤¤¤ Škodlivé procesy: : 0 ¤¤¤

¤¤¤ ¤¤¤ Záznamy Registrů: : 0 ¤¤¤

¤¤¤ Ovladač : [NENAHRÁNO 0x0] ¤¤¤

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ Resetovaný HOSTS: ¤¤¤
127.0.0.1 localhost


Dokončeno : << RKreport[0]_H_01062014_233625.txt >>
RKreport[0]_D_01062014_233532.txt;RKreport[0]_S_01062014_224942.txt;RKreport[0]_S_01062014_233524.txt

Re: Obnovení systému

Napsal: 07 led 2014 08:18
od Márty84
Dejte novy log z RSIT

Re: Obnovení systému

Napsal: 07 led 2014 15:59
od Neliell
Logfile of random's system information tool 1.09 (written by random/random)
Run by toshiba at 2014-01-07 15:59:10
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 149 GB (49%) free of 305 GB
Total RAM: 5607 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:59:20, on 7.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\toshiba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll
O4 - HKLM\..\Run: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
O4 - HKLM\..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe /STARTUP
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Toshiba Places Icon Utility.lnk = C:\Program Files\Toshiba\TOSHIBA Places Icon Utility\TosDIMonitor.exe
O8 - Extra context menu item: Přidat do aplikace TOSHIBA Bulletin Board - res://C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-229 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-228 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: McAfee Application Installer Cleanup (0279691381158036) (0279691381158036mcinstcleanup) - Unknown owner - C:\Users\toshiba\AppData\Local\Temp\027969~1.EXE (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe
O23 - Service: @c:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13868 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 22447392
\??\C:\Windows\system32\conhost.exe "13530920053807604201883721805859405021555771230-9906345219813778371530662347
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"taskhost.exe"
"C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe" /s "N360" /m "C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\diMaster.dll" /prefetch:1
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe" /c /a /s UserSession2
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe"
C:\Windows\system32\TODDSrv.exe
"C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe"
"C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe"
"C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe"
"C:\Program Files\Toshiba\Power Saver\TPwrMain.exe"
"C:\Program Files\Toshiba\FlashCards\TCrdMain.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
WLIDSvcM.exe 1804
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Toshiba\TECO\Teco.exe" /r
"C:\Program Files\TOSHIBA\TECO\TecoService.exe"
taskeng.exe {61AEB39F-AB8B-4C66-B882-56D356DB809A}
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe" /STARTUP
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files\Toshiba\TOSHIBA Places Icon Utility\TosDIMonitor.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe"
"C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\tosBtProc.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe"
"C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe"
"C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe"
"C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5432.0.107107198\1589013421" --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --reduce-gpu-sandbox --gpu-vendor-id=0x1002 --gpu-device-id=0x9641 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=8.911.6.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/RestoreNavsuggestControl_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group5 pct:10d stable:pp3 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --instant-process --disable-html-notifications --channel="5432.1.360522469\619595361" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/RestoreNavsuggestControl_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group5 pct:10d stable:pp3 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="5432.3.163667018\1812910266" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/RestoreNavsuggestControl_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group5 pct:10d stable:pp3 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --channel="5432.4.43115163\1703965371" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/RestoreNavsuggestControl_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group5 pct:10d stable:pp3 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="5432.7.318752749\476306738" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AutocompleteDynamicTrial_2/RestoreNavsuggestControl_Stable/BrowserPreReadExperiment/100-pct-default/CookieRetentionPriorityStudy/ExperimentOn/DeferBackgroundExtensionCreation/RateLimited/ForceCompositingMode/thread/InstantExtended/Group5 pct:10d stable:pp3 use_remote_ntp_on_startup:1 espv:210 suppress_on_srp:1/OmniboxBundledExperimentV1/Standard/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_18/UMA-Uniformity-Trial-50-Percent/group_01/" --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --channel="5432.9.4948514\1326892886" /prefetch:673131151
taskhost.exe $(Arg0)
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5432.10.2003687759\1102257197" --ppapi-flash-args --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
"C:\Users\toshiba\Downloads\RSITx64 (1).exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\hvdleacf.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll


C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.DEU
nppdf32.dll
nppdf32.FRA
nppdf32.JPN
nppluginrichmediaplayer.dll

C:\Users\toshiba\AppData\Roaming\Mozilla\Firefox\Profiles\hvdleacf.default\extensions\
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Norton Identity Protection - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll [2013-05-30 509776]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Norton Vulnerability Protection - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\IPS\IPSBHO.DLL [2012-08-10 387040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-08-03 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\coIEPlg.dll [2013-05-30 509776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TosReelTimeMonitor"=C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [2011-03-30 38304]
"Toshiba TEMPRO"=C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [2011-02-10 1546720]
"TPwrMain"=C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [2011-03-02 566696]
"HSON"=C:\Program Files\TOSHIBA\TBS\HSON.exe [2010-09-25 296824]
"TCrdMain"=C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [2011-03-09 967544]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2010-12-14 316032]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2011-02-03 2679592]
"Teco"=C:\Program Files\TOSHIBA\TECO\Teco.exe [2011-04-07 1544104]
"TosSENotify"=C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [2010-12-08 710040]
"TosWaitSrv"=C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [2011-07-01 712096]
"TosNC"=C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [2011-03-03 597928]
"TosVolRegulator"=C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [2009-11-11 24376]
"Toshiba Registration"=C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [2011-08-03 150992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [2011-05-16 846936]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-07-25 20684656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NBAgent"=c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [2011-06-29 1409424]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2013-09-03 40312]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-11-11 343168]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START []
"TSleepSrv"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [2010-06-04 252792]
"ToshibaServiceStation"=C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [2010-11-29 1294712]
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-04-21 59720]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2013-10-01 152392]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
Toshiba Places Icon Utility.lnk - C:\Program Files\Toshiba\TOSHIBA Places Icon Utility\TosDIMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLinkedConnections"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-01-07 00:16:39 ----A---- C:\Windows\system32\IEUDINIT.EXE
2014-01-07 00:02:34 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2014-01-07 00:02:34 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\wextract.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\url.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\occache.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\msls31.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\inseng.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\icardie.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-01-07 00:02:11 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\wininet.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\urlmon.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-01-07 00:02:11 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-01-07 00:02:11 ----A---- C:\Windows\system32\msrating.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\msls31.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\mshtmler.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\msfeedssync.exe
2014-01-07 00:02:11 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\jsproxy.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\jsIntl.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\jscript9diag.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\jscript9.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\ieui.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\iesysprep.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\iertutil.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\ieframe.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-01-07 00:02:11 ----A---- C:\Windows\system32\elshyph.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\wextract.exe
2014-01-07 00:02:10 ----A---- C:\Windows\system32\webcheck.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\vbscript.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\url.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\pngfilt.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\occache.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\mshtmled.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\mshtml.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\mshta.exe
2014-01-07 00:02:10 ----A---- C:\Windows\system32\msfeeds.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\licmgr10.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\jscript.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\inseng.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\imgutil.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\iexpress.exe
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ieUnatt.exe
2014-01-07 00:02:10 ----A---- C:\Windows\system32\iesetup.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\iernonce.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-01-07 00:02:10 ----A---- C:\Windows\system32\iedkcs32.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ieapfltr.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ieapfltr.dat
2014-01-07 00:02:10 ----A---- C:\Windows\system32\ie4uinit.exe
2014-01-07 00:02:10 ----A---- C:\Windows\system32\icardie.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\dxtrans.dll
2014-01-07 00:02:10 ----A---- C:\Windows\system32\dxtmsft.dll
2014-01-07 00:02:09 ----A---- C:\Windows\system32\iepeers.dll
2014-01-06 23:29:04 ----A---- C:\Windows\ntbtlog.txt
2014-01-06 22:49:38 ----A---- C:\Windows\system32\drivers\WUDFRd.sys.bak
2014-01-06 22:49:37 ----A---- C:\Windows\system32\drivers\WUDFPf.sys.bak
2014-01-06 22:49:37 ----A---- C:\Windows\system32\drivers\ws2ifsl.sys.bak
2014-01-06 22:49:37 ----A---- C:\Windows\system32\drivers\wmilib.sys.bak
2014-01-06 22:49:37 ----A---- C:\Windows\system32\drivers\wmiacpi.sys.bak
2014-01-06 22:49:36 ----A---- C:\Windows\system32\drivers\winusb.sys.bak
2014-01-06 22:49:36 ----A---- C:\Windows\system32\drivers\wimmount.sys.bak
2014-01-06 22:49:36 ----A---- C:\Windows\system32\drivers\wfplwf.sys.bak
2014-01-06 22:49:35 ----A---- C:\Windows\system32\drivers\WdfLdr.sys.bak
2014-01-06 22:49:35 ----A---- C:\Windows\system32\drivers\Wdf01000.sys.bak
2014-01-06 22:49:34 ----A---- C:\Windows\system32\drivers\wd.sys.bak
2014-01-06 22:49:34 ----A---- C:\Windows\system32\drivers\watchdog.sys.bak
2014-01-06 22:49:34 ----A---- C:\Windows\system32\drivers\wanarp.sys.bak
2014-01-06 22:49:34 ----A---- C:\Windows\system32\drivers\wacompen.sys.bak
2014-01-06 22:49:33 ----A---- C:\Windows\system32\drivers\vwifimp.sys.bak
2014-01-06 22:49:33 ----A---- C:\Windows\system32\drivers\vwififlt.sys.bak
2014-01-06 22:49:31 ----A---- C:\Windows\system32\drivers\vwifibus.sys.bak
2014-01-06 22:49:31 ----A---- C:\Windows\system32\drivers\VSTDPV6.SYS.bak
2014-01-06 22:49:30 ----A---- C:\Windows\system32\drivers\VSTCNXT6.SYS.bak
2014-01-06 22:49:29 ----A---- C:\Windows\system32\drivers\VSTAZL6.SYS.bak
2014-01-06 22:49:28 ----A---- C:\Windows\system32\drivers\vsmraid.sys.bak
2014-01-06 22:49:28 ----A---- C:\Windows\system32\drivers\volsnap.sys.bak
2014-01-06 22:49:28 ----A---- C:\Windows\system32\drivers\volmgrx.sys.bak
2014-01-06 22:49:27 ----A---- C:\Windows\system32\drivers\volmgr.sys.bak
2014-01-06 22:49:27 ----A---- C:\Windows\system32\drivers\videoprt.sys.bak
2014-01-06 22:49:26 ----A---- C:\Windows\system32\drivers\viaide.sys.bak
2014-01-06 22:49:26 ----A---- C:\Windows\system32\drivers\vhdmp.sys.bak
2014-01-06 22:49:26 ----A---- C:\Windows\system32\drivers\vgapnp.sys.bak
2014-01-06 22:49:26 ----A---- C:\Windows\system32\drivers\vga.sys.bak
2014-01-06 22:49:25 ----A---- C:\Windows\system32\drivers\vdrvroot.sys.bak
2014-01-06 22:49:25 ----A---- C:\Windows\system32\drivers\usbvideo.sys.bak
2014-01-06 22:49:25 ----A---- C:\Windows\system32\drivers\usbuhci.sys.bak
2014-01-06 22:49:24 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS.bak
2014-01-06 22:49:24 ----A---- C:\Windows\system32\drivers\usbscan.sys.bak
2014-01-06 22:49:24 ----A---- C:\Windows\system32\drivers\usbrpm.sys.bak
2014-01-06 22:49:23 ----A---- C:\Windows\system32\drivers\usbprint.sys.bak
2014-01-06 22:49:23 ----A---- C:\Windows\system32\drivers\usbport.sys.bak
2014-01-06 22:49:22 ----A---- C:\Windows\system32\drivers\usbohci.sys.bak
2014-01-06 22:49:22 ----A---- C:\Windows\system32\drivers\usbhub.sys.bak
2014-01-06 22:49:21 ----A---- C:\Windows\system32\drivers\usbehci.sys.bak
2014-01-06 22:49:21 ----A---- C:\Windows\system32\drivers\usbd.sys.bak
2014-01-06 22:49:21 ----A---- C:\Windows\system32\drivers\usbcir.sys.bak
2014-01-06 22:49:21 ----A---- C:\Windows\system32\drivers\usbccgp.sys.bak
2014-01-06 22:49:20 ----A---- C:\Windows\system32\drivers\USBCAMD2.sys.bak
2014-01-06 22:49:20 ----A---- C:\Windows\system32\drivers\usbaapl64.sys.bak
2014-01-06 22:49:20 ----A---- C:\Windows\system32\drivers\usb8023.sys.bak
2014-01-06 22:49:19 ----A---- C:\Windows\system32\drivers\umpass.sys.bak
2014-01-06 22:49:19 ----A---- C:\Windows\system32\drivers\umbus.sys.bak
2014-01-06 22:49:19 ----A---- C:\Windows\system32\drivers\ULIAGPKX.SYS.bak
2014-01-06 22:49:18 ----A---- C:\Windows\system32\drivers\udfs.sys.bak
2014-01-06 22:49:18 ----A---- C:\Windows\system32\drivers\UAGP35.SYS.bak
2014-01-06 22:49:17 ----A---- C:\Windows\system32\drivers\TVALZFL.sys.bak
2014-01-06 22:49:17 ----A---- C:\Windows\system32\drivers\TVALZ_O.SYS.bak
2014-01-06 22:49:17 ----A---- C:\Windows\system32\drivers\tunnel.sys.bak
2014-01-06 22:49:17 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys.bak
2014-01-06 22:49:16 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys.bak
2014-01-06 22:49:16 ----A---- C:\Windows\system32\drivers\tssecsrv.sys.bak
2014-01-06 22:49:15 ----A---- C:\Windows\system32\drivers\tosrfusb.sys.bak
2014-01-06 22:49:15 ----A---- C:\Windows\system32\drivers\TosRfSnd.sys.bak
2014-01-06 22:49:15 ----A---- C:\Windows\system32\drivers\tosrfnds.sys.bak
2014-01-06 22:49:15 ----A---- C:\Windows\system32\drivers\Tosrfhid.sys.bak
2014-01-06 22:49:14 ----A---- C:\Windows\system32\drivers\tosrfec.sys.bak
2014-01-06 22:49:14 ----A---- C:\Windows\system32\drivers\tosrfcom.sys.bak
2014-01-06 22:49:13 ----A---- C:\Windows\system32\drivers\tosrfbnp.sys.bak
2014-01-06 22:49:13 ----A---- C:\Windows\system32\drivers\tosrfbd.sys.bak
2014-01-06 22:49:13 ----A---- C:\Windows\system32\drivers\tosporte.sys.bak
2014-01-06 22:49:12 ----A---- C:\Windows\system32\drivers\termdd.sys.bak
2014-01-06 22:49:12 ----A---- C:\Windows\system32\drivers\tdx.sys.bak
2014-01-06 22:49:12 ----A---- C:\Windows\system32\drivers\tdtcp.sys.bak
2014-01-06 22:49:11 ----A---- C:\Windows\system32\drivers\tdpipe.sys.bak
2014-01-06 22:49:11 ----A---- C:\Windows\system32\drivers\tdi.sys.bak
2014-01-06 22:49:09 ----A---- C:\Windows\system32\drivers\tdcmdpst.sys.bak
2014-01-06 22:49:08 ----A---- C:\Windows\system32\drivers\tcpipreg.sys.bak
2014-01-06 22:49:08 ----A---- C:\Windows\system32\drivers\tcpip.sys.bak
2014-01-06 22:49:07 ----A---- C:\Windows\system32\drivers\tape.sys.bak
2014-01-06 22:49:06 ----A---- C:\Windows\system32\drivers\SynTP.sys.bak
2014-01-06 22:49:05 ----A---- C:\Windows\system32\drivers\SYMEVENT64x86.SYS.bak
2014-01-06 22:49:05 ----A---- C:\Windows\system32\drivers\swenum.sys.bak
2014-01-06 22:49:05 ----A---- C:\Windows\system32\drivers\stream.sys.bak
2014-01-06 22:49:04 ----A---- C:\Windows\system32\drivers\storport.sys.bak
2014-01-06 22:49:03 ----A---- C:\Windows\system32\drivers\stexstor.sys.bak
2014-01-06 22:49:03 ----A---- C:\Windows\system32\drivers\ssudmdm.sys.bak
2014-01-06 22:49:03 ----A---- C:\Windows\system32\drivers\ssudbus.sys.bak
2014-01-06 22:49:03 ----A---- C:\Windows\system32\drivers\srvnet.sys.bak
2014-01-06 22:49:01 ----A---- C:\Windows\system32\drivers\srv2.sys.bak
2014-01-06 22:49:01 ----A---- C:\Windows\system32\drivers\srv.sys.bak
2014-01-06 22:49:01 ----A---- C:\Windows\system32\drivers\spsys.sys.bak
2014-01-06 22:49:00 ----A---- C:\Windows\system32\drivers\spldr.sys.bak
2014-01-06 22:48:59 ----A---- C:\Windows\system32\drivers\smclib.sys.bak
2014-01-06 22:48:59 ----A---- C:\Windows\system32\drivers\smb.sys.bak
2014-01-06 22:48:59 ----A---- C:\Windows\system32\drivers\sisraid4.sys.bak
2014-01-06 22:48:58 ----A---- C:\Windows\system32\drivers\sisraid2.sys.bak
2014-01-06 22:48:58 ----A---- C:\Windows\system32\drivers\Sftvollh.sys.bak
2014-01-06 22:48:58 ----A---- C:\Windows\system32\drivers\Sftredirlh.sys.bak
2014-01-06 22:48:57 ----A---- C:\Windows\system32\drivers\Sftplaylh.sys.bak
2014-01-06 22:48:57 ----A---- C:\Windows\system32\drivers\Sftfslh.sys.bak
2014-01-06 22:48:56 ----A---- C:\Windows\system32\drivers\sfloppy.sys.bak
2014-01-06 22:48:56 ----A---- C:\Windows\system32\drivers\sffp_sd.sys.bak
2014-01-06 22:48:56 ----A---- C:\Windows\system32\drivers\sffp_mmc.sys.bak
2014-01-06 22:48:56 ----A---- C:\Windows\system32\drivers\sffdisk.sys.bak
2014-01-06 22:48:55 ----A---- C:\Windows\system32\drivers\sermouse.sys.bak
2014-01-06 22:48:55 ----A---- C:\Windows\system32\drivers\serial.sys.bak
2014-01-06 22:48:55 ----A---- C:\Windows\system32\drivers\serenum.sys.bak
2014-01-06 22:48:54 ----A---- C:\Windows\system32\drivers\secdrv.sys.bak
2014-01-06 22:48:53 ----A---- C:\Windows\system32\drivers\scsiport.sys.bak
2014-01-06 22:48:53 ----A---- C:\Windows\system32\drivers\scfilter.sys.bak
2014-01-06 22:48:53 ----A---- C:\Windows\system32\drivers\sbp2port.sys.bak
2014-01-06 22:48:53 ----A---- C:\Windows\system32\drivers\rtsuvstor.sys.bak
2014-01-06 22:48:52 ----A---- C:\Windows\system32\drivers\RtsUStor.sys.bak
2014-01-06 22:48:51 ----A---- C:\Windows\system32\drivers\rspndr.sys.bak
2014-01-06 22:48:51 ----A---- C:\Windows\system32\drivers\rootmdm.sys.bak
2014-01-06 22:48:50 ----A---- C:\Windows\system32\drivers\RNDISMP.sys.bak
2014-01-06 22:48:50 ----A---- C:\Windows\system32\drivers\rmcast.sys.bak
2014-01-06 22:48:49 ----A---- C:\Windows\system32\drivers\rdyboost.sys.bak
2014-01-06 22:48:49 ----A---- C:\Windows\system32\drivers\rdpwd.sys.bak
2014-01-06 22:48:48 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys.bak
2014-01-06 22:48:48 ----A---- C:\Windows\system32\drivers\RDPREFMP.sys.bak
2014-01-06 22:48:48 ----A---- C:\Windows\system32\drivers\RDPENCDD.sys.bak
2014-01-06 22:48:48 ----A---- C:\Windows\system32\drivers\RDPCDD.sys.bak
2014-01-06 22:48:47 ----A---- C:\Windows\system32\drivers\rdpbus.sys.bak
2014-01-06 22:48:47 ----A---- C:\Windows\system32\drivers\rdbss.sys.bak
2014-01-06 22:48:46 ----A---- C:\Windows\system32\drivers\rassstp.sys.bak
2014-01-06 22:48:46 ----A---- C:\Windows\system32\drivers\raspptp.sys.bak
2014-01-06 22:48:45 ----A---- C:\Windows\system32\drivers\raspppoe.sys.bak
2014-01-06 22:48:45 ----A---- C:\Windows\system32\drivers\rasl2tp.sys.bak
2014-01-06 22:48:45 ----A---- C:\Windows\system32\drivers\rasacd.sys.bak
2014-01-06 22:48:44 ----A---- C:\Windows\system32\drivers\qwavedrv.sys.bak
2014-01-06 22:48:43 ----A---- C:\Windows\system32\drivers\ql40xx.sys.bak
2014-01-06 22:48:43 ----A---- C:\Windows\system32\drivers\ql2300.sys.bak
2014-01-06 22:48:42 ----A---- C:\Windows\system32\drivers\QIOMem.sys.bak
2014-01-06 22:48:42 ----A---- C:\Windows\system32\drivers\processr.sys.bak
2014-01-06 22:48:41 ----A---- C:\Windows\system32\drivers\portcls.sys.bak
2014-01-06 22:48:41 ----A---- C:\Windows\system32\drivers\PGEffect.sys.bak
2014-01-06 22:48:41 ----A---- C:\Windows\system32\drivers\PEAuth.sys.bak
2014-01-06 22:48:40 ----A---- C:\Windows\system32\drivers\pcw.sys.bak
2014-01-06 22:48:39 ----A---- C:\Windows\system32\drivers\pcmcia.sys.bak
2014-01-06 22:48:39 ----A---- C:\Windows\system32\drivers\pciidex.sys.bak
2014-01-06 22:48:38 ----A---- C:\Windows\system32\drivers\pciide.sys.bak
2014-01-06 22:48:38 ----A---- C:\Windows\system32\drivers\pci.sys.bak
2014-01-06 22:48:37 ----A---- C:\Windows\system32\drivers\partmgr.sys.bak
2014-01-06 22:48:37 ----A---- C:\Windows\system32\drivers\parport.sys.bak
2014-01-06 22:48:36 ----A---- C:\Windows\system32\drivers\pacer.sys.bak
2014-01-06 22:48:36 ----A---- C:\Windows\system32\drivers\ohci1394.sys.bak
2014-01-06 22:48:35 ----A---- C:\Windows\system32\drivers\nwifi.sys.bak
2014-01-06 22:48:35 ----A---- C:\Windows\system32\drivers\nvstor.sys.bak
2014-01-06 22:48:35 ----A---- C:\Windows\system32\drivers\NV_AGP.SYS.bak
2014-01-06 22:48:34 ----A---- C:\Windows\system32\drivers\nvraid.sys.bak
2014-01-06 22:48:32 ----A---- C:\Windows\system32\drivers\null.sys.bak
2014-01-06 22:48:32 ----A---- C:\Windows\system32\drivers\ntfs.sys.bak
2014-01-06 22:48:32 ----A---- C:\Windows\system32\drivers\nsiproxy.sys.bak
2014-01-06 22:48:31 ----A---- C:\Windows\system32\drivers\npfs.sys.bak
2014-01-06 22:48:31 ----A---- C:\Windows\system32\drivers\nfrd960.sys.bak
2014-01-06 22:48:30 ----A---- C:\Windows\system32\drivers\netio.sys.bak
2014-01-06 22:48:30 ----A---- C:\Windows\system32\drivers\netbt.sys.bak
2014-01-06 22:48:30 ----A---- C:\Windows\system32\drivers\netbios.sys.bak
2014-01-06 22:48:29 ----A---- C:\Windows\system32\drivers\ndproxy.sys.bak
2014-01-06 22:48:29 ----A---- C:\Windows\system32\drivers\ndiswan.sys.bak
2014-01-06 22:48:28 ----A---- C:\Windows\system32\drivers\ndisuio.sys.bak
2014-01-06 22:48:28 ----A---- C:\Windows\system32\drivers\ndistapi.sys.bak
2014-01-06 22:48:27 ----A---- C:\Windows\system32\drivers\ndiscap.sys.bak
2014-01-06 22:48:27 ----A---- C:\Windows\system32\drivers\ndis.sys.bak
2014-01-06 22:48:26 ----A---- C:\Windows\system32\drivers\mup.sys.bak
2014-01-06 22:48:26 ----A---- C:\Windows\system32\drivers\MTConfig.sys.bak
2014-01-06 22:48:26 ----A---- C:\Windows\system32\drivers\mstee.sys.bak
2014-01-06 22:48:25 ----A---- C:\Windows\system32\drivers\mssmbios.sys.bak
2014-01-06 22:48:25 ----A---- C:\Windows\system32\drivers\msrpc.sys.bak
2014-01-06 22:48:25 ----A---- C:\Windows\system32\drivers\mspqm.sys.bak
2014-01-06 22:48:25 ----A---- C:\Windows\system32\drivers\mspclock.sys.bak
2014-01-06 22:48:24 ----A---- C:\Windows\system32\drivers\mskssrv.sys.bak
2014-01-06 22:48:24 ----A---- C:\Windows\system32\drivers\msiscsi.sys.bak
2014-01-06 22:48:23 ----A---- C:\Windows\system32\drivers\msisadrv.sys.bak
2014-01-06 22:48:23 ----A---- C:\Windows\system32\drivers\mshidkmdf.sys.bak
2014-01-06 22:48:23 ----A---- C:\Windows\system32\drivers\msfs.sys.bak
2014-01-06 22:48:23 ----A---- C:\Windows\system32\drivers\msdsm.sys.bak
2014-01-06 22:48:22 ----A---- C:\Windows\system32\drivers\msahci.sys.bak
2014-01-06 22:48:21 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys.bak
2014-01-06 22:48:21 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys.bak
2014-01-06 22:48:20 ----A---- C:\Windows\system32\drivers\mrxsmb.sys.bak
2014-01-06 22:48:20 ----A---- C:\Windows\system32\drivers\mrxdav.sys.bak
2014-01-06 22:48:20 ----A---- C:\Windows\system32\drivers\mpsdrv.sys.bak
2014-01-06 22:48:20 ----A---- C:\Windows\system32\drivers\mpio.sys.bak
2014-01-06 22:48:19 ----A---- C:\Windows\system32\drivers\mountmgr.sys.bak
2014-01-06 22:48:18 ----A---- C:\Windows\system32\drivers\mouhid.sys.bak
2014-01-06 22:48:18 ----A---- C:\Windows\system32\drivers\mouclass.sys.bak
2014-01-06 22:48:18 ----A---- C:\Windows\system32\drivers\monitor.sys.bak
2014-01-06 22:48:18 ----A---- C:\Windows\system32\drivers\modem.sys.bak
2014-01-06 22:48:17 ----A---- C:\Windows\system32\drivers\MegaSR.sys.bak
2014-01-06 22:48:17 ----A---- C:\Windows\system32\drivers\megasas.sys.bak
2014-01-06 22:48:17 ----A---- C:\Windows\system32\drivers\mcd.sys.bak
2014-01-06 22:48:16 ----A---- C:\Windows\system32\drivers\mbam.sys.bak
2014-01-06 22:48:15 ----A---- C:\Windows\system32\drivers\luafv.sys.bak
2014-01-06 22:48:14 ----A---- C:\Windows\system32\drivers\lsi_scsi.sys.bak
2014-01-06 22:48:14 ----A---- C:\Windows\system32\drivers\lsi_sas2.sys.bak
2014-01-06 22:48:12 ----A---- C:\Windows\system32\drivers\lsi_sas.sys.bak
2014-01-06 22:48:12 ----A---- C:\Windows\system32\drivers\lsi_fc.sys.bak
2014-01-06 22:48:11 ----A---- C:\Windows\system32\drivers\lltdio.sys.bak
2014-01-06 22:48:11 ----A---- C:\Windows\system32\drivers\L1C62x64.sys.bak
2014-01-06 22:48:10 ----A---- C:\Windows\system32\drivers\ksthunk.sys.bak
2014-01-06 22:48:09 ----A---- C:\Windows\system32\drivers\ksecpkg.sys.bak
2014-01-06 22:48:09 ----A---- C:\Windows\system32\drivers\ksecdd.sys.bak
2014-01-06 22:48:09 ----A---- C:\Windows\system32\drivers\ks.sys.bak
2014-01-06 22:48:08 ----A---- C:\Windows\system32\drivers\kbdhid.sys.bak
2014-01-06 22:48:07 ----A---- C:\Windows\system32\drivers\kbdclass.sys.bak
2014-01-06 22:48:07 ----A---- C:\Windows\system32\drivers\isapnp.sys.bak
2014-01-06 22:48:06 ----A---- C:\Windows\system32\drivers\irenum.sys.bak
2014-01-06 22:48:05 ----A---- C:\Windows\system32\drivers\irda.sys.bak
2014-01-06 22:48:05 ----A---- C:\Windows\system32\drivers\ipnat.sys.bak
2014-01-06 22:48:05 ----A---- C:\Windows\system32\drivers\IPMIDrv.sys.bak
2014-01-06 22:48:05 ----A---- C:\Windows\system32\drivers\ipfltdrv.sys.bak
2014-01-06 22:48:03 ----A---- C:\Windows\system32\drivers\intelppm.sys.bak
2014-01-06 22:48:01 ----A---- C:\Windows\system32\drivers\intelide.sys.bak
2014-01-06 22:48:01 ----A---- C:\Windows\system32\drivers\iirsp.sys.bak
2014-01-06 22:48:01 ----A---- C:\Windows\system32\drivers\iaStorV.sys.bak
2014-01-06 22:48:01 ----A---- C:\Windows\system32\drivers\i8042prt.sys.bak
2014-01-06 22:48:00 ----A---- C:\Windows\system32\drivers\hwpolicy.sys.bak
2014-01-06 22:47:59 ----A---- C:\Windows\system32\drivers\http.sys.bak
2014-01-06 22:47:59 ----A---- C:\Windows\system32\drivers\HpSAMD.sys.bak
2014-01-06 22:47:59 ----A---- C:\Windows\system32\drivers\hidusb.sys.bak
2014-01-06 22:47:58 ----A---- C:\Windows\system32\drivers\hidparse.sys.bak
2014-01-06 22:47:58 ----A---- C:\Windows\system32\drivers\hidir.sys.bak
2014-01-06 22:47:57 ----A---- C:\Windows\system32\drivers\hidclass.sys.bak
2014-01-06 22:47:57 ----A---- C:\Windows\system32\drivers\hidbth.sys.bak
2014-01-06 22:47:57 ----A---- C:\Windows\system32\drivers\hidbatt.sys.bak
2014-01-06 22:47:57 ----A---- C:\Windows\system32\drivers\HdAudio.sys.bak
2014-01-06 22:47:55 ----A---- C:\Windows\system32\drivers\hdaudbus.sys.bak
2014-01-06 22:47:55 ----A---- C:\Windows\system32\drivers\hcw85cir.sys.bak
2014-01-06 22:47:55 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys.bak
2014-01-06 22:47:54 ----A---- C:\Windows\system32\drivers\GAGP30KX.SYS.bak
2014-01-06 22:47:53 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS.bak
2014-01-06 22:47:53 ----A---- C:\Windows\system32\drivers\fvevol.sys.bak
2014-01-06 22:47:53 ----A---- C:\Windows\system32\drivers\fs_rec.sys.bak
2014-01-06 22:47:52 ----A---- C:\Windows\system32\drivers\fsdepends.sys.bak
2014-01-06 22:47:52 ----A---- C:\Windows\system32\drivers\fltMgr.sys.bak
2014-01-06 22:47:52 ----A---- C:\Windows\system32\drivers\flpydisk.sys.bak
2014-01-06 22:47:51 ----A---- C:\Windows\system32\drivers\filetrace.sys.bak
2014-01-06 22:47:51 ----A---- C:\Windows\system32\drivers\fileinfo.sys.bak
2014-01-06 22:47:50 ----A---- C:\Windows\system32\drivers\fdc.sys.bak
2014-01-06 22:47:50 ----A---- C:\Windows\system32\drivers\fastfat.sys.bak
2014-01-06 22:47:48 ----A---- C:\Windows\system32\drivers\exfat.sys.bak
2014-01-06 22:47:48 ----A---- C:\Windows\system32\drivers\evbda.sys.bak
2014-01-06 22:47:47 ----A---- C:\Windows\system32\drivers\errdev.sys.bak
2014-01-06 22:47:46 ----A---- C:\Windows\system32\drivers\elxstor.sys.bak
2014-01-06 22:47:45 ----A---- C:\Windows\system32\drivers\dxgmms1.sys.bak
2014-01-06 22:47:44 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys.bak
2014-01-06 22:47:44 ----A---- C:\Windows\system32\drivers\dxg.sys.bak
2014-01-06 22:47:44 ----A---- C:\Windows\system32\drivers\dxapi.sys.bak
2014-01-06 22:47:43 ----A---- C:\Windows\system32\drivers\dumpfve.sys.bak
2014-01-06 22:47:43 ----A---- C:\Windows\system32\drivers\Dumpata.sys.bak
2014-01-06 22:47:43 ----A---- C:\Windows\system32\drivers\drmkaud.sys.bak
2014-01-06 22:47:43 ----A---- C:\Windows\system32\drivers\drmk.sys.bak
2014-01-06 22:47:43 ----A---- C:\Windows\system32\drivers\Diskdump.sys.bak
2014-01-06 22:47:43 ----A---- C:\Windows\system32\drivers\disk.sys.bak
2014-01-06 22:47:42 ----A---- C:\Windows\system32\drivers\discache.sys.bak
2014-01-06 22:47:42 ----A---- C:\Windows\system32\drivers\dfsc.sys.bak
2014-01-06 22:47:41 ----A---- C:\Windows\system32\drivers\crcdisk.sys.bak
2014-01-06 22:47:40 ----A---- C:\Windows\system32\drivers\crashdmp.sys.bak
2014-01-06 22:47:40 ----A---- C:\Windows\system32\drivers\CompositeBus.sys.bak
2014-01-06 22:47:39 ----A---- C:\Windows\system32\drivers\compbatt.sys.bak
2014-01-06 22:47:39 ----A---- C:\Windows\system32\drivers\cng.sys.bak
2014-01-06 22:47:39 ----A---- C:\Windows\system32\drivers\cmdide.sys.bak
2014-01-06 22:47:39 ----A---- C:\Windows\system32\drivers\CmBatt.sys.bak
2014-01-06 22:47:38 ----A---- C:\Windows\system32\drivers\Classpnp.sys.bak
2014-01-06 22:47:37 ----A---- C:\Windows\system32\drivers\circlass.sys.bak
2014-01-06 22:47:36 ----A---- C:\Windows\system32\drivers\CHDRT64.sys.bak
2014-01-06 22:47:36 ----A---- C:\Windows\system32\drivers\cdrom.sys.bak
2014-01-06 22:47:35 ----A---- C:\Windows\system32\drivers\cdfs.sys.bak
2014-01-06 22:47:35 ----A---- C:\Windows\system32\drivers\bxvbda.sys.bak
2014-01-06 22:47:35 ----A---- C:\Windows\system32\drivers\bthmodem.sys.bak
2014-01-06 22:47:34 ----A---- C:\Windows\system32\drivers\btfilter.sys.bak
2014-01-06 22:47:34 ----A---- C:\Windows\system32\drivers\BrUsbSer.sys.bak
2014-01-06 22:47:34 ----A---- C:\Windows\system32\drivers\BrUsbMdm.sys.bak
2014-01-06 22:47:33 ----A---- C:\Windows\system32\drivers\BrSerWdm.sys.bak
2014-01-06 22:47:33 ----A---- C:\Windows\system32\drivers\BrSerId.sys.bak
2014-01-06 22:47:33 ----A---- C:\Windows\system32\drivers\bridge.sys.bak
2014-01-06 22:47:33 ----A---- C:\Windows\system32\drivers\BrFiltUp.sys.bak
2014-01-06 22:47:32 ----A---- C:\Windows\system32\drivers\BrFiltLo.sys.bak
2014-01-06 22:47:32 ----A---- C:\Windows\system32\drivers\bowser.sys.bak
2014-01-06 22:47:31 ----A---- C:\Windows\system32\drivers\blbdrive.sys.bak
2014-01-06 22:47:31 ----A---- C:\Windows\system32\drivers\beep.sys.bak
2014-01-06 22:47:31 ----A---- C:\Windows\system32\drivers\battc.sys.bak
2014-01-06 22:47:30 ----A---- C:\Windows\system32\drivers\b57nd60a.sys.bak
2014-01-06 22:47:25 ----A---- C:\Windows\system32\drivers\atikmpag.sys.bak
2014-01-06 22:47:24 ----A---- C:\Windows\system32\drivers\atikmdag.sys.bak
2014-01-06 22:47:23 ----A---- C:\Windows\system32\drivers\AtihdW76.sys.bak
2014-01-06 22:47:21 ----A---- C:\Windows\system32\drivers\athrx.sys.bak
2014-01-06 22:47:21 ----A---- C:\Windows\system32\drivers\ataport.sys.bak
2014-01-06 22:47:20 ----A---- C:\Windows\system32\drivers\atapi.sys.bak
2014-01-06 22:47:20 ----A---- C:\Windows\system32\drivers\asyncmac.sys.bak
2014-01-06 22:47:20 ----A---- C:\Windows\system32\drivers\arcsas.sys.bak
2014-01-06 22:47:20 ----A---- C:\Windows\system32\drivers\arc.sys.bak
2014-01-06 22:47:20 ----A---- C:\Windows\system32\drivers\appid.sys.bak
2014-01-06 22:47:19 ----A---- C:\Windows\system32\drivers\amdxata.sys.bak
2014-01-06 22:47:18 ----A---- C:\Windows\system32\drivers\amdsbs.sys.bak
2014-01-06 22:47:18 ----A---- C:\Windows\system32\drivers\amdsata.sys.bak
2014-01-06 22:47:18 ----A---- C:\Windows\system32\drivers\amdppm.sys.bak
2014-01-06 22:47:18 ----A---- C:\Windows\system32\drivers\amdk8.sys.bak
2014-01-06 22:47:17 ----A---- C:\Windows\system32\drivers\amdide.sys.bak
2014-01-06 22:47:17 ----A---- C:\Windows\system32\drivers\aliide.sys.bak
2014-01-06 22:47:17 ----A---- C:\Windows\system32\drivers\AGP440.sys.bak
2014-01-06 22:47:16 ----A---- C:\Windows\system32\drivers\agilevpn.sys.bak
2014-01-06 22:47:16 ----A---- C:\Windows\system32\drivers\afd.sys.bak
2014-01-06 22:47:15 ----A---- C:\Windows\system32\drivers\adpu320.sys.bak
2014-01-06 22:47:15 ----A---- C:\Windows\system32\drivers\adpahci.sys.bak
2014-01-06 22:47:15 ----A---- C:\Windows\system32\drivers\adp94xx.sys.bak
2014-01-06 22:47:15 ----A---- C:\Windows\system32\drivers\acpipmi.sys.bak
2014-01-06 22:47:13 ----A---- C:\Windows\system32\drivers\acpi.sys.bak
2014-01-06 22:47:13 ----A---- C:\Windows\system32\drivers\1394ohci.sys.bak
2014-01-06 22:47:12 ----A---- C:\Windows\system32\drivers\1394bus.sys.bak
2014-01-06 20:18:09 ----D---- C:\Users\toshiba\AppData\Roaming\Malwarebytes
2014-01-06 20:17:46 ----D---- C:\ProgramData\Malwarebytes
2014-01-06 18:42:50 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-01-06 18:18:36 ----D---- C:\AdwCleaner
2014-01-06 17:40:07 ----A---- C:\Windows\system32\wmploc.DLL
2014-01-06 17:40:06 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2014-01-06 17:40:06 ----A---- C:\Windows\SYSWOW64\wmp.dll
2014-01-06 17:40:04 ----A---- C:\Windows\system32\wmp.dll
2014-01-06 17:29:41 ----D---- C:\Program Files\trend micro
2014-01-06 17:29:39 ----D---- C:\rsit
2014-01-06 17:11:41 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2014-01-06 17:11:41 ----A---- C:\Windows\system32\msieftp.dll
2014-01-05 23:27:49 ----A---- C:\Windows\system32\win32k.sys
2014-01-05 23:27:26 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2014-01-05 23:27:26 ----A---- C:\Windows\system32\WMPhoto.dll
2014-01-05 23:26:03 ----A---- C:\Windows\system32\crypt32.dll
2014-01-05 23:26:02 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-01-05 23:25:26 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-01-05 23:25:26 ----A---- C:\Windows\system32\imagehlp.dll
2014-01-05 23:23:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-01-05 23:23:37 ----A---- C:\Windows\system32\tzres.dll
2014-01-05 23:22:03 ----A---- C:\Windows\system32\drivers\afd.sys
2014-01-05 23:21:45 ----A---- C:\Windows\system32\drivers\portcls.sys
2014-01-05 23:21:44 ----A---- C:\Windows\system32\drivers\drmk.sys
2014-01-05 23:20:00 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-01-05 23:20:00 ----A---- C:\Windows\system32\authui.dll
2014-01-05 23:19:58 ----A---- C:\Windows\SYSWOW64\SmartcardCredentialProvider.dll
2014-01-05 23:19:58 ----A---- C:\Windows\SYSWOW64\credui.dll
2014-01-05 23:19:58 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
2014-01-05 23:19:58 ----A---- C:\Windows\system32\credui.dll
2014-01-05 23:18:09 ----A---- C:\Windows\system32\schannel.dll
2014-01-05 23:18:07 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-01-05 23:18:07 ----A---- C:\Windows\system32\lsasrv.dll
2014-01-05 23:18:07 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-01-05 23:18:07 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-01-05 23:18:07 ----A---- C:\Windows\system32\drivers\cng.sys
2014-01-05 23:18:06 ----A---- C:\Windows\system32\sspicli.dll
2014-01-05 23:18:05 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-01-05 23:18:05 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-01-05 23:18:05 ----A---- C:\Windows\system32\secur32.dll
2014-01-05 23:18:05 ----A---- C:\Windows\system32\ncrypt.dll
2014-01-05 23:18:05 ----A---- C:\Windows\system32\lsass.exe
2014-01-05 23:18:04 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-01-05 23:18:04 ----A---- C:\Windows\system32\sspisrv.dll
2014-01-05 23:16:44 ----A---- C:\Windows\system32\gdi32.dll
2014-01-05 23:16:43 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-01-05 23:16:39 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-01-05 23:16:39 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-01-05 23:16:39 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-01-05 23:16:39 ----A---- C:\Windows\system32\wscript.exe
2014-01-05 23:16:39 ----A---- C:\Windows\system32\scrrun.dll
2014-01-05 23:16:39 ----A---- C:\Windows\system32\cscript.exe
2014-01-05 23:16:36 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-01-05 23:16:36 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-01-05 23:16:36 ----A---- C:\Windows\system32\nshwfp.dll
2014-01-05 23:16:36 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-01-05 23:16:36 ----A---- C:\Windows\system32\FWPUCLNT.DLL

======List of files/folders modified in the last 1 month======

2014-01-07 15:59:06 ----D---- C:\Windows\Temp
2014-01-07 15:53:38 ----D---- C:\Users\toshiba\AppData\Roaming\Skype
2014-01-07 15:53:12 ----SHD---- C:\System Volume Information
2014-01-07 15:50:20 ----D---- C:\Windows\system32\config
2014-01-07 05:08:47 ----D---- C:\Windows\winsxs
2014-01-07 05:04:45 ----D---- C:\Program Files (x86)\Internet Explorer
2014-01-07 05:04:43 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-01-07 05:04:43 ----D---- C:\Program Files\Internet Explorer
2014-01-07 05:04:39 ----D---- C:\Windows\system32\cs-CZ
2014-01-07 05:04:17 ----D---- C:\Windows\SYSWOW64\migration
2014-01-07 05:04:16 ----D---- C:\Windows\SYSWOW64\en-US
2014-01-07 05:04:07 ----D---- C:\Windows\SysWOW64
2014-01-07 05:04:00 ----D---- C:\Windows\PolicyDefinitions
2014-01-07 05:03:59 ----D---- C:\Windows\system32\migration
2014-01-07 05:03:57 ----D---- C:\Windows\system32\en-US
2014-01-07 05:03:51 ----D---- C:\Windows\System32
2014-01-07 00:15:42 ----D---- C:\Windows\system32\catroot
2014-01-07 00:12:24 ----D---- C:\Windows\system32\catroot2
2014-01-06 23:57:52 ----D---- C:\Windows\Logs
2014-01-06 23:56:23 ----D---- C:\Windows
2014-01-06 23:35:19 ----D---- C:\Windows\system32\drivers
2014-01-06 22:57:00 ----RD---- C:\Program Files (x86)
2014-01-06 22:45:33 ----D---- C:\Users\toshiba\AppData\Roaming\Seznam.cz
2014-01-06 22:39:09 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-06 22:36:04 ----D---- C:\Program Files (x86)\HandyUpdater
2014-01-06 22:36:04 ----D---- C:\Program Files (x86)\GotClip
2014-01-06 20:17:46 ----HD---- C:\ProgramData
2014-01-06 18:20:00 ----D---- C:\Windows\Tasks
2014-01-06 18:20:00 ----D---- C:\Windows\system32\Tasks
2014-01-06 18:00:57 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-01-06 18:00:56 ----D---- C:\Windows\inf
2014-01-06 17:50:37 ----D---- C:\Program Files (x86)\Windows Media Player
2014-01-06 17:50:32 ----D---- C:\Program Files\Windows Media Player
2014-01-06 17:48:30 ----D---- C:\Windows\system32\DriverStore
2014-01-06 17:47:52 ----D---- C:\Users\toshiba\AppData\Roaming\TS3Client
2014-01-06 17:29:41 ----RD---- C:\Program Files
2014-01-06 17:24:17 ----D---- C:\Windows\system32\MRT
2014-01-06 17:22:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-01-05 23:04:05 ----SHD---- C:\Windows\Installer
2014-01-05 22:44:50 ----D---- C:\Windows\system32\wfp
2014-01-05 22:44:49 ----RSD---- C:\Windows\Media
2014-01-05 22:44:34 ----D---- C:\Windows\system32\wbem
2014-01-05 22:41:14 ----D---- C:\Windows\SYSWOW64\wbem
2014-01-05 22:41:04 ----D---- C:\Windows\rescache
2014-01-05 22:40:04 ----D---- C:\Windows\SYSWOW64\Macromed
2014-01-05 22:39:55 ----D---- C:\Windows\system32\Macromed
2014-01-05 22:39:53 ----D---- C:\Windows\system32\CodeIntegrity
2014-01-05 22:39:43 ----D---- C:\Windows\AppCompat
2014-01-05 22:39:09 ----D---- C:\ProgramData\Norton
2014-01-05 22:39:03 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-01-05 22:39:02 ----D---- C:\Program Files (x86)\Skype
2014-01-05 22:39:01 ----D---- C:\Program Files (x86)\PokerStars
2014-01-05 22:31:56 ----D---- C:\Windows\registration
2014-01-05 22:29:42 ----D---- C:\Users\toshiba\AppData\Roaming\SoftGrid Client
2014-01-05 22:29:23 ----D---- C:\ProgramData\Skype
2014-01-05 22:27:54 ----RHD---- C:\MSOCache
2013-12-30 12:01:46 ----D---- C:\Windows\Prefetch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SymDS;Symantec Data Store; C:\Windows\system32\drivers\N360x64\1404000.028\SYMDS64.SYS [2013-05-20 493656]
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\N360x64\1404000.028\SYMEFA64.SYS [2013-05-22 1139800]
R0 TVALZ;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver; C:\Windows\system32\DRIVERS\TVALZ_O.SYS [2009-07-14 26840]
R1 BHDrvx64;BHDrvx64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20131218.001\BHDrvx64.sys [2013-12-18 1526488]
R1 ccSet_N360;Norton 360 Settings Manager; C:\Windows\system32\drivers\N360x64\1404000.028\ccSetx64.sys [2013-04-15 169048]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [2013-11-23 484952]
R1 IDSVia64;IDSVia64; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20140103.001_dc1\IDSvia64.sys [2014-01-03 521944]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL) x64; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSPX64.SYS [2013-03-04 36952]
R1 SymIRON;Symantec Iron Driver; C:\Windows\system32\drivers\N360x64\1404000.028\Ironx64.SYS [2012-07-27 224416]
R1 SymNetS;Symantec Network Security WFP Driver; C:\Windows\system32\drivers\N360x64\1404000.028\SYMNETS.SYS [2013-04-24 433752]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2010-11-29 82224]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver; C:\Windows\system32\DRIVERS\TVALZFL.sys [2009-06-19 14472]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-11-11 10496512]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-11-10 326656]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2010-12-17 2675712]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2010-09-24 116752]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver; C:\Windows\system32\DRIVERS\btfilter.sys [2010-10-18 42096]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2011-01-27 1577088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2014-01-04 137648]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-02-09 77424]
R3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20140106.001\ENG64.SYS [2014-01-04 126040]
R3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20140106.001\EX64.SYS [2014-01-04 2099288]
R3 PGEffect;Pangu effect driver; C:\Windows\system32\DRIVERS\pgeffect.sys [2011-02-08 38096]
R3 QIOMem;Generic IO & Memory Access; C:\Windows\system32\drivers\QIOMem.sys [2009-06-15 12800]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SRTSP;Symantec Real Time Storage Protection x64; C:\Windows\system32\drivers\N360x64\1404000.028\SRTSP64.SYS [2013-05-15 796760]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [2013-10-07 177312]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-02-03 1413680]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver; C:\Windows\system32\DRIVERS\tdcmdpst.sys [2009-07-30 27784]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2011-02-23 291120]
R3 tosrfec;Bluetooth ACPI; C:\Windows\system32\DRIVERS\tosrfec.sys [2010-06-18 18872]
R3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2010-08-30 94528]
R3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2011-01-27 67384]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2013-08-20 103576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-12-01 250984]
S3 RSUSBVSTOR;RTSUVSTOR.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RTSUVSTOR.sys [2010-11-30 307304]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2013-08-20 204568]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2010-11-11 50864]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 TosRfSnd;Bluetooth Audio; C:\Windows\system32\drivers\tosrfsnd.sys [2010-04-26 63488]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-09 65640]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-11-10 204288]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2013-09-07 55624]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 cfWiMAXService;ConfigFree WiMAX Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
R2 ConfigFree Service;ConfigFree Service; C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 N360;Norton 360; C:\Program Files (x86)\Norton 360\Engine\20.4.0.40\ccSvcHst.exe [2013-05-20 144368]
R2 NAUpdate;@c:\Program Files (x86)\Nero\Update\NASvc.exe,-200; c:\Program Files (x86)\Nero\Update\NASvc.exe [2011-03-29 598312]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 Skype C2C Service;Skype C2C Service; C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-08-14 3291008]
R2 TeamViewer8;TeamViewer 8; C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-04-23 3574624]
R2 TODDSrv;TOSHIBA Optical Disc Drive Service; C:\Windows\system32\TODDSrv.exe [2010-10-20 138656]
R2 TosCoSrv;TOSHIBA Power Saver; C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [2010-12-09 489384]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [2011-04-07 294328]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2013-10-01 641352]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
R3 TMachInfo;TMachInfo; C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-29 54136]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2010-04-12 196976]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-12-08 137632]
R3 TPCHSrv;TPCH Service; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2011-07-01 828856]
S2 0279691381158036mcinstcleanup;McAfee Application Installer Cleanup (0279691381158036); C:\Users\toshiba\AppData\Local\Temp\027969~1.EXE -cleanup -nolog []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-03 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-07-25 162672]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-06 257416]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-08-03 136176]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-01-07 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-01-06 119408]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2009-11-19 4925184]
S3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO); C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [2011-02-10 112080]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-04-17 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Re: Obnovení systému

Napsal: 07 led 2014 16:37
od Márty84
Jeste jeden sken a budem mazat.


:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).